# Example nginx site for jray-server. NOT installed anywhere by the package — # the proxy usually runs on a different host from the server, so a file dropped # into this machine's nginx would be in the wrong place. Copy it to the proxy. # # /etc/nginx/sites-available/jray-server (then symlink into sites-enabled) # # Replace jray.example.org and the upstream address, and point ssl_certificate # at your own certificate. upstream jray_server { # The address jray-server listens on. If the proxy runs on the SAME host, # this is 127.0.0.1:8080 and JRAY_BIND can stay at its loopback default. If # the proxy is elsewhere, put the server's address here, set JRAY_BIND to # something that host can reach (0.0.0.0:8080), and firewall the port to # this proxy. server 10.0.0.42:8080; keepalive 8; } server { listen 443 ssl; http2 on; server_name jray.example.org; ssl_certificate /etc/letsencrypt/live/jray.example.org/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/jray.example.org/privkey.pem; # SPEC section 6 stage 1 body caps, mirrored at the edge. Section 8 asks for # them in both places: the proxy rejects the bulk before it reaches the # application, and the application stays correct if it is ever run without a # proxy. These must not be tightened below the application's own limits or # legitimate uploads get a 413 from nginx that the server never sees. client_max_body_size 2m; location = /api/v1/manifests/bundle { # Series bundles only (section 2). This is why the cap is per-location # rather than one global 25m: widening it everywhere would hand every # other endpoint a 25 MiB budget it has no use for. client_max_body_size 25m; proxy_pass http://jray_server; include snippets/jray-server-proxy.conf; } # Liveness. Kept out of the access log because uptime checks poll it hard. location = /health { proxy_pass http://jray_server; include snippets/jray-server-proxy.conf; access_log off; } location / { proxy_pass http://jray_server; include snippets/jray-server-proxy.conf; } } # --------------------------------------------------------------------------- # /etc/nginx/snippets/jray-server-proxy.conf # --------------------------------------------------------------------------- # # proxy_http_version 1.1; # proxy_set_header Connection ""; # # proxy_set_header Host $host; # proxy_set_header X-Forwarded-Proto $scheme; # # # $proxy_add_x_forwarded_for appends the real peer on the RIGHT of any header # # the client sent. That is the safe form for this server: client_ip() in # # src/auth.rs reads X-Forwarded-For from the right and walks left past further # # trusted hops, so a client that forges its own entries only pollutes the part # # that is ignored. Do not "harden" this to $remote_addr unless you have exactly # # one proxy layer — with two, overwriting loses the real client. # proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; # # # Longer than JRAY_REQUEST_TIMEOUT_SEC (30 by default) so the application's own # # timeout fires first and returns a real status rather than nginx reporting 504 # # for a request the server was still handling. # proxy_read_timeout 60s;