From de148f9c53d78c97f94535cfd885c049c57d833d Mon Sep 17 00:00:00 2001 From: "J. Q." <55899496+jawadqur@users.noreply.github.com> Date: Thu, 17 Sep 2026 10:14:52 -0500 Subject: [PATCH] Configure NGINX for workspace-assets with auth Added NGINX configuration for handling workspace assets with authentication. --- .../qa-mc2dp-helm/values/values.yaml | 43 +++++++++++++++++++ 1 file changed, 43 insertions(+) diff --git a/devplanetv2/dev-environments/qa-mc2dp-helm/values/values.yaml b/devplanetv2/dev-environments/qa-mc2dp-helm/values/values.yaml index 3429aa15..c02af5ac 100644 --- a/devplanetv2/dev-environments/qa-mc2dp-helm/values/values.yaml +++ b/devplanetv2/dev-environments/qa-mc2dp-helm/values/values.yaml @@ -773,6 +773,49 @@ revproxy: proxy_read_timeout 600s; } + # (/api/workspace-assets/remote/), so nginx must forward them to workspace-proxy + # which re-adds the /lw-workspace/proxy/ prefix before forwarding to the container. + location ^~ /api/workspace-assets/remote/lmod { + if ($request_method = 'OPTIONS') { + add_header Access-Control-Allow-Origin $http_origin always; + add_header Access-Control-Allow-Credentials true always; + add_header Access-Control-Allow-Methods "GET, POST, DELETE, OPTIONS" always; + add_header Access-Control-Allow-Headers "Authorization, Content-Type" always; + add_header Content-Length 0; + add_header Content-Type text/plain; + return 204; + } + set $authz_resource "/workspace"; + set $authz_method "access"; + set $authz_service "jupyterhub"; + auth_request_set $remoteUser $upstream_http_REMOTE_USER; + auth_request_set $saved_set_cookie $upstream_http_set_cookie; + auth_request /gen3-authz; + if ($saved_set_cookie != "") { + add_header Set-Cookie $saved_set_cookie always; + } + add_header Cache-Control "no-store"; + proxy_set_header REMOTE_USER $remoteUser; + error_page 403 = @errorworkspace; + + set $upstream http://workspace-proxy-service.$namespace.svc.cluster.local:8080; + rewrite ^/api/workspace-assets/remote/(lmod.*) /$1 break; + proxy_pass $upstream; + proxy_http_version 1.1; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto https; + proxy_set_header X-Forwarded-Host $host; + proxy_set_header X-URL-SCHEME https; + add_header Access-Control-Allow-Origin $http_origin always; + add_header Access-Control-Allow-Credentials true always; + add_header Access-Control-Allow-Methods "GET, POST, DELETE, OPTIONS" always; + add_header Access-Control-Allow-Headers "Authorization, Content-Type" always; + client_max_body_size 0; + proxy_read_timeout 600s; + } + # Remote JupyterLite assets served by workspace-proxy (no auth gate — static files). location ^~ /api/workspace-assets/remote/ { if ($request_method = 'OPTIONS') {