X-Git-Url: https://git.arvados.org/arvados.git/blobdiff_plain/9869b312368e2dd7a7156c7fbd53714f73a77ead..27ba0e2e0733ddaeb7437dc4194f684306636635:/doc/install/install-api-server.html.textile.liquid diff --git a/doc/install/install-api-server.html.textile.liquid b/doc/install/install-api-server.html.textile.liquid index c7303bbba2..4c9f168e82 100644 --- a/doc/install/install-api-server.html.textile.liquid +++ b/doc/install/install-api-server.html.textile.liquid @@ -48,8 +48,6 @@ h3. Tokens
    SystemRootToken: "$system_root_token"
     ManagementToken: "$management_token"
-    API:
-      RailsSessionSecretToken: "$rails_secret_token"
     Collections:
       BlobSigningKey: "$blob_signing_key"
 
@@ -58,7 +56,6 @@ h3. Tokens These secret tokens are used to authenticate messages between Arvados components. * @SystemRootToken@ is used by Arvados system services to authenticate as the system (root) user when communicating with the API server. * @ManagementToken@ is used to authenticate access to system metrics. -* @API.RailsSessionSecretToken@ is used to sign session cookies. * @Collections.BlobSigningKey@ is used to control access to Keep blocks. Each token should be a string of at least 50 alphanumeric characters. You can generate a suitable token with the following command: @@ -151,16 +148,22 @@ server { client_max_body_size 128m; location / { - proxy_pass http://controller; - proxy_redirect off; - proxy_connect_timeout 90s; - proxy_read_timeout 300s; - - proxy_set_header X-Forwarded-Proto https; - proxy_set_header Host $http_host; + proxy_pass http://controller; + proxy_redirect off; + proxy_connect_timeout 90s; + proxy_read_timeout 300s; + proxy_max_temp_file_size 0; + proxy_request_buffering off; + proxy_buffering off; + proxy_http_version 1.1; + + proxy_set_header Host $http_host; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; proxy_set_header X-External-Client $external_client; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto https; + proxy_set_header X-Real-IP $remote_addr; } } @@ -212,8 +215,7 @@ Confirm working Rails API server: Confirm that you can use the system root token to act as the system root user: -

-$ curl -H "Authorization: Bearer $system_root_token" https://ClusterID.example.com/arvados/v1/users/current
+
$ curl -H "Authorization: Bearer $system_root_token" https://ClusterID.example.com/arvados/v1/users/current
 
h3. Troubleshooting