Has anyone had success with self hosted n8n behind nginx, to leverage Gemini Enterprise.
We have a basic workflow with a MCP trigger that we are trying to establish connectivity to for a test, with no authorization.
When Gemini Enterprise attempts to load custom actions, it 503 errors:
response_body: {“error”:{“code”:“UPSTREAM_CONNECTION_FAILURE”,“flag”:“UpstreamConnectionFailure”,“message”:“See go/conduit-troubleshooting#upstream-connection-failure for more information.”}}
We believe we have the /mpc location on nginx set up correctly (able to connect via postman), wondering if anyone else has had success.
Gemini Enterprise currently requires Streamable HTTP for custom MCP servers and does not support the legacy SSE transport.
So Postman reaching /mcp successfully doesn’t necessarily mean Gemini can complete the MCP handshake.
I would check the nginx logs while using Reload custom actions in Gemini.
That triggers a tools/list request and should show whether the request reaches nginx/n8n or fails before that.
If you can share the nginx log from one failed attempt that would probably narrow it down quickly.
We were able to get a local self hosted LLM through the reverse proxy, so I am thinking the issues is realted with the Gemini side configuration, which, does not seem to have a lot of options when no authorization is chosen except for the url.
That is actually a useful clue. If nothing reaches the nginx logs I would stop debugging nginx n8n for now and look at the Gemini Google Cloud side.
One thing worth checking is the egress policy. Google documents that with policy enforcement VPC Service Controls enabled the MCP server domain must be explicitly allowed in allowedEgressFqdns and custom_mcp must be an allowed data source.
Since Gemini is returning the 503 before nginx sees anything that would be my next place to look.
Hi @dagarritysps, your Gemini trace shows initialize going to http://.../mcp/..., with a Conduit 503 and no request in nginx. Google requires an HTTPS URL with a publicly trusted certificate for a custom MCP server.
Can you check the MCP Server URL saved in Gemini against the Production URL shown by n8n’s MCP Server Trigger? If Gemini has http:// saved, change it to the HTTPS URL and reload custom actions. The x-forwarded-proto: https header doesn’t confirm what URL is saved there.
If it already has HTTPS, test that same URL from outside your network while watching nginx’s access log. If the external test reaches nginx but Gemini still doesn’t, send Google support the failed request’s timestamp and trace ID.