feat(api): 单次上传上限改为 context_max_bytes 可配,Cloudflare 边缘后默认 95Mi,新增 GET /me/submissions/limits 供面板预检

This commit is contained in:
Lemon-miaow committed 2026-09-25 18:31:10 +08:00
1 parent e7326e6315
commit 87dee3e5a5
10 files changed
+158 -2

No files matched your search

+30 -1
View File
@@ -5278,6 +5278,31 @@ paths:
'503':
$ref: '#/components/responses/ServiceUnavailable'
/api/v1/me/submissions/limits:
get:
tags: [submissions]
operationId: submissionLimits
x-felis-face: [external]
x-felis-tier: app
security: [{ sessionCookie: [] }]
summary: The per-upload build-context cap
description: >-
The effective [registry] context_max_bytes: 1 GiB by default, 95 MiB
behind the Cloudflare edge (its proxy refuses bodies over 100 MB before
they reach the API). The panel checks a file against it before upload.
responses:
'200':
description: The cap.
content:
application/json:
schema:
type: object
additionalProperties: false
required: [max_context_bytes]
properties:
max_context_bytes: {type: integer, format: int64}
'503':
$ref: '#/components/responses/ServiceUnavailable'
/api/v1/me/submissions/{id}/context:
post:
tags: [submissions]
@@ -5290,7 +5315,11 @@ paths:
principal; a submission the caller does not own is reported as 404, so
this endpoint cannot upload to or probe another user's submission. Only a
pending_review submission accepts a context (409 otherwise); a wrong-format
or oversize body is rejected with 400, and an upload that would push the
or oversize body is rejected with 400 (the per-upload cap is [registry]
context_max_bytes: 1 GiB by default and 95 MiB behind the Cloudflare
edge, whose proxy refuses bodies over 100 MB with its own HTML 413
before they reach the API; GET /api/v1/me/submissions/limits reports
the effective cap so a client can check a file before sending it), and an upload that would push the
caller past their per-user stored-context budget is refused with 403
before the excess is persisted. Returns 503 when the deployment's context
store has no implemented upload transport.
+4
View File
@@ -552,6 +552,7 @@ build_user_namespaces = "auto" # §8f: auto | on | off
build_runtime_class = "" # §8f: e.g. "gvisor"
max_concurrent_builds = 2 # §8f: 1-6; later builds queue
user_uploads_max_bytes = "4Gi" # every user's uploaded contexts together; 507 uploads_full past it
context_max_bytes = "95Mi" # one uploaded context; empty = 1Gi, or 95Mi behind Cloudflare (edge caps bodies at 100 MB)
```
Put them in **both** `/etc/felis/felis.host.toml` (host-side CLI) and
@@ -693,6 +694,9 @@ control namespace (or `--registry-namespace`):
(`FELIS_UPLOADS_STORAGE`, 5Gi) and the world-archive PVC
(`FELIS_BACKUP_STORAGE`, 10Gi) work the same way; re-running the installer
keeps an existing claim's size and warns when the variable asks for another.
One uploaded context is capped by `context_max_bytes` (1Gi, or 95Mi behind
the Cloudflare edge, whose proxy answers its own 413 page for bodies over
100 MB; the panel checks the file against it before uploading).
Uploaded build contexts are bounded by `user_uploads_max_bytes` (4Gi for all
users together, §8e), 2 GiB per user, and 10% free space on the volume; past
any of them an upload answers `507 uploads_full` or `403 submission_quota_exceeded`. A