deis / deis/router

Per domain real_ip_header

Open
#308 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
80
Forks
56
PR merge metrics
No merged PRs in 30d

Description

I'm not sure how good/bad idea this is, I'll describe my issue and maybe better solution will came up during discussion.

Configuration:
- Workflow 2.10
- EC2
- TCP ELB with proxy protocol
- Router deployment with `router.deis.io/nginx.useProxyProtocol: true` and proper `router.deis.io/nginx.proxyRealIpCidrs`.

Usually our request are running `client -> elb -> workflow` and it's working fine real ip is present in logs. However some domains (not even whole apps), are running through CloudFlare `client -> cf -> elb -> workflow` and here hell breaks loose :/ we're getting CF ip as remote address. So best option would be per domain `real_ip_header`, is it possible? Each domain is separate server block in nginx.conf, but is application/domain configuration available from nginx.conf template?

Maybe are there some workarounds? Switch to HTTP(S) LB is not an option.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.