Preserving Source IP and webdav request conflict
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 25/100
- Issue 类型
- 缺陷
- 描述清晰度
- 需要澄清
- 活跃度
- 停滞
- 技术栈
- apache, helm, kubernetes, nginx
调研方向
先从 issue 中展示的 ingress annotations 和 curl OPTIONS 请求开始,然后跟踪 ingress-nginx 如何处理发往 Nextcloud WebDAV 端点的 CORS 预检请求。完成的标准是确定一种配置:保留源 IP、保持 CORS 启用、将 OPTIONS 转发到后端,并返回预期的 WebDAV 标头。
由索引模型根据 Issue 内容生成。
描述
Describe your Issue
Hi,
I am trying to set up WebDAV for Zotero, but I am running into an issue with ingress and CORS settings.
- The deployment uses image.flavor: apache.
- I followed the recommended settings: preserve the source IP and support CORS.
- My current ingress annotations:
ingress:
annotations:
nginx.ingress.kubernetes.io/enable-cors: "true"
nginx.ingress.kubernetes.io/cors-allow-headers: "X-Forwarded-For"
With this config, when Zotero or I use an OPTIONS request (for WebDAV capability check), the response is processed directly by the ingress (HTTP 204), and the request does not reach the backend (Nextcloud).
As a result, Zotero cannot detect the WebDAV capabilities correctly, since the WebDAV-specific headers (like DAV:) are not provided as expected. Though I can correctly synchronize webdav files, zotero must firstly do this step for checking before synchronizing.
Here is the curl test:
···bash
curl -i -X OPTIONS https://NEXTCLOUD-URL/remote.php/dav/files/USERNAME
···
Output
HTTP/2 204
...
access-control-allow-methods: GET, PUT, POST, DELETE, PATCH, OPTIONS, PROPFIND, PROPPATCH, COPY, MOVE, LOCK, UNLOCK
access-control-allow-headers: X-Forwarded-For
...
Question:
How should I configure ingress-nginx so that:
-
CORS is enabled,
-
Source IP is preserved,
-
AND the OPTIONS/WebDAV capability requests are actually forwarded to the backend (not intercepted by the ingress), so the WebDAV headers are correctly returned?
Any help is much appreciated!
Describe your Environment
-
Kubernetes distribution: rke2
-
Helm Version (or App that manages helm): it's independent to helm version
-
Helm Chart Version: it's independent to helm chart version
-
values.yaml:
# paste your values.yaml (anonymize any sensitive data)
Additional context, if any
- 主要语言
- Go Template
- 星标
- 536
- 派生
- 316
- 平均合并
- 4 天 16 小时
- 30 天内合并 PR
- 2
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
nextcloud/helm 的其他 Issue
-
No native support for REDIS_USER enviroment var可能已有人在做 @jholmes802 于 2 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 70/100
-
难度 2/5 1-3 小时 新手友好度 72/100
-
难度 2/5 1-3 小时 新手友好度 68/100
-
nextcloud.openmetrics.allowedClients is silently ignored unless nextcloud.configs is set可能已有人在做 @JanWelker 于 18 天前认领。 未关闭
难度 3/5 1-2 天 新手友好度 78/100
-
External Redis not working: redis-session.ini: Permission denied可能已有人在做 @antoinetran 于 23 天前认领。 未关闭
难度 3/5 1-2 天 新手友好度 55/100
相似的 Issue
-
bug
难度 2/5 1-3 小时 新手友好度 72/100
mishraprafful/multihull#147 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
paperclipai/paperclip#15751 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 65/100
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 75/100
维护者通常 1 天内回复
-
good first issue need help packaging
难度 2/5 1-3 小时 新手友好度 66/100
phonology024/babelscribe#23 ·