Issue with Cloudflare template


(Stephen) #1

Recent rebuilds with Cloudflare support enabled through the official template result in an erroneous line appearing in /etc/nginx/conf.d/discourse.conf:

set_real_ip_from 103.21.244.0/22;
set_real_ip_from 103.22.200.0/22;
set_real_ip_from 103.31.4.0/22;
set_real_ip_from 104.16.0.0/12;
set_real_ip_from 108.162.192.0/18;
set_real_ip_from 141.101.64.0/18;
set_real_ip_from 162.158.0.0/15;
set_real_ip_from 172.64.0.0/13;
set_real_ip_from 173.245.48.0/20;
set_real_ip_from 188.114.96.0/20;
set_real_ip_from 190.93.240.0/20;
set_real_ip_from 197.234.240.0/22;
set_real_ip_from 198.41.128.0/17;
set_real_ip_from 199.27.128.0/21;
set_real_ip_from ;
set_real_ip_from 2400:cb00::/32;
set_real_ip_from 2405:8100::/32;
set_real_ip_from 2405:b500::/32;
set_real_ip_from 2606:4700::/32;
set_real_ip_from 2803:f800::/32;

The result is that the Discourse instance becomes unavailable, with the production.log flooded by:

invalid number of arguments in "set_real_ip_from" directive in /etc/nginx/conf.d/discourse.conf

Commenting out the line immediately resolves the issue.

Has the source data at Cloudflare changed? At the minimum it looks like they might be sending a blank row that will need trimming to avoid recurrences of this issue.


(Jeff Atwood) #2

We need to fix this @riking @mpalmer


(Matt Palmer) #3

Ooh, that’s no good. I’ll sort that out right now.


(Stephen) #4

Presumably users will have to update their docker images to benefit from the fix? Anyone who just rebuilds will end up in the same position as us?


(Matt Palmer) #5

Yes, users will have to pull the latest discourse_docker changes to get the fix, but that is (or at least should be) standard procedure.


(Stephen) #6

Standard procedure for what?


(Matt Palmer) #7

Standard procedure for anyone seeing a problem with their Discourse site on rebuild.


(Stephen) #8

Do you have any way of telling how many installs use Cloudflare @codinghorror? Unless Cloudflare correct their data this issue is likely to impact every install which uses the template. I’d hate for others to experience the same outage and impact as we have today.


(Jeff Atwood) #9

It’s probably a fairly low number that use the CF template, as it is a very advanced user kind of thing.


(Matt Palmer) #10

I’ve pushed an update which will fix the reported problem. A git pull should get it and a ./launcher rebuild thereafter should produce a working config.


(Stephen) #11

Will wait until we’re out of peak time before I test, so should be able to provide an update within 12 hours.


(Jeff Atwood) #12

This topic was automatically closed after 2 days. New replies are no longer allowed.