From 367ecd6a93e7be57db28dccc4ca35da38c7b2cbe Mon Sep 17 00:00:00 2001 From: Anthony Ettinger Date: Mon, 28 Sep 2026 18:55:45 +0000 Subject: [PATCH] fix(dev2): raise proxy_buffer_size in the site vhost template Supabase SSR auth sets several chunked sb-*-auth-token cookies on a successful sign-in; nginx's default 4k/8k proxy_buffer_size cannot hold them, logs "upstream sent too big header" and answers 502. Failed logins set no cookies, so they 401 cleanly and the site looks healthy. On 2026-09-28 alone dev2's error log has 955 such ugig.net logins, 34 ugig.net /auth/confirm (email confirmation) clicks, 11 pairux logins and 148 supabase.brisk.news REST calls. 79 of 81 enabled vhosts set no proxy_buffer_size. Proxy blocks are cut from the same template, so they pick this up too. Co-Authored-By: Claude Opus 5.5 (1M context) --- dev2/templates/nginx-vhost.conf | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/dev2/templates/nginx-vhost.conf b/dev2/templates/nginx-vhost.conf index eef5994..68afa7e 100644 --- a/dev2/templates/nginx-vhost.conf +++ b/dev2/templates/nginx-vhost.conf @@ -41,5 +41,12 @@ server { proxy_set_header Connection $connection_upgrade; proxy_read_timeout 300s; proxy_buffering off; + # Response headers are read into proxy_buffer_size even with buffering + # off. Supabase SSR auth sets several chunked sb-*-auth-token cookies on + # login, which overflow the 4k/8k default: nginx logs "upstream sent too + # big header" and every successful sign-in becomes a 502. + proxy_buffer_size 64k; + proxy_buffers 8 64k; + proxy_busy_buffers_size 128k; } }