test bugs fixed
This commit is contained in:
@@ -105,27 +105,63 @@ server {
|
||||
# console's origin and should not need to: the browser only ever talks to
|
||||
# its own host, and this container makes the cross-origin call.
|
||||
location /ingest/ {
|
||||
# Say when the token is missing, rather than letting it look like a
|
||||
# rejected one.
|
||||
# ── Where the ingest service is, and how we prove who we are ─────────
|
||||
#
|
||||
# nginx omits a header whose value is empty, so an unset INGEST_TOKEN
|
||||
# sends no `X-API-Key` at all — and the ingest service answers that with
|
||||
# the same 401 it gives a wrong key. Two very different problems, one
|
||||
# indistinguishable message, and the one that is actually ours reads as
|
||||
# the other team's. This names it.
|
||||
# Both are environment variables so the deployment can move between two
|
||||
# arrangements without a rebuild:
|
||||
#
|
||||
# `if` is a blunt instrument in nginx and mostly to be avoided, but
|
||||
# `return` inside a location is the one use that is documented as safe.
|
||||
# INGEST_UPSTREAM=https://mcp.nearle.ai.in INGEST_TOKEN=<secret>
|
||||
# The public host. Needs a credential, because that host is on the
|
||||
# internet and its guards do not care who is asking.
|
||||
#
|
||||
# INGEST_UPSTREAM=http://<container>:<port> INGEST_TOKEN=
|
||||
# The internal Docker network. `app.nearledaily.com` and
|
||||
# `mcp.nearle.ai.in` both resolve to 72.60.218.25 — the same host —
|
||||
# so the two containers can talk without going out to the internet
|
||||
# and back. No secret has to exist on this side at all, which is
|
||||
# the whole point: a credential that is never issued cannot leak,
|
||||
# expire, or be pasted into a chat window.
|
||||
#
|
||||
# The second needs the ingest service to trust its own machine. That is
|
||||
# their change, not ours; this side is ready for either.
|
||||
set $ingest_token "${INGEST_TOKEN}";
|
||||
# At location level: `default_type` is not permitted inside `if`.
|
||||
default_type application/json;
|
||||
if ($ingest_token = "") {
|
||||
return 503 '{"detail":"INGEST_TOKEN is not set on this container, so no X-API-Key was sent. Set it in the deployment environment and restart — envsubst runs at container start, so a running container will not pick it up."}';
|
||||
}
|
||||
|
||||
proxy_pass https://mcp.nearle.ai.in/;
|
||||
# No 503 guard for a missing token any more, deliberately.
|
||||
#
|
||||
# It existed because an unset token sent no header and the service
|
||||
# answered with the same flat 401 it gives a wrong key. Two problems,
|
||||
# one message. It cannot stay: on the internal network an empty token is
|
||||
# the CORRECT configuration, and a guard that refuses the intended setup
|
||||
# is worse than the ambiguity it was written to remove. The service's own
|
||||
# 401 now names the fix — "Send a bearer token ... or an X-API-Key
|
||||
# header" — which is the sentence the guard was standing in for.
|
||||
#
|
||||
# nginx omits a header whose value is empty, so the line below sends
|
||||
# `X-API-Key` on the public host and nothing at all internally. One
|
||||
# directive, both modes, no branching.
|
||||
|
||||
# `${INGEST_UPSTREAM}` and not `$upstream_variable`, and the difference
|
||||
# is not cosmetic.
|
||||
#
|
||||
# envsubst rewrites this line at container start, so nginx parses a
|
||||
# literal address and behaves exactly as it did when the host was
|
||||
# hardcoded. Putting an nginx VARIABLE in proxy_pass instead changes
|
||||
# three things at once: nginx resolves the name per request rather than
|
||||
# at startup, which requires a `resolver` directive; 127.0.0.11 (Docker's
|
||||
# embedded DNS) exists only on a user-defined network, so on a default
|
||||
# bridge every ingest call fails with "recv() failed ... while resolving";
|
||||
# and a variable proxy_pass stops stripping the location prefix, so the
|
||||
# upstream starts receiving `/ingest/api/...` and 404s. Measured, not
|
||||
# guessed — the first version of this did all three.
|
||||
#
|
||||
# The trailing slash is what strips `/ingest/`, so INGEST_UPSTREAM must
|
||||
# NOT end in one. A name that cannot be resolved now fails at startup
|
||||
# rather than per request, which is the better place to find out.
|
||||
proxy_pass ${INGEST_UPSTREAM}/;
|
||||
proxy_ssl_server_name on;
|
||||
proxy_set_header Host mcp.nearle.ai.in;
|
||||
# Derived from the upstream rather than hardcoded, so it stays correct
|
||||
# when the upstream becomes a container name.
|
||||
proxy_set_header Host $proxy_host;
|
||||
proxy_set_header X-API-Key $ingest_token;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_http_version 1.1;
|
||||
|
||||
Reference in New Issue
Block a user