docs: add Apache HTTP Server reverse proxy guide - #161
Merged
Merged
Conversation
Drive-by fixes in the Nginx/Traefik/Caddy/HAProxy guides (all five locales), noted in the Apache HTTP Server guide PR: - RUSTFS_OBS_LOG_DIRECTORY: /var/log/rustfs/ makes the rootless RustFS container exit at startup with Permission denied; use /logs. - The RustFS v2.x Console lives at /rustfs/console/; the sign-in URL now points there.
Implements rustfs/rustfs#8070. Adds a verified httpd reverse-proxy guide for the S3 API and Console with TLS termination, SigV4-preserving settings, request-body and timeout guidance, a table of settings that do not suit RustFS, and a multi-node balancer configuration. English plus Chinese translation; de/fr/ja follow the section's existing pattern of English copies. Navigation updated in all five locales.
|
@majinghe is attempting to deploy a commit to the overtrue's projects Team on Vercel. A member of the Team first needs to authorize it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements rustfs/rustfs#8070 (Add official Apache HTTP Server reverse proxy documentation).
content/*/developer/integration/reverse-proxy/httpd.md: a complete Apache HTTP Server (httpd) reverse-proxy guide for the RustFS S3 API (:9000) and Console (:9001) behind separate hostnames with TLS termination at Apache.Hostand SigV4 inputs (ProxyPreserveHost On,nocanon,AllowEncodedSlashes NoDecode,X-Forwarded-Proto), presigned URLs, multipart uploads, large/streaming request bodies without unnecessary buffering, timeout guidance (Timeout,ProxyTimeout,RequestReadTimeout,LimitRequestBody), Console WebSocket upgrades (upgrade=websocket), Apache path-rewriting/subpath caveats, a Settings that do not suit RustFS section, and a multi-node balancer variant.meta.json,index.md) updated in all five locales.ensource and fullzhtranslation;de/fr/jafollow the reverse-proxy section's existing pattern (English copies, same as the Nginx/Traefik/Caddy/HAProxy guides).Verification (live on a test server)
The guide's exact artifacts (Dockerfile,
config/rustfs.conf,compose.yaml, as published) were deployed againstrustfs/rustfs:latestand httpd 2.4.68. Only the host HTTP port was mapped to 8088 because the test host's port 80 is occupied by another service; the published guide keeps80:80.docker compose config,httpd -t, and the guide'scurl --failchecks pass for both endpoints; the Console UI loads at/rustfs/console/301 Moved PermanentlywithLocation: https://s3.example.com/cmp; 50 MB multipart upload (ETag ...-7, confirmed with aws CLI and boto3)httpd -t+httpd -k gracefulcertificate reload keeps the service healthyProxyPreserveHost Offand a missingnocanoneach yieldSignatureDoesNotMatch; theAllowEncodedSlashesdefault returns404for%2Fkeys;ProxyErrorOverride Onreplaces RustFS S3 XML errors with Apache HTML pagesContent-Lengthand chunked bodies with zero disk I/O;proxy-sendclspools bodies to disk (a 23 MB temp file observed for a 24 MB body)Settings marked as unsuitable for RustFS (issue request)
The guide marks, with verified symptoms:
ProxyPreserveHost Off(default),ProxyPasswithoutnocanon,AllowEncodedSlashes Off(default), path prefixes such asProxyPass /s3/,ProxyErrorOverride On,SetEnv proxy-sendcl 1/SetEnv force-proxy-request-1.0 1,SetEnv proxy-sendchunked 1, and the deprecatedmod_proxy_wstunnel. RustFS-side limits are marked as well, because no proxy setting can remove them: request bodies arriving asTransfer-Encoding: chunkedare rejected with400 UnexpectedContent; a presigned upload that adds an unsignedContent-Typefails with403 SignatureDoesNotMatch; object keys with empty (//) or dot (.) segments are rejected withInvalidArgument; and the v2.x Console lives under/rustfs/console/.Drive-by fixes (same section, same bug class)
Applied to the sibling reverse-proxy guides in all five locales, with the failure reproduced on the test server first:
RUSTFS_OBS_LOG_DIRECTORY: /var/log/rustfs/->/logs: the rootless RustFS image cannot create/var/log/rustfs/and exits at startup withPermission denied.https://console.example.com->https://console.example.com/rustfs/console/(the v2.x Console path).Flagged, not fixed (separate follow-up recommended): the same log-directory value appears in container contexts outside this section:
installation/container/docker.md(3x),installation/container/podman.md,operations/upgrade/container/index.md(2x), anddeveloper/integration/big-data/iceberg.md/milvus.md(compose style), in every locale. The systemd/env-file usages (installation/linux/*,operations/observability.md) are correct as written.Commands run
npm run docs:check- OK (6/6 checks)npm run build- OK (3235 files generated; zh anchor#多节点后端confirmed in the generated HTML)node .agents/skills/localize-rustfs-docs/scripts/audit-locales.mjs --locales zh,de,fr,ja- reportsUNTRANSLATED_FILEfor de/fr/ja, consistent with the section's pre-existing state (the four sibling guides report identically)