metrics: rate limit /metrics per client address before Basic Auth (closes #101)
check / check (push) Successful in 1m18s
check / check (push) Successful in 1m18s
/metrics is behind a password, and REPO_POLICIES.md requires rate limiting on password logins. Each client address may now send it 30 requests a minute, counted by httprate before Basic Auth, so failed logins use up the allowance and a request over it gets 429 without the password being checked. The address is the one the existing trusted-proxy logic in internal/middleware works out, with IPv6 addresses grouped by /64; an IPv4 address a proxy reports in IPv6-mapped form counts as the plain IPv4 address. A Prometheus server scraping every 15 seconds sends 4 requests a minute. Model: opus-5-5
This commit was merged in pull request #180.
This commit is contained in:
@@ -267,7 +267,7 @@ internal/
|
||||
logger/logger.go slog structured logging (TTY detection)
|
||||
healthcheck/healthcheck.go Health check service
|
||||
middleware/middleware.go HTTP middleware (logging, CORS, security
|
||||
headers, metrics auth)
|
||||
headers, metrics auth and rate limit)
|
||||
handlers/handlers.go HTTP request handlers
|
||||
server/
|
||||
server.go HTTP server lifecycle
|
||||
@@ -335,6 +335,15 @@ is a misconfiguration, so dnswatcher fails fast with a clear error message
|
||||
rather than running silently. Set `DNSWATCHER_TARGETS` to a comma-separated
|
||||
list of DNS names before starting.
|
||||
|
||||
**`/metrics` is rate limited.** Each client address may send it 30 requests a
|
||||
minute, failed logins included; beyond that it answers `429 Too Many Requests`
|
||||
without checking the password. A Prometheus server scraping every 15 seconds
|
||||
sends 4 a minute. IPv6 addresses in one /64 count as one client. When the
|
||||
request comes from a private or loopback address, such as a reverse proxy's,
|
||||
the client address is taken from the `X-Real-IP` or `X-Forwarded-For` header
|
||||
the proxy sets; a proxy that sets neither makes all its clients share one
|
||||
allowance.
|
||||
|
||||
### Example `.env`
|
||||
|
||||
```sh
|
||||
|
||||
Reference in New Issue
Block a user