Fix worker/gateway logic bugs and duplicate CORS headers
worker.py (both the ConfigMap copy and conf/worker.py): - Set an explicit ack_wait=60s on the JetStream pull consumer. It was previously left at the implicit default (~30s), the same ballpark as the outbound HTTP timeout - a slow-but-legitimate external call could cause JetStream to redeliver the message to another worker while the first was still mid-request, double-processing a non-idempotent call (e.g. duplicate order creation). - Track in-flight tasks and drain them (bounded wait) before closing the NATS/HTTP connections on shutdown, instead of cutting them off immediately - avoids dropped/duplicated messages on pod restarts. - Generic exception handler now does nak(delay=5) instead of an undelayed nak(), avoiding a tight redelivery loop on a persistent bug. - Missing 'data' field in a message now explicitly drops with a log line instead of silently forwarding the entire internal envelope. - Removed the hardcoded NATS password fallback baked into the source (every deployment already supplies it via a Secret at runtime, so this was a redundant plaintext copy sitting in a ConfigMap). app.py (both the ConfigMap copy and conf/app.py): - Fixed "NATS by connected" typo -> "NATS not connected". - Same hardcoded-password-fallback removal as worker.py. CORS: - conf/nginx-jupiter.conf and the in-cluster jupiter-cors-proxy nginx config both add their own CORS headers without stripping any the upstream might set, unlike nginx-queue-proxy.conf which does this correctly. Added proxy_hide_header for the ACA-* headers in both - browsers reject a response with duplicate Access-Control-* values. docker-compose.yml: - Added the missing doormile-proxy service (doormile.com -> :8206 -> NodePort 30830). nginx-doormile.conf existed but had no service wiring it into Traefik, unlike every other app.
This commit is contained in:
@@ -67,7 +67,7 @@ data:
|
||||
# Configuration
|
||||
NATS_URL = os.getenv("NATS_URL", "nats://nats-server:4222")
|
||||
NATS_USER = os.getenv("NATS_USER", "admin")
|
||||
NATS_PASSWORD = os.getenv("NATS_PASSWORD", "package@321#")
|
||||
NATS_PASSWORD = os.getenv("NATS_PASSWORD", "")
|
||||
|
||||
# Endpoint to NATS subject mapping
|
||||
ENDPOINT_ROUTES = {
|
||||
@@ -179,7 +179,7 @@ data:
|
||||
subject = ENDPOINT_ROUTES.get(endpoint, "api.unknown")
|
||||
|
||||
if not js:
|
||||
raise HTTPException(status_code=503, detail="NATS by connected")
|
||||
raise HTTPException(status_code=503, detail="NATS not connected")
|
||||
|
||||
try:
|
||||
# Create a unique inbox for the reply
|
||||
|
||||
@@ -16,6 +16,15 @@ data:
|
||||
|
||||
location / {
|
||||
proxy_pass http://jupiter_backend;
|
||||
|
||||
# Strip any CORS headers the backend may set itself, so we don't
|
||||
# end up sending duplicate Access-Control-* headers (browsers
|
||||
# reject a response that has more than one value for these).
|
||||
proxy_hide_header 'Access-Control-Allow-Origin';
|
||||
proxy_hide_header 'Access-Control-Allow-Methods';
|
||||
proxy_hide_header 'Access-Control-Allow-Headers';
|
||||
proxy_hide_header 'Access-Control-Max-Age';
|
||||
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
|
||||
Reference in New Issue
Block a user