Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
50 changes: 1 addition & 49 deletions .devcontainer/images/nginx/conf/nginx_external_endpoints.conf
Original file line number Diff line number Diff line change
@@ -1,12 +1,7 @@
server {
listen 80;

# Forbid access to internal endpoints
location /internal/v4/ {
return 403 'Forbidden';
}

# proxy and log all CC traffic
# proxy and log all CC traffic (including internal endpoints)
location / {
access_log /tmp/nginx-access.log main;
proxy_buffering off;
Expand Down Expand Up @@ -60,54 +55,11 @@ server {
include public_upload.conf;
}

location ~ /staging/(v3/)?(droplets|buildpack_cache)/.*/upload {
# Allow download the droplets and buildpacks
if ($request_method = GET){
proxy_pass http://cloud_controller;
}

# Allow large uploads
client_max_body_size 1536M; #already enforced upstream/but doesn't hurt.

# Pass along auth header
set $auth_header $upstream_http_x_auth;
proxy_set_header Authorization $auth_header;

# Pass altered request body to this location
upload_pass @cc_uploads;

# Store files to this directory
upload_store /tmp/staged_droplet_uploads;

# Allow uploaded files to be read only by user
#upload_store_access user:r;

# Set specified fields in request body
upload_set_form_field "droplet_path" $upload_tmp_path;

#on any error, delete uploaded files.
upload_cleanup 400-505;
}

# Pass altered request body to a backend
location @cc_uploads {
proxy_pass http://cloud_controller;
}

location ~ ^/internal_redirect/(.*){
# only allow internal redirects
internal;

set $download_url $1;

#have to manualy pass along auth header
set $auth_header $upstream_http_x_auth;
proxy_set_header Authorization $auth_header;

# Download the file and send it to client
proxy_pass $download_url;
}

location /nginx_status {
stub_status on;

Expand Down
Loading