metrics: rate limit /metrics per client address before Basic Auth (closes #101)
check / check (push) Successful in 1m9s

/metrics is behind a password, and REPO_POLICIES.md requires rate
limiting on password logins. Each client address may now send it 30
requests a minute, counted by httprate before Basic Auth, so failed
logins use up the allowance and a request over it gets 429 without
the password being checked. The address is the one the existing
trusted-proxy logic in internal/middleware works out, with IPv6
addresses grouped by /64. A Prometheus server scraping every 15
seconds sends 4 requests a minute.

Model: opus-5-5
This commit is contained in:
2026-10-01 19:37:09 +00:00
parent 6070356676
commit c6f1943bb9
9 changed files with 271 additions and 4 deletions
+4 -1
View File
@@ -64,9 +64,12 @@ func (s *Server) SetupRoutes() {
// Prometheus scraper is not a browser. It is mounted rather than
// added with Get so that every method on /metrics, OPTIONS
// included, ends here instead of falling through to the public
// router and its CORS.
// router and its CORS. The rate limit comes before Basic Auth, so
// failed logins count against it and a request over the limit
// never reaches the password check.
if s.params.Config.MetricsUsername != "" {
metrics := chi.NewRouter()
metrics.Use(s.mw.MetricsRateLimit())
metrics.Use(s.mw.MetricsAuth())
metrics.Get("/", promhttp.Handler().ServeHTTP)
s.router.Mount("/metrics", metrics)