caddy: tune ADR 0032 rate limits from Loki 429 data, and revisit the auth zone #302
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#302
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Follow-up to the ADR 0032 Phase 2 rate limits applied in #296.
Tune from data
The ADR requires tuning from observed 429s and recording the final thresholds. Current values are
starting points, not measurements: Forgejo API 120/min, Forgejo general 300/min, auth 300/min, all
per client IP with
ipv6_prefix 56. Query Loki for 429s by zone and vhost before tightening anything.Revisit the auth zone specifically
It is deliberately 300/min rather than the ADR's ~20/min. Kanidm serves its SPA assets and several
XHRs from the same host, so one genuine interactive login is well over 20 requests, and a literal
20/min across all paths would lock real users out mid-sign-in on the only sign-in path there is.
If a tighter limit is wanted, scope a second zone to Kanidm's credential-submission endpoints rather
than the whole host. That needs someone to establish which paths those actually are.
Keep the internal exemption in mind
Every zone excludes
private_ranges, and that is load-bearing. The first version of this changethrottled the reconciler into
HTTP 429within six minutes, because it reaches Forgejo over thepublic URL (
reconciler_forgejo_url) and all of its calls share one{remote_host}key. Any futurezone must carry the same exemption, and any new first-party caller that traverses the edge inherits
the same trap. Same shape as the fail2ban shared-SNAT ban in #195.