Skip to content

For the complete documentation index, see llms.txt. Markdown versions of all docs pages are available by appending .md to any docs URL.

Forward 100-continue requests

Page as Markdown

    

Forward Expect 100-continue requests to the backend instead of answering them at the gateway proxy.

Forward Expect: 100-continue requests to the backend so that the backend decides whether to accept the request body.

About 100-continue

A client that is about to send a large request body can first send the request headers with an Expect: 100-continue header. The client then waits for a 100 Continue response before it sends the body. This process allows a server to reject the request before the client uploads the body, because the client is not authorized or the body is too large.

By default, the gateway proxy handles this exchange itself. The gateway proxy removes the Expect header, immediately returns 100 Continue to the client, and forwards the request without the header to the backend. Because of that, the backend cannot reject the request before the client sends the body.

To let the backend make that decision, set the proxy100Continue field in a ListenerPolicy. The gateway proxy then forwards the Expect: 100-continue header to the backend, and passes the 100 Continue response from the backend back to the client.

Before you begin

  1. Follow the Get started guide to install kgateway.

  2. Follow the Sample app guide to create a gateway proxy with an HTTP listener and deploy the httpbin sample app.

  3. Get the external address of the gateway and save it in an environment variable.

    export INGRESS_GW_ADDRESS=$(kubectl get svc -n kgateway-system http -o jsonpath="{.status.loadBalancer.ingress[0]['hostname','ip']}")
    echo $INGRESS_GW_ADDRESS  

Forward 100-continue requests

  1. Send a request with an Expect: 100-continue header to the httpbin app. The httpbin app returns the request headers that it received in the response body.

    curl -v -X POST http://$INGRESS_GW_ADDRESS:8080/anything \
      -H "host: www.example.com" \
      -H "Expect: 100-continue" \
      --data-binary 'hello'

    In the output, the gateway proxy returns a 100 Continue HTTP response. The headers in the response body do not include an Expect header, because the gateway proxy removed the header before it forwarded the request.

    < HTTP/1.1 100 Continue
    < HTTP/1.1 200 OK
    ...
    
  2. Create a ListenerPolicy with the proxy100Continue field. In the targetRefs, attach the policy to the Gateway that you want to forward 100-continue requests for.

    kubectl apply -f- <<EOF
    apiVersion: gateway.kgateway.dev/v1alpha1
    kind: ListenerPolicy
    metadata:
      name: proxy-100-continue
      namespace: kgateway-system
    spec:
      targetRefs:
      - group: gateway.networking.k8s.io
        kind: Gateway
        name: http
      default:
        httpSettings:
          proxy100Continue: true
    EOF
    Field Description
    spec.targetRefsThe Gateway resources that the ListenerPolicy applies to. In this example, the policy applies to the http Gateway from the sample app guide.
    spec.default.httpSettings.proxy100ContinueSet to true to forward requests with an Expect: 100-continue header to the backend, and to pass the 100 Continue response from the backend back to the client. Omit the field or set it to false to let the gateway proxy answer with 100 Continue itself.
  3. Send the same request to the httpbin app again. Verify that the headers in the response body include the Expect header, which means that the gateway proxy forwarded the header to httpbin. The 100 Continue response now comes from httpbin.

    curl -v -X POST http://$INGRESS_GW_ADDRESS:8080/anything \
      -H "host: www.example.com" \
      -H "Expect: 100-continue" \
      --data-binary 'hello'

    Example output:

    < HTTP/1.1 100 Continue
    < HTTP/1.1 200 OK
    ...
    {
      ...
      "headers": {
        ...
        "Expect": [
          "100-continue"
        ],
        ...
      }
    }
    
  4. Optional: Port-forward the gateway proxy on port 19000 to open the Envoy admin interface, and verify that the proxy_100_continue field is set to true in the HTTP connection manager.

    kubectl port-forward deploy/http -n kgateway-system 19000 & \
    sleep 2 && curl -s localhost:19000/config_dump | grep proxy_100_continue

    Example output:

          "proxy_100_continue": true,
    

Cleanup

You can remove the resources that you created in this guide.
kubectl delete listenerpolicy proxy-100-continue -n kgateway-system
Was this page helpful?