mirror of
https://github.com/kevinveenbirkenbach/computer-playbook.git
synced 2025-08-26 21:45:20 +02:00
Set default buffer level for proxy basic conf, which are necessary for OIDC login
This commit is contained in:
parent
fa46523433
commit
ad7e61e8b1
6
roles/srv-proxy-core/templates/headers/buffers.conf.j2
Normal file
6
roles/srv-proxy-core/templates/headers/buffers.conf.j2
Normal file
@ -0,0 +1,6 @@
|
|||||||
|
# Raise the maximal header size to allow huge headers Keycloak for authentification
|
||||||
|
proxy_buffer_size 16k;
|
||||||
|
proxy_buffers 8 16k;
|
||||||
|
proxy_busy_buffers_size 16k;
|
||||||
|
client_header_buffer_size 8k;
|
||||||
|
large_client_header_buffers 8 32k;
|
@ -1,5 +1,4 @@
|
|||||||
{% set location = location | default("/")%}
|
{% set location = location | default("/")%}
|
||||||
|
|
||||||
location {{location}}
|
location {{location}}
|
||||||
{
|
{
|
||||||
{% if oauth2_proxy_enabled | default(false) | bool %}
|
{% if oauth2_proxy_enabled | default(false) | bool %}
|
||||||
|
@ -1,6 +1,7 @@
|
|||||||
server
|
server
|
||||||
{
|
{
|
||||||
server_name {{ domain }};
|
server_name {{ domain }};
|
||||||
|
{% include 'roles/srv-proxy-core/templates/headers/buffers.conf.j2' %}
|
||||||
|
|
||||||
{% if applications | get_app_conf(application_id, 'features.oauth2', False) %}
|
{% if applications | get_app_conf(application_id, 'features.oauth2', False) %}
|
||||||
{% include 'roles/web-app-oauth2-proxy/templates/endpoint.conf.j2'%}
|
{% include 'roles/web-app-oauth2-proxy/templates/endpoint.conf.j2'%}
|
||||||
|
@ -1,11 +1,3 @@
|
|||||||
{# Include OAuth2 Proxy #}
|
|
||||||
{# Raise the maximal header size. #}
|
|
||||||
{# Keycloak uses huge headers for authentification #}
|
|
||||||
proxy_buffer_size 16k;
|
|
||||||
proxy_buffers 8 16k;
|
|
||||||
proxy_busy_buffers_size 16k;
|
|
||||||
large_client_header_buffers 4 16k;
|
|
||||||
|
|
||||||
# OAuth2-Proxy-Endpoint
|
# OAuth2-Proxy-Endpoint
|
||||||
location /oauth2/ {
|
location /oauth2/ {
|
||||||
proxy_pass http://127.0.0.1:{{ ports.localhost.oauth2_proxy[application_id] }};
|
proxy_pass http://127.0.0.1:{{ ports.localhost.oauth2_proxy[application_id] }};
|
||||||
|
Loading…
x
Reference in New Issue
Block a user