Preserving Source IP and webdav request conflict
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 25/100
- issue の種類
- バグ
- 明瞭さ
- 説明が足りない
- 活発さ
- 停滞
- 技術スタック
- apache, helm, kubernetes, nginx
調査の方向性
Issue に示されている ingress annotations と curl OPTIONS リクエストから始め、ingress-nginx が Nextcloud WebDAV エンドポイントへの CORS preflight リクエストをどのように処理するかを追跡します。送信元 IP を保持し、CORS を有効なままにし、OPTIONS をバックエンドに転送し、期待される WebDAV ヘッダーを返す設定を特定できれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Describe your Issue
Hi,
I am trying to set up WebDAV for Zotero, but I am running into an issue with ingress and CORS settings.
- The deployment uses image.flavor: apache.
- I followed the recommended settings: preserve the source IP and support CORS.
- My current ingress annotations:
ingress:
annotations:
nginx.ingress.kubernetes.io/enable-cors: "true"
nginx.ingress.kubernetes.io/cors-allow-headers: "X-Forwarded-For"
With this config, when Zotero or I use an OPTIONS request (for WebDAV capability check), the response is processed directly by the ingress (HTTP 204), and the request does not reach the backend (Nextcloud).
As a result, Zotero cannot detect the WebDAV capabilities correctly, since the WebDAV-specific headers (like DAV:) are not provided as expected. Though I can correctly synchronize webdav files, zotero must firstly do this step for checking before synchronizing.
Here is the curl test:
···bash
curl -i -X OPTIONS https://NEXTCLOUD-URL/remote.php/dav/files/USERNAME
···
Output
HTTP/2 204
...
access-control-allow-methods: GET, PUT, POST, DELETE, PATCH, OPTIONS, PROPFIND, PROPPATCH, COPY, MOVE, LOCK, UNLOCK
access-control-allow-headers: X-Forwarded-For
...
Question:
How should I configure ingress-nginx so that:
-
CORS is enabled,
-
Source IP is preserved,
-
AND the OPTIONS/WebDAV capability requests are actually forwarded to the backend (not intercepted by the ingress), so the WebDAV headers are correctly returned?
Any help is much appreciated!
Describe your Environment
-
Kubernetes distribution: rke2
-
Helm Version (or App that manages helm): it's independent to helm version
-
Helm Chart Version: it's independent to helm chart version
-
values.yaml:
# paste your values.yaml (anonymize any sensitive data)
Additional context, if any
- 主要言語
- Go Template
- スター
- 536
- フォーク
- 316
- 平均マージ
- 4日 16時間
- マージ済み PR(30日)
- 2
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
nextcloud/helm のほかの issue
-
No native support for REDIS_USER enviroment var対応中かも @jholmes802 が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
-
nextcloud.openmetrics.allowedClients is silently ignored unless nextcloud.configs is set対応中かも @JanWelker が 17 日前に担当しました。 オープン
難易度 3/5 1〜2日 初心者へのやさしさ 78/100
-
External Redis not working: redis-session.ini: Permission denied対応中かも @antoinetran が 22 日前に担当しました。 オープン
難易度 3/5 1〜2日 初心者へのやさしさ 55/100
似ている issue
-
Bump .cicd to wamp-cicd 4c2f9ac: `just land` refuses open A18 decisions, `just where` lists themオープン
難易度 1/5 1時間未満 初心者へのやさしさ 84/100
crossbario/txaio#241 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
flathub/com.snes9x.Snes9x#129 ·
-
enhancement
難易度 2/5 1〜3時間 初心者へのやさしさ 92/100
alunduil/projects-v2-sync#14 ·
-
`helios / deploy`: switch zone wait in `deploy.sh` has almost no headroom over healthy startup times対応中かも このイシューにリンクされたプルリクエストがオープン中、またはマージ済みです。 オープンTest Flake
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
oxidecomputer/omicron#11453 ·
メンテナーはふだん 1 日以内に返信
-
Website: the docs site's own service worker can't install (navigateFallback "/" isn't precached)オープンbug
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
components-web-app/docs#173 ·