Skip to content

Conversation

kvaps
Copy link
Member

@kvaps kvaps commented Sep 4, 2025

Signed-off-by: Andrei Kvapil kvapss@gmail.com

What this PR does

Release note

[seaweedfs] Fix connectivity issues for SeaweedFS

Summary by CodeRabbit

  • Chores
    • Increased Nginx Ingress timeouts for the SeaweedFS S3 endpoint (read/send: 3600s, client body: 3600s, client header: 120s). This enhances stability for long-running S3 operations, reducing premature disconnects and timeout errors.
    • Users should experience more reliable large uploads/downloads and fewer interruptions, especially over slower or inconsistent networks.
    • No other behavior changes; existing S3 access and routing remain the same.

Signed-off-by: Andrei Kvapil <kvapss@gmail.com>
Copy link
Contributor

coderabbitai bot commented Sep 4, 2025

Walkthrough

Added four Nginx Ingress timeout annotations to the SeaweedFS S3 ingress configuration in packages/system/seaweedfs/values.yaml.

Changes

Cohort / File(s) Summary of Changes
SeaweedFS S3 Ingress annotations
packages/system/seaweedfs/values.yaml
Added annotations under seaweedfs.s3.ingress.annotations: nginx.ingress.kubernetes.io/proxy-read-timeout: "3600", nginx.ingress.kubernetes.io/proxy-send-timeout: "3600", nginx.ingress.kubernetes.io/client-body-timeout: "3600", nginx.ingress.kubernetes.io/client-header-timeout: "120"

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Suggested reviewers

  • lllamnyp
  • klinch0

Poem

A bunny taps keys with gentle delight,
Extending timeouts into the night. ⏳
Headers and bodies, no need to rush,
Read, send—steady—no panicked hush.
SeaweedFS hums; ingress hops true—
Nginx awaits, and so do I: woo-hoo! 🐇✨

✨ Finishing Touches
🧪 Generate unit tests
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix-seaweedfs-connectivity

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.

Support

Need help? Create a ticket on our support page for assistance with any issues or questions.

CodeRabbit Commands (Invoked using PR/Issue comments)

Type @coderabbitai help to get the list of available commands.

Other keywords and placeholders

  • Add @coderabbitai ignore or @coderabbit ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Status, Documentation and Community

  • Visit our Status Page to check the current availability of CodeRabbit.
  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

Copy link

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary of Changes

Hello @kvaps, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses potential connectivity issues within the SeaweedFS deployment by adjusting the Nginx ingress timeout settings. The modifications aim to enhance the stability and reliability of connections, particularly for operations that require extended durations, thereby improving the overall user experience with SeaweedFS.

Highlights

  • Nginx Ingress Configuration: Added proxy-read-timeout, proxy-send-timeout, client-body-timeout (all set to 3600 seconds), and client-header-timeout (set to 120 seconds) to the SeaweedFS Nginx ingress annotations. These changes are intended to prevent connection timeouts for long-running operations.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point in your pull request via creating an issue comment (i.e. comment on the pull request page) using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in issue comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@kvaps kvaps added the backport Should change be backported on previus release label Sep 4, 2025
Copy link

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request aims to fix connectivity issues with SeaweedFS by increasing several NGINX ingress timeouts. While increasing timeouts is a valid approach for services that handle large file transfers, the new default timeout of 3600 seconds (1 hour) for proxy and client body operations is very high. This could expose the ingress controller to resource exhaustion and potential denial-of-service attacks. I've recommended reducing this to a more conservative default and documenting that it can be increased by users if needed.

Comment on lines +102 to +104
nginx.ingress.kubernetes.io/proxy-read-timeout: "3600"
nginx.ingress.kubernetes.io/proxy-send-timeout: "3600"
nginx.ingress.kubernetes.io/client-body-timeout: "3600"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

Setting timeouts to 3600 seconds (1 hour) is quite high and could make the ingress controller vulnerable to slowloris-type denial-of-service attacks, where an attacker could hold connections open for a long time by sending data very slowly. This can exhaust the available worker connections on the ingress controller, affecting other services.

While long timeouts are necessary for large file transfers with SeaweedFS, a 1-hour default seems excessive. Consider reducing this to a more moderate value, for example, 600 (10 minutes), and adding a comment to inform users that they can increase it if they need to handle extremely large file transfers over slow connections.

If 1 hour is truly necessary for your use case, please add a comment explaining why such a long timeout is required as a default.

        nginx.ingress.kubernetes.io/proxy-read-timeout: "600"
        nginx.ingress.kubernetes.io/proxy-send-timeout: "600"
        nginx.ingress.kubernetes.io/client-body-timeout: "600"

Copy link
Contributor

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/system/seaweedfs/values.yaml (1)

96-111: TLS host mismatch will break cert issuance/termination

ingress.host is seaweedfs2.demo.cozystack.io but tls.hosts lists seaweedfs.demo.cozystack.io. This mismatch can cause the wrong certificate to be requested/attached and result in browser/client TLS errors.

       tls:
         - hosts:
-            - seaweedfs.demo.cozystack.io
+            - seaweedfs2.demo.cozystack.io
           secretName: seaweedfs-s3-ingress-tls
🧹 Nitpick comments (1)
packages/system/seaweedfs/values.yaml (1)

102-105: Good timeout additions; also consider connect-timeout and confirm controller

These timeouts make sense for long S3 uploads/downloads. Consider also setting proxy-connect-timeout to cover slow upstream TCP handshakes, and verify that className: tenant-root points to an NGINX IngressController so these annotations take effect.

       nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
       nginx.ingress.kubernetes.io/proxy-read-timeout: "3600"
       nginx.ingress.kubernetes.io/proxy-send-timeout: "3600"
       nginx.ingress.kubernetes.io/client-body-timeout: "3600"
       nginx.ingress.kubernetes.io/client-header-timeout: "120"
+      nginx.ingress.kubernetes.io/proxy-connect-timeout: "120"
📜 Review details

Configuration used: CodeRabbit UI

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • MCP integration is disabled by default for public repositories
  • Jira integration is disabled by default for public repositories
  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9f89ef3 and a291bad.

📒 Files selected for processing (1)
  • packages/system/seaweedfs/values.yaml (1 hunks)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (1)
  • GitHub Check: Build

@kvaps kvaps merged commit 7090b8a into main Sep 5, 2025
20 checks passed
@kvaps kvaps deleted the fix-seaweedfs-connectivity branch September 5, 2025 08:18
Copy link

github-actions bot commented Sep 5, 2025

Successfully created backport PR for release-0.35:

kvaps added a commit that referenced this pull request Sep 5, 2025
…edFS (#1390)

# Description
Backport of #1386 to `release-0.35`.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport Should change be backported on previus release
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant