Files
ThothII/deploy/dwh-auth/nginx-dwh-location.conf.example
T

29 lines
937 B
Plaintext

# Include these locations inside the HTTPS server that publishes /dwh/.
# The verifier is deliberately reachable only through an internal subrequest.
location = /_check_dwh_key {
internal;
proxy_method GET;
proxy_pass http://unix:/run/dwh-auth/verify.sock:/verify;
proxy_pass_request_body off;
proxy_set_header Content-Length "";
proxy_set_header X-API-Key $http_x_api_key;
}
location @dwh_auth_unavailable {
return 503;
}
location /dwh/ {
limit_req zone=dwh_auth burst=100 nodelay;
auth_request /_check_dwh_key;
auth_request_set $dwh_key_id $upstream_http_x_dwh_key_id;
error_page 500 =503 @dwh_auth_unavailable;
# Never forward the credential. Only the verifier's public identity may
# reach the upstream for audit/rate attribution.
proxy_set_header X-API-Key "";
proxy_set_header X-DWH-Key-ID "";
proxy_set_header Host $host;
proxy_pass http://127.0.0.1:3001;
}