X-Forwarded headers not handled with Nginx + FPM
@wrenix がすでに取り組んでいます。
2025年1月24日 から。
評価
この issue はまだ評価されていません。
説明
Describe your Issue
I run Nextcloud behind a Openstack Octavia Loadbalancer (with HTTPS termination), that send X-Forwarded-For, X-Forwarded-Port and X-Forwarded-Proto headers to the Nginx ingress controller.
The LB pool is configured to use the Proxy Protocol in order to preserve client source IP.
Natively, the chart does not allow me to pass these headers from Nginx to PHP-FPM, so I had to create a custom configuration.
Also, the documentation is wrong about trusted_proxies Nextcloud parameter. In our case, it should be equal to ['127.0.0.1'], since the Nextcloud instance and the Nginx webserver are running under the same pod, and since the trafic is forwarded to the PHP upstream on 127.0.0.1 too.
Logs and Errors
Under Nextcloud Administration Area > Admin Settings > Security, the recognized IP is something like ::ffff:10.42.X.X this is the address of the rke2-nginx-ingress-controller, with a helm configuration that is supposed to be correct (I think)
On the Nginx container logs, $http_x_forwarded_for log value is correct, but not transmitted to PHP.
Describe your Environment
-
Kubernetes distribution: RKE2 v1.31
-
Argo-CD Version : v2.13.1+af54ef8
-
Helm Version : v3.15.4+gfa9efb0
-
Helm Chart Version: 6.5.1
-
values.yaml: (issue non relative content is removed)
ingress:
annotations:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/enable-cors: "true"
nginx.ingress.kubernetes.io/cors-allow-headers: "X-Forwarded-For"
nginx.ingress.kubernetes.io/proxy-body-size: "0"
nextcloud:
configs:
proxy.config.php: |-
<?php
$CONFIG = array (
'trusted_proxies' => array('127.0.0.1'),
'forwarded_for_headers' => array('HTTP_X_FORWARDED_FOR')
);
nginx:
ipFamilies:
- IPv4
- IPv6
config:
default: false
custom: |-
map $http_x_forwarded_proto $fastcgi_https {
default "";
https "on";
}
...
server {
set_real_ip_from 10.42.0.0/16; # My pod IPv4 subnet
set_real_ip_from fd00:42::/56; # My pod IPv6 subnet
real_ip_header X-Forwarded-For;
real_ip_recursive on;
location ~ \.php(?:$|/) {
fastcgi_param HTTPS $fastcgi_https;
fastcgi_param SERVER_PORT $http_x_forwarded_port;
...
}
...
}
Additional context, if any
With this solution, you can pass all the headers that I mentionned. Working fine :)
Creating conditions on the Helm chart, it would be great to implement these fixes.
- 主要言語
- Go Template
- スター
- 536
- フォーク
- 316
- 平均マージ
- 4日 16時間
- マージ済み PR(30日)
- 2
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
nextcloud/helm のほかの issue
-
No native support for REDIS_USER enviroment var対応中かも @jholmes802 が 1 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
-
nextcloud.openmetrics.allowedClients is silently ignored unless nextcloud.configs is set対応中かも @JanWelker が 18 日前に担当しました。 オープン
難易度 3/5 1〜2日 初心者へのやさしさ 78/100
-
External Redis not working: redis-session.ini: Permission denied対応中かも @antoinetran が 22 日前に担当しました。 オープン
難易度 3/5 1〜2日 初心者へのやさしさ 55/100