Files
homelab-frontend/tasks/1.7-body-size-caps.md
T
Story Crater BotandClaude Opus 5 058f11cf2b
CI / Test (push) Canceled after 0s
CI / Vet (push) Canceled after 0s
CI / Build (push) Canceled after 0s
CI / Security (govulncheck) (push) Canceled after 0s
chore: initial commit of Go API gateway
Baseline for the Kong replacement on api.riotpiao.com. Brings the working
tree under version control for the first time: gateway source, the task
board that drives the agent runs, test fixtures, and K8s manifests.

Anchor the gateway ignore rule to the repo root. Unanchored, "gateway"
also matched the cmd/gateway/ source directory, so the program entrypoint
was excluded from every commit.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-19 20:54:34 -07:00

1.3 KiB

1.7 — Per-route body size caps (RED)

Phase: 1 — Proxy core Stage: RED Depends on: 0.2, 1.1

  • Each route enforces its own configured maximum request body size
  • A body over the cap is rejected with 413 and a body the upstream never sees
  • Rejection happens while reading, not after buffering the whole body into memory
  • A request with a lying or absent Content-Length is still capped by bytes actually read
  • A body at exactly the cap is accepted and proxied intact
  • The rejection is logged with a reason distinguishing it from other rejections
  • No global default cap silently applies to a route that failed to declare one — that is a config error, per 0.2

nginx in front is configured with proxy-body-size: 0, meaning it enforces no limit at all, so the gateway is the only place a cap exists. Embedding and rerank callers can send large batches legitimately, which is why the cap is per route rather than one number for the whole surface.

Verify

go test ./internal/proxy/... -run TestBodySizeCap -v
# expected: passes — a body one byte over the route cap returns 413 and the stub
# upstream records zero requests; a body exactly at the cap returns the stub's 200