metrics: rate limit /metrics per client address before Basic Auth (closes #101)
check / check (push) Successful in 1m18s
check / check (push) Successful in 1m18s
/metrics is behind a password, and REPO_POLICIES.md requires rate limiting on password logins. Each client address may now send it 30 requests a minute, counted by httprate before Basic Auth, so failed logins use up the allowance and a request over it gets 429 without the password being checked. The address is the one the existing trusted-proxy logic in internal/middleware works out, with IPv6 addresses grouped by /64; an IPv4 address a proxy reports in IPv6-mapped form counts as the plain IPv4 address. A Prometheus server scraping every 15 seconds sends 4 requests a minute. Model: opus-5-5
This commit was merged in pull request #180.
This commit is contained in:
@@ -64,9 +64,12 @@ func (s *Server) SetupRoutes() {
|
||||
// Prometheus scraper is not a browser. It is mounted rather than
|
||||
// added with Get so that every method on /metrics, OPTIONS
|
||||
// included, ends here instead of falling through to the public
|
||||
// router and its CORS.
|
||||
// router and its CORS. The rate limit comes before Basic Auth, so
|
||||
// failed logins count against it and a request over the limit
|
||||
// never reaches the password check.
|
||||
if s.params.Config.MetricsUsername != "" {
|
||||
metrics := chi.NewRouter()
|
||||
metrics.Use(s.mw.MetricsRateLimit())
|
||||
metrics.Use(s.mw.MetricsAuth())
|
||||
metrics.Get("/", promhttp.Handler().ServeHTTP)
|
||||
s.router.Mount("/metrics", metrics)
|
||||
|
||||
Reference in New Issue
Block a user