fix(dev2): raise proxy_buffer_size in the site vhost template - #112
Merged
Merged
Conversation
Supabase SSR auth sets several chunked sb-*-auth-token cookies on a successful sign-in; nginx's default 4k/8k proxy_buffer_size cannot hold them, logs "upstream sent too big header" and answers 502. Failed logins set no cookies, so they 401 cleanly and the site looks healthy. On 2026-09-28 alone dev2's error log has 955 such ugig.net logins, 34 ugig.net /auth/confirm (email confirmation) clicks, 11 pairux logins and 148 supabase.brisk.news REST calls. 79 of 81 enabled vhosts set no proxy_buffer_size. Proxy blocks are cut from the same template, so they pick this up too. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ThreatCrush Security Scan25 finding(s) HIGH/CRITICAL: 4 | MEDIUM: 12 | LOW: 9
Snippets are redacted; ThreatCrush never prints matched credential material. |
ralyodio
added a commit
that referenced
this pull request
Sep 28, 2026
… kit (#113) Two vhosts could not be re-rendered, so they missed the proxy_buffer_size fix (#112): - r4ck.dev carries a hand-added ThreatCrush x402 paywall location that a re-render would delete. sites.d may now set nginx_locations (raw location blocks, __APP_PORT__ substituted), inserted ahead of the catch-all; the paywall block moves into sites.d/r4ck.dev.json. - bittorrented.com is not a Railway site, so it has no sites.json row and `dev2-site vhost` died "unknown site". site() now falls back to a sites.d file that names itself, and nginx_app: false renders only the proxies (its app runs on a droplet; only supabase.bittorrented.com is here). Proxy tuning moved into proxy_tuned(). Dry run against dev2: 74 vhosts render byte-identical to live; these two differ only by the buffer lines. Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Every successful Supabase login behind a dev2 vhost 502s: nginx
upstream sent too big header(sb-*-auth-token Set-Cookie chunks exceed the default proxy_buffer_size; buffering off does not change that). Addsproxy_buffer_size 64k; proxy_buffers 8 64k; proxy_busy_buffers_size 128k;to the vhost template (also inherited by proxy blocks such as supabase.).Evidence from /var/log/nginx/error.log on 2026-09-28: ugig.net POST /api/auth/login x955, ugig.net GET /auth/confirm x34, www.pairux.com POST /api/auth/login x11, supabase.brisk.news GET /rest/v1/short_urls x148.
After merge, live vhosts need re-rendering (backs up to .bak-NNN, runs nginx -t, reloads):
(ideally every site, since 79/81 vhosts lack the directive).
🤖 Generated with Claude Code