Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

X-Forwarded headers not handled with Nginx + FPM

オープン
#675 コメント 20 件 リアクション 0 件 担当者 1 名 GitHub で見る

@wrenix がすでに取り組んでいます。

2025年1月24日 から。

評価

この issue はまだ評価されていません。

説明

Describe your Issue

I run Nextcloud behind a Openstack Octavia Loadbalancer (with HTTPS termination), that send X-Forwarded-For, X-Forwarded-Port and X-Forwarded-Proto headers to the Nginx ingress controller.

The LB pool is configured to use the Proxy Protocol in order to preserve client source IP.

Natively, the chart does not allow me to pass these headers from Nginx to PHP-FPM, so I had to create a custom configuration.

Also, the documentation is wrong about trusted_proxies Nextcloud parameter. In our case, it should be equal to ['127.0.0.1'], since the Nextcloud instance and the Nginx webserver are running under the same pod, and since the trafic is forwarded to the PHP upstream on 127.0.0.1 too.

Logs and Errors

Under Nextcloud Administration Area > Admin Settings > Security, the recognized IP is something like ::ffff:10.42.X.X this is the address of the rke2-nginx-ingress-controller, with a helm configuration that is supposed to be correct (I think)

On the Nginx container logs, $http_x_forwarded_for log value is correct, but not transmitted to PHP.

Describe your Environment

  • Kubernetes distribution: RKE2 v1.31

  • Argo-CD Version : v2.13.1+af54ef8

  • Helm Version : v3.15.4+gfa9efb0

  • Helm Chart Version: 6.5.1

  • values.yaml: (issue non relative content is removed)

ingress:
  annotations:
   nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
   nginx.ingress.kubernetes.io/enable-cors: "true"
   nginx.ingress.kubernetes.io/cors-allow-headers: "X-Forwarded-For"
   nginx.ingress.kubernetes.io/proxy-body-size: "0"

nextcloud:
  configs:
    proxy.config.php: |-
      <?php
      $CONFIG = array (
        'trusted_proxies'       => array('127.0.0.1'),
        'forwarded_for_headers' => array('HTTP_X_FORWARDED_FOR')
      );

nginx:
  ipFamilies:
    - IPv4
    - IPv6
  config:
    default: false
    custom: |-

      map $http_x_forwarded_proto $fastcgi_https {
          default "";
          https   "on";
      }

      ...

      server {

          set_real_ip_from  10.42.0.0/16; # My pod IPv4 subnet
          set_real_ip_from  fd00:42::/56; # My pod IPv6 subnet
          real_ip_header    X-Forwarded-For;
          real_ip_recursive on;

          location ~ \.php(?:$|/) {

              fastcgi_param HTTPS $fastcgi_https;
              fastcgi_param SERVER_PORT $http_x_forwarded_port;

              ...

          }

          ...

      }

Additional context, if any

With this solution, you can pass all the headers that I mentionned. Working fine :)
Creating conditions on the Helm chart, it would be great to implement these fixes.

主要言語
Go Template
スター
536
フォーク
316
平均マージ
4日 16時間
マージ済み PR(30日)
2

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

nextcloud/helm のほかの issue

nextcloud/helm の issue をすべて見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。