So I’d setup an OwnCloud server in my Homelab last year. Got it up and running with cloudflared (and no I’m not telling where it is 😉). I recently found out that the OwnCloud Android App has (added?) photo and video sync from the camera. So I set it up and lo and behold… the uploads fail. All of them. The cloudflared was relatively new, and I’d only used it in my Lan, with a direct to Apache address, and that worked.

Two days of frustratingly seeing 404 HEAD requests in the owncloud logs, and then I find out (while trying to upload app logs), that uploads in general are not working. So then I logged back in to the LAN, direct to Apache address, and it started working. Both the camera syncs and uploads.

Now I had a direction, in which to dig further. First order of business, checking Cloudflare tunnel settings. That didn’t help much. Two hours down the drain.

Next order of business (point of failure?) was my Nginx reverse proxy, which I’d setup fairly recently (because certbot don’t work on non-standard ports) and I was reverse proxying all my services through it. Turns out, WebDav needed a little more configuring for it to forward the necessary headers. After a little tinkering, it works! 😎

Here’s what my server block config looks like now:

server {
    server_name owncloud.REDACTED.com;
    listen 443 ssl;
    location / {
        proxy_pass                 http://127.0.0.1:8080;
        proxy_pass_request_headers on;
        set $dest $http_destination;
        if ($http_destination ~ "^https://(?<myvar>(.+))") {
            set $dest http://$myvar;
        }
        proxy_set_header           Host              $host;
        proxy_set_header           Destination       $dest;
        proxy_set_header           X-Real-IP         $remote_addr;
        proxy_set_header           X-Forwarded-For   $proxy_add_x_forwarded_for;
        proxy_set_header           X-Forwarded-Proto $scheme;
        proxy_set_header           X-Forwarded-Host  $host;
        proxy_set_header           X-Forwarded-Port  $server_port;
        proxy_set_header           X-Forwarded-Ssl   on;
        proxy_set_header           Connection        "";
        proxy_buffering       off;
        client_max_body_size  0;
    }
    ssl_certificate /etc/letsencrypt/live/REDACTED.com/fullchain.pem; # managed by Certbot
    ssl_certificate_key /etc/letsencrypt/live/REDACTED.com/privkey.pem; # managed by Certbot
}

References

These docs helped a ton