diff --git a/S3-Nginx-Proxy.md b/S3-Nginx-Proxy.md index ee7701c..b8012f3 100644 --- a/S3-Nginx-Proxy.md +++ b/S3-Nginx-Proxy.md @@ -156,4 +156,22 @@ server { ssl on; ssl_certificate /{path_to_ssl_cert}/cert.pem; ssl_certificate_key /{path_to_ssl_cert}/key.pem; -} \ No newline at end of file +} +``` + +## Kubernetes Ingress + +When using Kubernetes Ingress (nginx-ingress controller), you must disable request buffering to prevent signature verification failures on write operations (PUT, POST). Without this setting, nginx removes the `Transfer-Encoding: chunked` header that S3 clients include in their signature, causing 403 Forbidden errors on uploads while reads work fine. + +**Required Helm chart configuration:** + +```yaml +s3: + ingress: + enabled: true + className: nginx + host: s3.example.com + annotations: + nginx.ingress.kubernetes.io/proxy-request-buffering: "off" + nginx.ingress.kubernetes.io/proxy-body-size: "0" +```