From 0bfcee97d3dd5022172ba01e734041fe7170e483 Mon Sep 17 00:00:00 2001 From: Chris Lu Date: Wed, 31 Dec 2025 12:15:51 -0800 Subject: [PATCH] Updated S3 Nginx Proxy (markdown) Updated S3 Nginx Proxy (markdown) --- S3-Nginx-Proxy.md | 20 +++++++++++++++++++- 1 file changed, 19 insertions(+), 1 deletion(-) diff --git a/S3-Nginx-Proxy.md b/S3-Nginx-Proxy.md index ee7701c..b8012f3 100644 --- a/S3-Nginx-Proxy.md +++ b/S3-Nginx-Proxy.md @@ -156,4 +156,22 @@ server { ssl on; ssl_certificate /{path_to_ssl_cert}/cert.pem; ssl_certificate_key /{path_to_ssl_cert}/key.pem; -} \ No newline at end of file +} +``` + +## Kubernetes Ingress + +When using Kubernetes Ingress (nginx-ingress controller), you must disable request buffering to prevent signature verification failures on write operations (PUT, POST). Without this setting, nginx removes the `Transfer-Encoding: chunked` header that S3 clients include in their signature, causing 403 Forbidden errors on uploads while reads work fine. + +**Required Helm chart configuration:** + +```yaml +s3: + ingress: + enabled: true + className: nginx + host: s3.example.com + annotations: + nginx.ingress.kubernetes.io/proxy-request-buffering: "off" + nginx.ingress.kubernetes.io/proxy-body-size: "0" +```