Repository navigation
Conversation
Integration TestsTest summary after running integration tests
Test summary after rerunning failed integration tests
Please find the detailed integration test report here Please find the detailed integration test report after rerunning failed tests here Please find the Github Action logs here |
Failure AnalysisPlease find the detailed test analysis report here |
Integration TestsTest summary after running integration tests
Test summary after rerunning failed integration tests
Please find the detailed integration test report here Please find the detailed integration test report after rerunning failed tests here Please find the Github Action logs here |
Failure AnalysisPlease find the detailed test analysis report here |
| # workspace-assets/remote/lmod routing | ||
| location ^~ /api/workspace-assets/remote/lmod { | ||
| if ($request_method = 'OPTIONS') { | ||
| add_header Access-Control-Allow-Origin $http_origin always; | ||
| add_header Access-Control-Allow-Credentials true always; | ||
| add_header Access-Control-Allow-Methods "GET, POST, DELETE, OPTIONS" always; | ||
| add_header Access-Control-Allow-Headers "Authorization, Content-Type" always; | ||
| add_header Content-Length 0; | ||
| add_header Content-Type text/plain; | ||
| return 204; | ||
| } | ||
| set $authz_resource "/workspace"; | ||
| set $authz_method "access"; | ||
| set $authz_service "jupyterhub"; | ||
| auth_request_set $remoteUser $upstream_http_REMOTE_USER; | ||
| auth_request_set $saved_set_cookie $upstream_http_set_cookie; | ||
| auth_request /gen3-authz; | ||
| if ($saved_set_cookie != "") { | ||
| add_header Set-Cookie $saved_set_cookie always; | ||
| } | ||
| add_header Cache-Control "no-store"; | ||
| proxy_set_header REMOTE_USER $remoteUser; | ||
| error_page 403 = @errorworkspace; | ||
|
|
||
| set $upstream http://workspace-proxy-service.$namespace.svc.cluster.local:8080; | ||
| rewrite ^/api/workspace-assets/remote/(lmod.*) /$1 break; | ||
| proxy_pass $upstream; | ||
| proxy_http_version 1.1; | ||
| proxy_set_header Host $host; | ||
| proxy_set_header X-Real-IP $remote_addr; | ||
| proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | ||
| proxy_set_header X-Forwarded-Proto https; | ||
| proxy_set_header X-Forwarded-Host $host; | ||
| proxy_set_header X-URL-SCHEME https; | ||
| add_header Access-Control-Allow-Origin $http_origin always; | ||
| add_header Access-Control-Allow-Credentials true always; | ||
| add_header Access-Control-Allow-Methods "GET, POST, DELETE, OPTIONS" always; | ||
| add_header Access-Control-Allow-Headers "Authorization, Content-Type" always; | ||
| client_max_body_size 0; | ||
| proxy_read_timeout 600s; | ||
| } | ||
|
|
There was a problem hiding this comment.
this block seems generic and I'm wondering if it should move to gen3-helm instead.
CC @jawadqur
There was a problem hiding this comment.
We should! This is tech debt we're accruing and adding to gen3-helm tested and easily configurable will be very necessary!
There was a problem hiding this comment.
yup I think this configuration should go right around here once:
https://github.com/uc-cdis/gen3-helm/blob/master/helm/jeg/values.yaml
There was a problem hiding this comment.
Also fun security issue here that I think is legitimate, thread in slack:
https://cdis.slack.com/files/U620MQQAK/F0C4YTES9J9/screenshot_2026-09-28_at_5.56.51___pm.png
if X-Gen3-User-ID header is modifiable then the revproxy->multiheaded-workpsace-proxy has a potential to shuffle.
|
related PR: #2116 |
Integration TestsFailed to Prepare CI environment Please find the Github Action logs here |
Integration TestsFailed to Prepare CI environment Please find the Github Action logs here |
Integration TestsTest summary after running integration tests
Test summary after rerunning failed integration tests
Please find the detailed integration test report here Please find the detailed integration test report after rerunning failed tests here Please find the Github Action logs here |
Failure AnalysisPlease find the detailed test analysis report here |
Integration TestsTest summary after running integration tests
Test summary after rerunning failed integration tests
Please find the detailed integration test report here Please find the detailed integration test report after rerunning failed tests here Please find the Github Action logs here |
Failure AnalysisPlease find the detailed test analysis report here |
Integration TestsTest summary after running integration tests
Test summary after rerunning failed integration tests
Please find the detailed integration test report here Please find the detailed integration test report after rerunning failed tests here Please find the Github Action logs here |
Failure AnalysisPlease find the detailed test analysis report here |
Integration TestsTest summary after running integration tests
Test summary after rerunning failed integration tests
Please find the detailed integration test report here Please find the detailed integration test report after rerunning failed tests here Please find the Github Action logs here |
Failure AnalysisPlease find the detailed test analysis report here |
Integration TestsTest summary after running integration tests
Test summary after rerunning failed integration tests
Please find the detailed integration test report here Please find the detailed integration test report after rerunning failed tests here Please find the Github Action logs here |
Failure AnalysisPlease find the detailed test analysis report here |
https://ctds-planx.atlassian.net/browse/MC2DP-1134
Environments
MC2DP Prod
Description of changes