From 60be656cf1dc6158b74d8eb642a2f7dac78c1dc0 Mon Sep 17 00:00:00 2001 From: rameen Date: Tue, 1 Sep 2026 12:40:26 +0330 Subject: [PATCH] Allow Gitea registry pushes through gitea.wixur.ir: nginx 50M body limit 413s Docker layers. --- .gitea/workflows/prod-tag-deploy.yml | 1 + .gitea/workflows/registry-build-deploy.yml | 5 +- infrastructure/STAGING-DEPLOY.md | 6 +- infrastructure/nginx/windows-edge-http.conf | 12 +++- .../nginx/windows-gitea.wixur.snippet.conf | 58 +++++++++++++++++++ 5 files changed, 78 insertions(+), 4 deletions(-) create mode 100644 infrastructure/nginx/windows-gitea.wixur.snippet.conf diff --git a/.gitea/workflows/prod-tag-deploy.yml b/.gitea/workflows/prod-tag-deploy.yml index f94e37c..e01704b 100644 --- a/.gitea/workflows/prod-tag-deploy.yml +++ b/.gitea/workflows/prod-tag-deploy.yml @@ -8,6 +8,7 @@ # # Variables: # REGISTRY_HOST Windows Docker push host, e.g. host.docker.internal:3000 +# (not gitea.wixur.ir unless nginx client_max_body_size 0) # REGISTRY_OWNER Gitea user/org for packages # CLONE_HOST git clone, e.g. 127.0.0.1:3000 # PROD_PUBLIC_BASE_URL https://nudentic.ir (no trailing slash) diff --git a/.gitea/workflows/registry-build-deploy.yml b/.gitea/workflows/registry-build-deploy.yml index a14c67f..cfd05cd 100644 --- a/.gitea/workflows/registry-build-deploy.yml +++ b/.gitea/workflows/registry-build-deploy.yml @@ -4,7 +4,10 @@ # Production (nudentic.ir / git tags): .gitea/workflows/prod-tag-deploy.yml — this file is Windows staging only. # # Repository Variables (Settings → Actions → Variables): -# REGISTRY_HOST Docker registry host:port (no http/https). Windows Docker Desktop → host.docker.internal:3000 +# REGISTRY_HOST Docker registry host:port (no http/https). +# Windows Docker Desktop → host.docker.internal:3000 +# Do NOT use gitea.wixur.ir unless Windows nginx for that +# host has client_max_body_size 0 — Docker layer PUTs 413 otherwise. # REGISTRY_OWNER Gitea user or org that owns the packages # PUBLIC_BASE_URL URL users open in the browser, e.g. http://wixur.ir (no trailing slash, no :8088) # NEXT_PUBLIC_SENTRY_DSN GlitchTip frontend project DSN (https://…@errors.wixur.ir/…) diff --git a/infrastructure/STAGING-DEPLOY.md b/infrastructure/STAGING-DEPLOY.md index ab1fc1d..8dcecac 100644 --- a/infrastructure/STAGING-DEPLOY.md +++ b/infrastructure/STAGING-DEPLOY.md @@ -163,7 +163,7 @@ Rules: | Name | Example | Notes | |------|---------|--------| -| `REGISTRY_HOST` | `host.docker.internal:3000` | **Windows + Docker Desktop:** Docker runs in a Linux VM — `127.0.0.1` is the VM, not Gitea. Use `host.docker.internal:3000`. Gitea `ROOT_URL` should match this so registry login from CI works. Browsers and the Linux VPS use `http://wixur.ir:3000`. | +| `REGISTRY_HOST` | `host.docker.internal:3000` | **Windows + Docker Desktop:** Docker runs in a Linux VM — `127.0.0.1` is the VM, not Gitea. Use `host.docker.internal:3000`. Gitea `ROOT_URL` should match this so registry login from CI works. Browsers can use `http://wixur.ir:3000` or `https://gitea.wixur.ir`. **Do not** set this to `gitea.wixur.ir` unless that HTTPS proxy allows unlimited body size (see 413 below). | | `REGISTRY_OWNER` | `admin` | Gitea user/org owning packages | | `PUBLIC_BASE_URL` | `https://wixur.ir` | How **users** open staging (HTTPS on 443). No trailing slash. | | `DEPLOY_SECRETS_DIR` | `C:/dyolink/secrets` | Forward slashes OK on Windows | @@ -299,6 +299,7 @@ On the Windows host, from repo `infrastructure/`: | `no matching online runner with label` | Runner **offline** → start `act_runner.exe daemon`. Or wrong **runner level** → re-register with token from **Site Administration → Actions → Runners** or **repo → Settings → Actions → Runners** (not user profile). Confirm runner appears on **repo** Runners page as Online. | | Runner can't register on public IP | Use `http://127.0.0.1:3000` for `--instance` | | Variable name rejected in Gitea | No `GITEA_*` / `GITHUB_*` prefixes; use `CLONE_HOST` | +| `413 Request Entity Too Large` on `docker push` to `https://gitea.wixur.ir/v2/…/blobs/uploads` | Nginx (or Cloudflare) in front of Gitea is rejecting the image layer. **Fix the proxy** (then `nginx -s reload`): in the `server { server_name gitea.wixur.ir; }` block set `client_max_body_size 0;` and `proxy_request_buffering off;` — snippet: [`nginx/windows-gitea.wixur.snippet.conf`](nginx/windows-gitea.wixur.snippet.conf). **Or skip the proxy:** set `REGISTRY_HOST=host.docker.internal:3000` (and Gitea `ROOT_URL`) so CI pushes to `:3000`. If the hostname is orange-clouded on Cloudflare, grey-cloud it (free plan caps uploads at 100MB). | | `docker login` connection refused on `127.0.0.1:3000` | **Docker Desktop on Windows:** set `REGISTRY_HOST=host.docker.internal:3000`, add it to insecure-registries, set Gitea `ROOT_URL=http://host.docker.internal:3000/`. Keep `CLONE_HOST=127.0.0.1:3000` for git. | | `docker login` / push denied, redirect to public IP | Set Gitea `ROOT_URL` to a host Docker can reach (`host.docker.internal:3000` on Windows Docker Desktop). | | `server gave HTTP response to HTTPS client` | Add registry host to Docker **insecure-registries**, restart Docker | @@ -334,7 +335,8 @@ docker logs dyolink_frontend_staging --tail 50 | `infrastructure/database.staging.env.example` | Postgres secrets template | | `infrastructure/backend.staging.env.example` | API secrets template | | `infrastructure/nginx/http-only.conf` | HTTP reverse proxy **inside Docker** staging | -| `infrastructure/nginx/windows-edge-http.conf` | Windows **host** nginx on port 80 → 18088 | +| `infrastructure/nginx/windows-edge-http.conf` | Windows **host** nginx on port 80/443 → 18088 | +| `infrastructure/nginx/windows-gitea.wixur.snippet.conf` | Windows nginx vhost for `https://gitea.wixur.ir` (unlimited body — Docker push) | --- diff --git a/infrastructure/nginx/windows-edge-http.conf b/infrastructure/nginx/windows-edge-http.conf index 36044a1..7c5f23b 100644 --- a/infrastructure/nginx/windows-edge-http.conf +++ b/infrastructure/nginx/windows-edge-http.conf @@ -26,7 +26,9 @@ http { sendfile on; keepalive_timeout 65; - client_max_body_size 50M; + # Unlimited at http{} so a gitea.wixur.ir vhost can inherit it (Docker layers + # 413 with 50M). App server blocks below cap uploads at 50M. + client_max_body_size 0; # Shared proxy to Docker staging map $http_upgrade $connection_upgrade { @@ -39,6 +41,8 @@ http { listen [::]:80 default_server; server_name wixur.ir www.wixur.ir localhost 127.0.0.1; + client_max_body_size 50M; + location / { proxy_pass http://127.0.0.1:18088; proxy_http_version 1.1; @@ -62,6 +66,8 @@ http { ssl_certificate_key ssl/wixur-key.pem; ssl_protocols TLSv1.2 TLSv1.3; + client_max_body_size 50M; + location / { proxy_pass http://127.0.0.1:18088; proxy_http_version 1.1; @@ -75,4 +81,8 @@ http { proxy_connect_timeout 300; } } + + # Gitea + container registry (https://gitea.wixur.ir). Optional include — + # copy windows-gitea.wixur.snippet.conf next to this file and uncomment: + # include windows-gitea.wixur.snippet.conf; } diff --git a/infrastructure/nginx/windows-gitea.wixur.snippet.conf b/infrastructure/nginx/windows-gitea.wixur.snippet.conf new file mode 100644 index 0000000..8de5631 --- /dev/null +++ b/infrastructure/nginx/windows-gitea.wixur.snippet.conf @@ -0,0 +1,58 @@ +# Fastest fix if you already have a gitea.wixur.ir server { } block: add only +# client_max_body_size 0; +# proxy_request_buffering off; +# inside that server (or its location /), then nginx -t && nginx -s reload. +# Do not add a second server_name gitea.wixur.ir — duplicate listen/ssl will fail. +# +# Full vhost (only if that host is not already in nginx.conf): paste inside http { } +# of C:\tools\nginx-1.29.5\conf\nginx.conf. Needs the $connection_upgrade map from +# windows-edge-http.conf. +# +# Certs: keep the ssl_certificate paths you already use for gitea.wixur.ir +# (the names below are placeholders). +# +# After save: nginx -t then nginx -s reload + +server { + listen 80; + listen [::]:80; + server_name gitea.wixur.ir; + + location /.well-known/acme-challenge/ { + root html; + } + + location / { + return 301 https://$host$request_uri; + } +} + +server { + listen 443 ssl; + listen [::]:443 ssl; + server_name gitea.wixur.ir; + + ssl_certificate ssl/gitea-chain.pem; + ssl_certificate_key ssl/gitea-key.pem; + ssl_protocols TLSv1.2 TLSv1.3; + + # 0 = unlimited (Docker registry blob PUT) + client_max_body_size 0; + client_body_timeout 600s; + + location / { + proxy_pass http://127.0.0.1:3000; + proxy_http_version 1.1; + proxy_request_buffering off; + proxy_buffering off; + proxy_set_header Host $host; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection $connection_upgrade; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_read_timeout 600; + proxy_connect_timeout 60; + proxy_send_timeout 600; + } +}