Skip to content

Commit deec8a0

Browse files
ralyodioclaude
andauthored
fix(ops): raise nginx proxy_buffer_size for the app and Supabase gateway (#330)
Supabase SSR auth sets several chunked sb-*-auth-token cookies on sign-in; they overflow nginx's default proxy_buffer_size, which logs "upstream sent too big header" and turns a successful login into a 502. Same fix as the rest of dev2 (cli-tools #112). Applied to the live vhost in place, since certbot owns its TLS lines. Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
1 parent a21c1a3 commit deec8a0

1 file changed

Lines changed: 8 additions & 0 deletions

File tree

‎ops/selfhost/server/nginx-crawlproof.conf‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,10 @@ server {
4747
proxy_send_timeout 300s;
4848
proxy_read_timeout 300s;
4949
proxy_buffering off;
50+
# Supabase auth cookies overflow the default header buffer (502).
51+
proxy_buffer_size 64k;
52+
proxy_buffers 8 64k;
53+
proxy_busy_buffers_size 128k;
5054
}
5155
}
5256

@@ -86,5 +90,9 @@ server {
8690
proxy_send_timeout 3600s;
8791
proxy_read_timeout 3600s;
8892
proxy_buffering off;
93+
# Supabase auth cookies overflow the default header buffer (502).
94+
proxy_buffer_size 64k;
95+
proxy_buffers 8 64k;
96+
proxy_busy_buffers_size 128k;
8997
}
9098
}

0 commit comments

Comments
 (0)