# Proxy to S3 results in signature issues

**URL:** <https://hub.mender.io/t/proxy-to-s3-results-in-signature-issues/6534>\
**Category:** General Discussions\
**Tags:** mender-server, proxy, kubernetes, helm\
**Created:** [February 5, 2024, 2:35pm UTC](https://hub.mender.io/t/proxy-to-s3-results-in-signature-issues/6534 "2024-02-05T14:35:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dominik-Hstein](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/dominik-hstein/32/1927_2.png) [@Dominik-Hstein](https://hub.mender.io/u/Dominik-Hstein)\
**Post date:** [February 5, 2024, 2:35pm UTC](https://hub.mender.io/t/proxy-to-s3-results-in-signature-issues/6534/1 "2024-02-05T14:35:11Z")

</div>

Hi there,

In a setup where aws S3 cannot be reached, an nginx forward proxy is provided that will enable AWS download even when AWS is blocked.

Let’s say the nginx server is reachable via `https://s3.nginx.com` and we have the bucket at `https://s3-eu-central-1.amazonaws.com`.

The Mender server is set up in k8s with the Helm chart. The configuration `s3.AWS_EXTERNAL_URI` ([here](https://github.com/mendersoftware/mender-helm/blob/b4267ec2724a086cab141864192fba6f5e0b6bee/mender/values.yaml#L26C5-L26C25)) is set to `https://s3.nginx.com`.

This works. The Mender server generates s3 bucket URLs starting with `https://s3.nginx.com` for the artifacts.

However, when accessing the url, a signature error is thrown. This happens because of a presigning process where the signature depends on the url. This means that the download is signed with `https://s3.nginx.com`. The proxy then forwards the request and changes the start to `https://s3-eu-central-1.amazonaws.com`, leading to a wrong signature.

The configuration in the code also mentions a `ProxyUri`. However, there appears to be no Helm value for this.

Is there a solution to this problem? Otherwise the only solution that comes to my mind is to make the bucket public and either hope that public artifact url’s are not signed or cut off the signature headers from the url when forwarding in the proxy.

Thanks.  
-Dominik

---

<div class="post-metadata">

**Author:** ![robgio](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/robgio/32/1760_2.png) [@robgio](https://hub.mender.io/u/robgio)\
**Post date:** [February 5, 2024, 3:53pm UTC](https://hub.mender.io/t/proxy-to-s3-results-in-signature-issues/6534/2 "2024-02-05T15:53:41Z")

</div>

Hello @Dominik-Hstein ,  
have you tried the new `api_gateway.storage_proxy.url` option in the [Helm chart v5.5.0](https://github.com/mendersoftware/mender-helm/blob/master/mender/CHANGELOG.md#550)? This should cover your use-case.

---

<div class="post-metadata">

**Author:** ![Dominik-Hstein](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/dominik-hstein/32/1927_2.png) [@Dominik-Hstein](https://hub.mender.io/u/Dominik-Hstein)\
**Post date:** [February 5, 2024, 4:06pm UTC](https://hub.mender.io/t/proxy-to-s3-results-in-signature-issues/6534/3 "2024-02-05T16:06:50Z")

</div>

Hi,  
I’m not sure if I’m using it correctly.  
Should the AWS external URI stay the same? In this case, what values should be used in the proxy url? The aws one or nginx one?  
Edit: it seems to be the external for both.  
I’ll try that.

---

<div class="post-metadata">

**Author:** ![robgio](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/robgio/32/1760_2.png) [@robgio](https://hub.mender.io/u/robgio)\
**Post date:** [February 5, 2024, 4:11pm UTC](https://hub.mender.io/t/proxy-to-s3-results-in-signature-issues/6534/4 "2024-02-05T16:11:39Z")

</div>

Hi, the proxy url should be the nginx one and the external url should have the S3 bucket FQDN address, with also the region specified. For example: `https://my-mender-artifacts.s3.eu-central-1.amazonaws.com`

---

<div class="post-metadata">

**Author:** ![Dominik-Hstein](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/dominik-hstein/32/1927_2.png) [@Dominik-Hstein](https://hub.mender.io/u/Dominik-Hstein)\
**Post date:** [February 6, 2024, 10:24am UTC](https://hub.mender.io/t/proxy-to-s3-results-in-signature-issues/6534/5 "2024-02-06T10:24:22Z")

</div>

It’s working now with the following configuration:

- No AWS\_EXTERNAL\_URI

```yaml
mender:
  deployments:
    customEnvs:
      - name: DEPLOYMENTS_STORAGE_PROXY_URI
        value: "https://my-mender-domain"

nginx:
  ingress:
    hostname: my-mender-domain
    path: /my-bucket-name

```

The result is that Mender produces URLs like `https://my-mender-domain/my-bucket-name/...` with a correct signature.

---

<div class="post-metadata">

**Author:** ![robgio](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/robgio/32/1760_2.png) [@robgio](https://hub.mender.io/u/robgio)\
**Post date:** [February 6, 2024, 10:29am UTC](https://hub.mender.io/t/proxy-to-s3-results-in-signature-issues/6534/6 "2024-02-06T10:29:43Z")

</div>

Hi @Dominik-Hstein , thanks for letting know!  
I’m going to update the documentation.

Thanks!
