From 83d087860c46bafb8d7f7ad2ca7a584fde2f36a3 Mon Sep 17 00:00:00 2001 From: Pierre Le Fevre Date: Sat, 22 Nov 2025 10:16:22 +0100 Subject: [PATCH] fix: disable Axum default body size limit for large blob uploads --- caddy/Caddyfile | 16 ++++++++++++++-- src/main.rs | 2 ++ 2 files changed, 16 insertions(+), 2 deletions(-) diff --git a/caddy/Caddyfile b/caddy/Caddyfile index 3b9d979..a8aa732 100644 --- a/caddy/Caddyfile +++ b/caddy/Caddyfile @@ -1,9 +1,21 @@ # Replace 'your-registry.example.com' with your real domain # Caddy will automatically obtain TLS certificates for this domain via Let's Encrypt -# and reverse-proxy traffic to the `grain` service on port 8888 (same Docker network) +# and reverse-proxy traffic to the grain service on port 8888 (same Docker network) +# Note: Caddy passes the Authorization header through by default - do NOT use header_up +# directives as they can cause literal placeholder strings to be passed instead of values your-registry.example.com { - reverse_proxy grain:8888 + # Allow large uploads for container images + request_body { + max_size 0 + } + + reverse_proxy grain:8888 { + # Rewrite Location headers from internal address to public HTTPS URL + header_up Host {host} + header_down Location http://0.0.0.0:8888 https://your-registry.example.com + } + log { output file /var/log/caddy/grain_access.log } diff --git a/src/main.rs b/src/main.rs index 4bc481d..427f498 100644 --- a/src/main.rs +++ b/src/main.rs @@ -1,6 +1,7 @@ use std::sync::Arc; use axum::{ + extract::DefaultBodyLimit, routing::{delete, get, head, patch, post, put}, Router, }; @@ -109,6 +110,7 @@ async fn main() { .route("/{*path}", patch(meta::catch_all_patch)) .route("/{*path}", delete(meta::catch_all_delete)) .with_state(shared_state) + .layer(DefaultBodyLimit::disable()) // Allow unlimited body size for blob uploads .layer(axum::middleware::from_fn(middleware::track_metrics)) .layer(CorsLayer::permissive()) .merge( -- 2.51.2