metrics: rate limit /metrics per client address before Basic Auth (closes #101)
check / check (push) Successful in 1m9s

/metrics is behind a password, and REPO_POLICIES.md requires rate
limiting on password logins. Each client address may now send it 30
requests a minute, counted by httprate before Basic Auth, so failed
logins use up the allowance and a request over it gets 429 without
the password being checked. The address is the one the existing
trusted-proxy logic in internal/middleware works out, with IPv6
addresses grouped by /64. A Prometheus server scraping every 15
seconds sends 4 requests a minute.

Model: opus-5-5
This commit is contained in:
2026-10-01 19:37:09 +00:00
parent 6070356676
commit c6f1943bb9
9 changed files with 271 additions and 4 deletions
+10 -1
View File
@@ -267,7 +267,7 @@ internal/
logger/logger.go slog structured logging (TTY detection)
healthcheck/healthcheck.go Health check service
middleware/middleware.go HTTP middleware (logging, CORS, security
headers, metrics auth)
headers, metrics auth and rate limit)
handlers/handlers.go HTTP request handlers
server/
server.go HTTP server lifecycle
@@ -335,6 +335,15 @@ is a misconfiguration, so dnswatcher fails fast with a clear error message
rather than running silently. Set `DNSWATCHER_TARGETS` to a comma-separated
list of DNS names before starting.
**`/metrics` is rate limited.** Each client address may send it 30 requests a
minute, failed logins included; beyond that it answers `429 Too Many Requests`
without checking the password. A Prometheus server scraping every 15 seconds
sends 4 a minute. IPv6 addresses in one /64 count as one client. When the
request comes from a private or loopback address, such as a reverse proxy's,
the client address is taken from the `X-Real-IP` or `X-Forwarded-For` header
the proxy sets; a proxy that sets neither makes all its clients share one
allowance.
### Example `.env`
```sh