nginx
This commit is contained in:
@@ -78,10 +78,28 @@ server {
|
||||
# console's origin and should not need to: the browser only ever talks to
|
||||
# its own host, and this container makes the cross-origin call.
|
||||
location /ingest/ {
|
||||
# Say when the token is missing, rather than letting it look like a
|
||||
# rejected one.
|
||||
#
|
||||
# nginx omits a header whose value is empty, so an unset INGEST_TOKEN
|
||||
# sends no `X-API-Key` at all — and the ingest service answers that with
|
||||
# the same 401 it gives a wrong key. Two very different problems, one
|
||||
# indistinguishable message, and the one that is actually ours reads as
|
||||
# the other team's. This names it.
|
||||
#
|
||||
# `if` is a blunt instrument in nginx and mostly to be avoided, but
|
||||
# `return` inside a location is the one use that is documented as safe.
|
||||
set $ingest_token "${INGEST_TOKEN}";
|
||||
# At location level: `default_type` is not permitted inside `if`.
|
||||
default_type application/json;
|
||||
if ($ingest_token = "") {
|
||||
return 503 '{"detail":"INGEST_TOKEN is not set on this container, so no X-API-Key was sent. Set it in the deployment environment and restart — envsubst runs at container start, so a running container will not pick it up."}';
|
||||
}
|
||||
|
||||
proxy_pass https://mcp.nearle.ai.in/;
|
||||
proxy_ssl_server_name on;
|
||||
proxy_set_header Host mcp.nearle.ai.in;
|
||||
proxy_set_header X-API-Key "${INGEST_TOKEN}";
|
||||
proxy_set_header X-API-Key $ingest_token;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_http_version 1.1;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user