From ee047624eeb9f435977e94112bbd2d2634e4fd88 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=A9r=C3=A9my=20Lal?= Date: Mon, 29 Jul 2024 18:06:31 +0200 Subject: [PATCH 1/9] domains: do not clobber domains with id --- nginx/conf.d/proxy.conf | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/nginx/conf.d/proxy.conf b/nginx/conf.d/proxy.conf index b1fddeb..5b9f3ee 100644 --- a/nginx/conf.d/proxy.conf +++ b/nginx/conf.d/proxy.conf @@ -161,14 +161,17 @@ init_worker_by_lua_block { delay = 3 else local body = json.decode(res.body) + for key, val in pairs(body.domains) do + if key:find(".", 1, true) ~= nil then + domains:set(key, val) + end + end for key, val in pairs(body.domains) do if key:find(".", 1, true) == nil then local dkey = key .. "." .. rootDomain - if dkey ~= val:sub(2) then + if dkey ~= val:sub(2) and domains:get(dkey) == nil then domains:set(dkey, val) end - else - domains:set(key, val) end end upcache.disabled = false From a1736228255c2ee7fb3a02e6dd64ef4f037a759f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=A9r=C3=A9my=20Lal?= Date: Tue, 6 Aug 2024 10:35:19 +0200 Subject: [PATCH 2/9] 410 is a proxy page --- nginx/location.d/errors.conf | 1 + 1 file changed, 1 insertion(+) diff --git a/nginx/location.d/errors.conf b/nginx/location.d/errors.conf index 59c6dd0..a1af43a 100644 --- a/nginx/location.d/errors.conf +++ b/nginx/location.d/errors.conf @@ -1,3 +1,4 @@ +error_page 410 /.well-known/statics/410.html; error_page 500 /.well-known/statics/500.html; error_page 501 /.well-known/statics/501.html; error_page 502 /.well-known/statics/503.html; From 4b07b73e6d04c1af504719feb4eca174fb1505e4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=A9r=C3=A9my=20Lal?= Date: Tue, 6 Aug 2024 10:35:42 +0200 Subject: [PATCH 3/9] Stop intercepting proxy errors --- nginx/location.d/proxy.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nginx/location.d/proxy.conf b/nginx/location.d/proxy.conf index da44ee0..52e1eba 100644 --- a/nginx/location.d/proxy.conf +++ b/nginx/location.d/proxy.conf @@ -3,7 +3,7 @@ srcache_store_max_size 10m; http2_push_preload on; -proxy_intercept_errors on; +proxy_intercept_errors off; proxy_http_version 1.1; From ab997afca378916f2a56c2d9e69ebd2af53c8c83 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=A9r=C3=A9my=20Lal?= Date: Tue, 6 Aug 2024 11:04:18 +0200 Subject: [PATCH 4/9] readers zone is less limited --- nginx/conf.d/proxy.conf | 1 + nginx/server.d/proxy.conf | 3 +-- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/nginx/conf.d/proxy.conf b/nginx/conf.d/proxy.conf index 5b9f3ee..7f7ae92 100644 --- a/nginx/conf.d/proxy.conf +++ b/nginx/conf.d/proxy.conf @@ -32,6 +32,7 @@ map "$local_proxies$remote_proxies" $limit_host { limit_req_zone $limit_ip zone=perip:10m rate=5r/s; limit_req_zone $limit_host zone=perhost:10m rate=20r/s; +limit_req_zone $limit_host zone=readers:10m rate=1000r/s; limit_req_status 429; # configured upstreams diff --git a/nginx/server.d/proxy.conf b/nginx/server.d/proxy.conf index f32ac0c..ccb821d 100644 --- a/nginx/server.d/proxy.conf +++ b/nginx/server.d/proxy.conf @@ -34,8 +34,7 @@ location /@internal/ { location @get { # move this to access by lua below using lua limit module - limit_req zone=perip burst=20; - limit_req zone=perhost burst=100; + limit_req zone=readers burst=200; include location.d/upcache.conf; include location.d/proxy.conf; From 76cbd700b9a150ff959991415415ba5af30a289c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=A9r=C3=A9my=20Lal?= Date: Tue, 6 Aug 2024 16:24:07 +0200 Subject: [PATCH 5/9] Keep upstream tags when for Accelerated paths --- nginx/server.d/proxy.conf | 1 + nginx/server.d/statics.conf | 3 +++ 2 files changed, 4 insertions(+) diff --git a/nginx/server.d/proxy.conf b/nginx/server.d/proxy.conf index ccb821d..9c4a83f 100644 --- a/nginx/server.d/proxy.conf +++ b/nginx/server.d/proxy.conf @@ -28,6 +28,7 @@ location @notget { location /@internal/ { internal; more_set_headers "X-Upcache-Tag: $upstream_http_x_upcache_tag"; + more_set_headers "X-Upcache-Map: $upstream_http_x_upcache_map"; more_set_headers "Cache-Control: $upstream_http_cache_control"; alias /; } diff --git a/nginx/server.d/statics.conf b/nginx/server.d/statics.conf index 2c0da65..6becb33 100644 --- a/nginx/server.d/statics.conf +++ b/nginx/server.d/statics.conf @@ -1,4 +1,7 @@ location /.well-known/statics/ { + more_set_headers "X-Upcache-Tag: $upstream_http_x_upcache_tag"; + more_set_headers "X-Upcache-Map: $upstream_http_x_upcache_map"; + more_set_headers "Cache-Control: $upstream_http_cache_control"; expires 12h; alias ./statics/; } From 9ec1c78e599293e531be21185a06242df8236156 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=A9r=C3=A9my=20Lal?= Date: Tue, 6 Aug 2024 16:26:03 +0200 Subject: [PATCH 6/9] Increase per host limit --- nginx/conf.d/proxy.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nginx/conf.d/proxy.conf b/nginx/conf.d/proxy.conf index 7f7ae92..63321ab 100644 --- a/nginx/conf.d/proxy.conf +++ b/nginx/conf.d/proxy.conf @@ -32,7 +32,7 @@ map "$local_proxies$remote_proxies" $limit_host { limit_req_zone $limit_ip zone=perip:10m rate=5r/s; limit_req_zone $limit_host zone=perhost:10m rate=20r/s; -limit_req_zone $limit_host zone=readers:10m rate=1000r/s; +limit_req_zone $limit_host zone=readers:10m rate=5000r/s; limit_req_status 429; # configured upstreams From 12bfdd1a9e7d43185fa999b2e43f3eb832204fa4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=A9r=C3=A9my=20Lal?= Date: Tue, 13 Aug 2024 15:09:59 +0200 Subject: [PATCH 7/9] Fix charset types add css --- nginx/conf.d/utf8.conf | 2 ++ 1 file changed, 2 insertions(+) diff --git a/nginx/conf.d/utf8.conf b/nginx/conf.d/utf8.conf index 8a99f70..c628592 100644 --- a/nginx/conf.d/utf8.conf +++ b/nginx/conf.d/utf8.conf @@ -1 +1,3 @@ charset utf-8; +charset_types text/html text/xml text/plain text/vnd.wap.wml +application/javascript application/rss+xml text/css; From 882655b7535b5e61ef6727d256341555b85866a1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=A9r=C3=A9my=20Lal?= Date: Thu, 26 Sep 2024 13:08:58 +0200 Subject: [PATCH 8/9] Adjust limits: high chance internal redir are counted --- nginx/conf.d/proxy.conf | 2 +- nginx/server.d/proxy.conf | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/nginx/conf.d/proxy.conf b/nginx/conf.d/proxy.conf index 63321ab..f8f709a 100644 --- a/nginx/conf.d/proxy.conf +++ b/nginx/conf.d/proxy.conf @@ -32,7 +32,7 @@ map "$local_proxies$remote_proxies" $limit_host { limit_req_zone $limit_ip zone=perip:10m rate=5r/s; limit_req_zone $limit_host zone=perhost:10m rate=20r/s; -limit_req_zone $limit_host zone=readers:10m rate=5000r/s; +limit_req_zone $limit_host zone=readers:10m rate=15000r/s; limit_req_status 429; # configured upstreams diff --git a/nginx/server.d/proxy.conf b/nginx/server.d/proxy.conf index 9c4a83f..867332b 100644 --- a/nginx/server.d/proxy.conf +++ b/nginx/server.d/proxy.conf @@ -4,7 +4,7 @@ include server.d/bypasses[.]conf; location @notget { limit_req zone=perip burst=5 nodelay; - limit_req zone=perhost burst=20; + limit_req zone=perhost burst=100; set $req_body ''; set $req_jwt ''; @@ -35,7 +35,7 @@ location /@internal/ { location @get { # move this to access by lua below using lua limit module - limit_req zone=readers burst=200; + limit_req zone=readers burst=200 nodelay; include location.d/upcache.conf; include location.d/proxy.conf; From f27b4d1c8212b1f514f1b41521cdb9fbc9fe8136 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=A9r=C3=A9my=20Lal?= Date: Thu, 26 Sep 2024 13:12:08 +0200 Subject: [PATCH 9/9] Remove text/html from charset_types --- nginx/conf.d/utf8.conf | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/nginx/conf.d/utf8.conf b/nginx/conf.d/utf8.conf index c628592..771c28c 100644 --- a/nginx/conf.d/utf8.conf +++ b/nginx/conf.d/utf8.conf @@ -1,3 +1,2 @@ charset utf-8; -charset_types text/html text/xml text/plain text/vnd.wap.wml -application/javascript application/rss+xml text/css; +charset_types text/xml text/plain text/vnd.wap.wml application/javascript application/rss+xml text/css;