feat(api): 单次上传上限改为 context_max_bytes 可配,Cloudflare 边缘后默认 95Mi,新增 GET /me/submissions/limits 供面板预检
This commit is contained in:
10 files changed
+158
-2
No files matched your search
+30
-1
@@ -5278,6 +5278,31 @@ paths:
|
||||
'503':
|
||||
$ref: '#/components/responses/ServiceUnavailable'
|
||||
|
||||
/api/v1/me/submissions/limits:
|
||||
get:
|
||||
tags: [submissions]
|
||||
operationId: submissionLimits
|
||||
x-felis-face: [external]
|
||||
x-felis-tier: app
|
||||
security: [{ sessionCookie: [] }]
|
||||
summary: The per-upload build-context cap
|
||||
description: >-
|
||||
The effective [registry] context_max_bytes: 1 GiB by default, 95 MiB
|
||||
behind the Cloudflare edge (its proxy refuses bodies over 100 MB before
|
||||
they reach the API). The panel checks a file against it before upload.
|
||||
responses:
|
||||
'200':
|
||||
description: The cap.
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
type: object
|
||||
additionalProperties: false
|
||||
required: [max_context_bytes]
|
||||
properties:
|
||||
max_context_bytes: {type: integer, format: int64}
|
||||
'503':
|
||||
$ref: '#/components/responses/ServiceUnavailable'
|
||||
/api/v1/me/submissions/{id}/context:
|
||||
post:
|
||||
tags: [submissions]
|
||||
@@ -5290,7 +5315,11 @@ paths:
|
||||
principal; a submission the caller does not own is reported as 404, so
|
||||
this endpoint cannot upload to or probe another user's submission. Only a
|
||||
pending_review submission accepts a context (409 otherwise); a wrong-format
|
||||
or oversize body is rejected with 400, and an upload that would push the
|
||||
or oversize body is rejected with 400 (the per-upload cap is [registry]
|
||||
context_max_bytes: 1 GiB by default and 95 MiB behind the Cloudflare
|
||||
edge, whose proxy refuses bodies over 100 MB with its own HTML 413
|
||||
before they reach the API; GET /api/v1/me/submissions/limits reports
|
||||
the effective cap so a client can check a file before sending it), and an upload that would push the
|
||||
caller past their per-user stored-context budget is refused with 403
|
||||
before the excess is persisted. Returns 503 when the deployment's context
|
||||
store has no implemented upload transport.
|
||||
|
||||
@@ -552,6 +552,7 @@ build_user_namespaces = "auto" # §8f: auto | on | off
|
||||
build_runtime_class = "" # §8f: e.g. "gvisor"
|
||||
max_concurrent_builds = 2 # §8f: 1-6; later builds queue
|
||||
user_uploads_max_bytes = "4Gi" # every user's uploaded contexts together; 507 uploads_full past it
|
||||
context_max_bytes = "95Mi" # one uploaded context; empty = 1Gi, or 95Mi behind Cloudflare (edge caps bodies at 100 MB)
|
||||
```
|
||||
|
||||
Put them in **both** `/etc/felis/felis.host.toml` (host-side CLI) and
|
||||
@@ -693,6 +694,9 @@ control namespace (or `--registry-namespace`):
|
||||
(`FELIS_UPLOADS_STORAGE`, 5Gi) and the world-archive PVC
|
||||
(`FELIS_BACKUP_STORAGE`, 10Gi) work the same way; re-running the installer
|
||||
keeps an existing claim's size and warns when the variable asks for another.
|
||||
One uploaded context is capped by `context_max_bytes` (1Gi, or 95Mi behind
|
||||
the Cloudflare edge, whose proxy answers its own 413 page for bodies over
|
||||
100 MB; the panel checks the file against it before uploading).
|
||||
Uploaded build contexts are bounded by `user_uploads_max_bytes` (4Gi for all
|
||||
users together, §8e), 2 GiB per user, and 10% free space on the volume; past
|
||||
any of them an upload answers `507 uploads_full` or `403 submission_quota_exceeded`. A
|
||||
|
||||
Reference in new issue
Block a user