SPEC follows milestones 1 and 2: build order, two size limits, GeoJS answers in memory (closes #16)

The build order starts with milestone 1 and milestone 2, then keeps the
earlier stages in their order, less what the two milestones build.
Milestone 2 builds the container image with runit and the health check,
so it answers /_smallwebwaf/healthz before the other admin endpoints.

The four body-size settings become SWWAF_REQUEST_MAX_BYTES and
SWWAF_RESPONSE_MAX_BYTES, since bodies pass through unchanged; the four
timeouts stay.

GeoJS answers are kept in memory; lookups.json comes in milestone 3 or
later, as sneak ruled.

README.md: the two sentences this change made wrong.

Model: opus-5-5
This commit is contained in:
2026-09-29 00:00:20 +00:00
parent ba54ecb009
commit 5971529abb
2 changed files with 69 additions and 44 deletions
+9 -7
View File
@@ -56,9 +56,10 @@ goes through the candidates one by one.
- Real client address worked out from `X-Forwarded-For`, trusting only the proxy
networks you list, by default the private address ranges. IPv6 clients are
counted by /64 by default.
- Size and time limits on requests and responses, both between the client and
`smallwebwaf` and between `smallwebwaf` and the app: by default a request may
take 60 seconds and 100 MiB, a response 30 minutes and 5 GiB.
- Size and time limits on requests and responses, with the time limits both
between the client and `smallwebwaf` and between `smallwebwaf` and the app: by
default a request may take 60 seconds and 100 MiB, a response 30 minutes and 5
GiB.
- Rate limits per client on requests per minute, per hour and per day, and on
bytes per minute, per hour and per day, on by default and set well above what
real visitors need.
@@ -212,10 +213,11 @@ request log, the metrics and the ban notes, and for the country lists and biased
limits when you set them. It works with no setup: by default it asks the free
GeoJS web service, which needs no account and no file. This means that, by
default, the address of every new visitor is sent to GeoJS. Each answer is kept
for seven days, across restarts, and many addresses are asked about in one
request. GeoJS publishes no rate limit but may block a caller it thinks asks too
much; while it is not answering, new visitors count as coming from an unknown
country, which `SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES` refuses.
in memory for seven days, and many addresses are asked about in one request;
writing the answers to disk, so that they survive a restart, comes in milestone
3 or later. GeoJS publishes no rate limit but may block a caller it thinks asks
too much; while it is not answering, new visitors count as coming from an
unknown country, which `SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES` refuses.
To keep your visitors' addresses on your own host, set
`SWWAF_LOOKUP_SOURCE=off`, or use the database file instead of GeoJS: