feat(caddy): edge rate limiting via custom caddy-ratelimit build (#48) #186

Sammanfogat
supernaut sammanfogade 1 incheckning från feat/48-edge-rate-limiting in i main 2026-07-21 19:15:32 +00:00
Ägare

Edge rate limiting at the Caddy edge via a custom on-host build (stock Caddy + github.com/mholt/caddy-ratelimit) plus a sign-up/captcha rate_limit zone. Implements #48 (epic bitborg-docs#7).

⚠️ Already applied to production (bitborg-infra has no CI-gated apply yet, #38): Caddy on the services host runs localhost/bitborg-caddy:2.11.4-rlv0.1.0; health gate green; #63 running-image verify passed. This PR syncs git with the applied state.

Changes

  • roles/caddy/files/caddy-ratelimit.Containerfile — two-stage xcaddy build (builder-alpine → stock runtime).
  • roles/caddy/defaults/main.yml — caddy_runtime_image(_tag) (custom build, distinct from the stock caddy_image base kept for the monitoring VM + registry-mirror), module ref, zone limits.
  • roles/caddy/tasks/main.yml — on-host build (mirrors kanidm-provision); validate + #63 verify target the runtime image.
  • roles/caddy/templates/{caddy.container.j2,Caddyfile.j2} — run the custom image; order rate_limit + guarded sign-up/captcha zone.
  • renovate.json — customManager tracking mholt/caddy-ratelimit.

Notes

  • ADR 0032 (amends 0005) in a companion bitborg-docs PR.
  • Keyed by real client IP ({remote_host}) — correct at the edge via #81 + #129.
  • Phase 2 (auth/API/general zones + git/registry exemptions) is future tuning.
Edge rate limiting at the Caddy edge via a custom on-host build (stock Caddy + `github.com/mholt/caddy-ratelimit`) plus a sign-up/captcha `rate_limit` zone. Implements #48 (epic bitborg-docs#7). **⚠️ Already applied to production** (bitborg-infra has no CI-gated apply yet, #38): Caddy on the services host runs `localhost/bitborg-caddy:2.11.4-rlv0.1.0`; health gate green; #63 running-image verify passed. This PR syncs git with the applied state. ## Changes - `roles/caddy/files/caddy-ratelimit.Containerfile` — two-stage xcaddy build (builder-alpine → stock runtime). - `roles/caddy/defaults/main.yml` — `caddy_runtime_image(_tag)` (custom build, distinct from the stock `caddy_image` base kept for the monitoring VM + registry-mirror), module ref, zone limits. - `roles/caddy/tasks/main.yml` — on-host build (mirrors kanidm-provision); validate + #63 verify target the runtime image. - `roles/caddy/templates/{caddy.container.j2,Caddyfile.j2}` — run the custom image; `order rate_limit` + guarded sign-up/captcha zone. - `renovate.json` — customManager tracking `mholt/caddy-ratelimit`. ## Notes - ADR 0032 (amends 0005) in a companion bitborg-docs PR. - Keyed by real client IP (`{remote_host}`) — correct at the edge via #81 + #129. - Phase 2 (auth/API/general zones + git/registry exemptions) is future tuning.
supernaut lade till 1 incheckning 2026-07-21 18:29:38 +00:00
feat(caddy): edge rate limiting via custom caddy-ratelimit build (#48)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m29s
54e5d688e8
Build a custom Caddy image on the host (stock Caddy + github.com/mholt/caddy-ratelimit,
xcaddy) and run it via a distinct caddy_runtime_image, leaving the stock caddy_image as the
build base for the monitoring VM and registry-mirror. Add a sign-up/captcha rate_limit zone
(~10/min per client IP, ipv6_prefix 56), guarded so the module is only required when enabled.
Renovate tracks the module ref. Amends ADR 0005; see ADR 0032.
supernaut sammanfogade incheckning c02ee8e2be till main 2026-07-21 19:15:32 +00:00
supernaut tog bort grenen feat/48-edge-rate-limiting 2026-07-21 19:15:32 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!186
Ingen beskrivning angiven.