When a proxied app returns very large headers (big cookies, long auth tokens), Nginx's default response buffers overflow and it returns 502. The app logs look clean because the app did nothing wrong.
proxy_buffer_size defaults to only 4k/8k. Frameworks that pile cookies/JWTs/admin-toolbars onto responses overflow it.
Third-party scripts and old analytics cookies can bloat request cookies; the app echoes or expands them. Check the Set-Cookie sizes in the browser devtools.
sudo tail -20 /var/log/nginx/error.log | grep -i 'too big header'
# inside the proxying location/server:
# proxy_buffer_size 16k;
# proxy_buffers 8 16k;
# proxy_busy_buffers_size 24k;
sudo nginx -t && sudo systemctl reload nginx
# devtools → Application → Cookies: sort by size, delete abandoned mega-cookies
Buffers must be sized per platform: 16k buffers must exist in multiples that satisfy your page size — if nginx -t complains, adjust powers of two. FastCGI variants of the same problem use fastcgi_buffer_size / fastcgi_buffers.
Session and auth cookies make their response headers large. Anonymous responses fit in default buffers; authenticated ones don't. Raising proxy_buffer_size fixes both.
No — these are small per-connection allocations (kilobytes). The real fix if headers exceed ~32k is shrinking the cookies, since many clients have their own header size limits.
Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.
Browse the template store →One-time. Yours to modify. Instant download from the NinjaOps template store.