All checks were successful
check / check (push) Successful in 3m7s
With TRUSTED_PROXIES empty, every rate limiter keys on the connecting peer. Production runs behind a TLS-terminating reverse proxy, so the peer is that proxy for every request and all clients share one bucket per limit. For the login limiter that means any remote client sending five POSTs a minute holds the only administrative login at HTTP 429. The empty default is correct — trusting forwarded headers from arbitrary peers lets any client choose its own bucket — so this makes the consequence visible rather than changing the keying, the limits or the default: - config logs a WARN at startup when the environment is prod and TRUSTED_PROXIES is empty, naming the variable, the shared bucket and the deniable admin login. - The security-feature bullet's "per IP" login claim is now conditional on TRUSTED_PROXIES, which is the only case where it holds. - The rate-limiting section separates the receiver case (sharing costs throughput, the safe direction) from the login case (sharing costs availability of the only admin path, not safe). - The trusted-proxies configuration section states the consequence and names TRUSTED_PROXIES as the remedy.