Body Size Limit
All API requests are subject to a 20 MiB body size limit. Requests exceeding this limit will be rejected with 413 Payload Too Large. This accommodates large Visio stencil uploads (POST /icon-packs/import) and config backup imports (POST /admin/restore).
Exception: POST /admin/restore/database does not inherit the standard 20 MiB cap. api.max_restore_size is an optional hard upload/decompressed ceiling; its default 0 means no arbitrary size ceiling. Capacity is still bounded dynamically: while staging, Osprey retains max(api.restore_min_free_bytes, api.restore_min_free_percent) plus one complete staged-SQL size as database-build headroom. The packaged defaults are 5 GiB and 10%. A local PostgreSQL filesystem at api.restore_database_dir is checked again before import; a remote database's filesystem cannot be inspected by the API and remains an operator responsibility. The nginx reverse proxy accepts and streams the request.