Uploads live outside the document root, because nothing anybody uploads should sit where a web server might decide to execute it. They come back through a controller instead — but their addresses still end in .png.
A typical nginx configuration has a rule serving anything matching an image extension straight from disk, and that rule never reaches index.php. So every one of those addresses 404s.
🚨 The tell is nginx's own error page rather than Convoro's. If you get a styled Convoro page, the request did reach the application and this is not your problem.
The paths that need a block are listed in tools/deploy/nginx-paths-served-by-php.conf. Each looks like:
location ^~ /avatar/ { try_files $uri /index.php?$query_string; }It works locally because PHP's built-in server routes everything through the front controller and has no such rule.