Skip to content

fix: cut machine-path egress (browser headers, 204 heartbeat) - #219

Merged
edospadoni merged 3 commits into
mainfrom
proxy-machine-egress
Oct 5, 2026
Merged

edospadoni merged 3 commits into
mainfrom
proxy-machine-egress

Conversation

@edospadoni

@edospadoni edospadoni commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Problem

  • my-proxy-prod is ~77% of Render egress (~2.45 GB/day, ~2M req/day, ~80% heartbeats)
  • every machine response carries ~650 B of browser-only headers (CSP alone 497 B) against a 175 B heartbeat body

Changes

  • proxy: machine locations declare their own add_header, so they no longer inherit the dashboard set (CSP/XFO/XSS/Referrer/HSTS); they keep nosniff + a deny-all CSP (default-src 'none'; frame-ancestors 'none'), stricter than before for any HTML the same-origin legacy stack might return; frontend and /backend/api unchanged
  • collect: heartbeat answers 204 No Content; docs + OpenAPI updated

Compatibility

  • ns8-core and ns-plug send-heartbeat discard the body and accept any 2xx (checked on a cutover NS8 node and a NethSecurity 8.8.0 unit)

Expected: proxy ~2.45 → ~0.95 GB/day (−61%), heartbeat reply ~1075 → ~240 B

Review focus

  • nginx: no browser-facing location lost its headers
  • 204: any third-party integrator parsing the heartbeat JSON?

CSP, X-Frame-Options, X-XSS-Protection, Referrer-Policy and HSTS were
sent on every appliance, feed and legacy-forwarding response: ~650
bytes of headers against a 175-byte heartbeat body, on ~2M responses
a day, all billed as Render egress. Each machine location now declares
its own add_header (nosniff only), which stops nginx from inheriting
the browser block. Frontend and /backend/api keep the full set.
The 200 JSON reply (code, message, system_key, timestamp) was read by
no client: ns8-core and ns-plug send-heartbeat both discard the body
and only check for a 2xx. Dropping it saves ~245 bytes on each of the
~1.7M daily heartbeats. Docs and OpenAPI now tell integrators to rely
on the status code only.
@edospadoni
edospadoni temporarily deployed to proxy-machine-egress - my-backend-qa PR #219 October 5, 2026 13:18 — with Render Destroyed
@edospadoni
edospadoni temporarily deployed to proxy-machine-egress - my-collect-qa PR #219 October 5, 2026 13:18 — with Render Destroyed
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🔗 Redirect URIs Added to Logto

The following redirect URIs have been automatically added to the Logto application configuration:

Redirect URIs:

  • https://my-proxy-qa-pr-219.onrender.com/login-redirect

Post-logout redirect URIs:

  • https://my-proxy-qa-pr-219.onrender.com/login

These will be automatically removed when the PR is closed or merged.

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

🚨 Breaking my.nethesis.it API change detected

Preview documentation

Structural change details

Modified (1)

  • POST /systems/heartbeat
    • [Breaking] Response removed: 200
      • Removing a resource is always breaking unless it was deprecated before [Breaking]
    • Response added: 204
Powered by Bump.sh

The legacy forwards (/api, /isa, /proxy, /auth) are same-origin with
the SPA, whose Logto tokens live in browser storage, and /proxy
already answers some errors as text/html. Dropping CSP there removed
the safety net against any HTML the legacy stack might reflect.
default-src 'none'; frame-ancestors 'none' restores it, stricter than
the dashboard policy, for ~70 bytes instead of ~500.
@edospadoni
edospadoni temporarily deployed to proxy-machine-egress - my-proxy-qa PR #219 October 5, 2026 13:38 — with Render Destroyed
@edospadoni
edospadoni merged commit 7cdad71 into main Oct 5, 2026
15 of 16 checks passed
@edospadoni
edospadoni deleted the proxy-machine-egress branch October 5, 2026 14:06
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🗑️ Redirect URIs Removed from Logto

The following redirect URIs have been automatically removed from the Logto application configuration:

Redirect URIs:

  • https://my-proxy-qa-pr-219.onrender.com/login-redirect

Post-logout redirect URIs:

  • https://my-proxy-qa-pr-219.onrender.com/login

Cleanup completed for PR #219.

This branch was successfully deployed

No deployments
proxy-machine-egress - my-proxy-qa PR #219 — d88ad98f Deployed Oct 5, 2026 by edospadoni
proxy-machine-egress - my-collect-qa PR #219 — ce25537c Deployed Oct 5, 2026 by edospadoni
proxy-machine-egress - my-backend-qa PR #219 — ce25537c Deployed Oct 5, 2026 by edospadoni
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant