test bugs fixed

This commit is contained in:
2026-08-28 18:18:50 +05:30
parent 670d193f36
commit 32c3bef3ad
6 changed files with 598 additions and 473 deletions

View File

@@ -105,27 +105,63 @@ server {
# console's origin and should not need to: the browser only ever talks to
# its own host, and this container makes the cross-origin call.
location /ingest/ {
# Say when the token is missing, rather than letting it look like a
# rejected one.
# ── Where the ingest service is, and how we prove who we are ─────────
#
# nginx omits a header whose value is empty, so an unset INGEST_TOKEN
# sends no `X-API-Key` at all — and the ingest service answers that with
# the same 401 it gives a wrong key. Two very different problems, one
# indistinguishable message, and the one that is actually ours reads as
# the other team's. This names it.
# Both are environment variables so the deployment can move between two
# arrangements without a rebuild:
#
# `if` is a blunt instrument in nginx and mostly to be avoided, but
# `return` inside a location is the one use that is documented as safe.
# INGEST_UPSTREAM=https://mcp.nearle.ai.in INGEST_TOKEN=<secret>
# The public host. Needs a credential, because that host is on the
# internet and its guards do not care who is asking.
#
# INGEST_UPSTREAM=http://<container>:<port> INGEST_TOKEN=
# The internal Docker network. `app.nearledaily.com` and
# `mcp.nearle.ai.in` both resolve to 72.60.218.25 — the same host —
# so the two containers can talk without going out to the internet
# and back. No secret has to exist on this side at all, which is
# the whole point: a credential that is never issued cannot leak,
# expire, or be pasted into a chat window.
#
# The second needs the ingest service to trust its own machine. That is
# their change, not ours; this side is ready for either.
set $ingest_token "${INGEST_TOKEN}";
# At location level: `default_type` is not permitted inside `if`.
default_type application/json;
if ($ingest_token = "") {
return 503 '{"detail":"INGEST_TOKEN is not set on this container, so no X-API-Key was sent. Set it in the deployment environment and restart — envsubst runs at container start, so a running container will not pick it up."}';
}
proxy_pass https://mcp.nearle.ai.in/;
# No 503 guard for a missing token any more, deliberately.
#
# It existed because an unset token sent no header and the service
# answered with the same flat 401 it gives a wrong key. Two problems,
# one message. It cannot stay: on the internal network an empty token is
# the CORRECT configuration, and a guard that refuses the intended setup
# is worse than the ambiguity it was written to remove. The service's own
# 401 now names the fix — "Send a bearer token ... or an X-API-Key
# header" — which is the sentence the guard was standing in for.
#
# nginx omits a header whose value is empty, so the line below sends
# `X-API-Key` on the public host and nothing at all internally. One
# directive, both modes, no branching.
# `${INGEST_UPSTREAM}` and not `$upstream_variable`, and the difference
# is not cosmetic.
#
# envsubst rewrites this line at container start, so nginx parses a
# literal address and behaves exactly as it did when the host was
# hardcoded. Putting an nginx VARIABLE in proxy_pass instead changes
# three things at once: nginx resolves the name per request rather than
# at startup, which requires a `resolver` directive; 127.0.0.11 (Docker's
# embedded DNS) exists only on a user-defined network, so on a default
# bridge every ingest call fails with "recv() failed ... while resolving";
# and a variable proxy_pass stops stripping the location prefix, so the
# upstream starts receiving `/ingest/api/...` and 404s. Measured, not
# guessed — the first version of this did all three.
#
# The trailing slash is what strips `/ingest/`, so INGEST_UPSTREAM must
# NOT end in one. A name that cannot be resolved now fails at startup
# rather than per request, which is the better place to find out.
proxy_pass ${INGEST_UPSTREAM}/;
proxy_ssl_server_name on;
proxy_set_header Host mcp.nearle.ai.in;
# Derived from the upstream rather than hardcoded, so it stays correct
# when the upstream becomes a container name.
proxy_set_header Host $proxy_host;
proxy_set_header X-API-Key $ingest_token;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_http_version 1.1;