feat(caddy): edge rate limiting via custom caddy-ratelimit build (#48) #186
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!186
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/48-edge-rate-limiting"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Edge rate limiting at the Caddy edge via a custom on-host build (stock Caddy +
github.com/mholt/caddy-ratelimit) plus a sign-up/captcharate_limitzone. Implements #48 (epic bitborg-docs#7).⚠️ Already applied to production (bitborg-infra has no CI-gated apply yet, #38): Caddy on the services host runs
localhost/bitborg-caddy:2.11.4-rlv0.1.0; health gate green; #63 running-image verify passed. This PR syncs git with the applied state.Changes
roles/caddy/files/caddy-ratelimit.Containerfile— two-stage xcaddy build (builder-alpine → stock runtime).roles/caddy/defaults/main.yml—caddy_runtime_image(_tag)(custom build, distinct from the stockcaddy_imagebase kept for the monitoring VM + registry-mirror), module ref, zone limits.roles/caddy/tasks/main.yml— on-host build (mirrors kanidm-provision); validate + #63 verify target the runtime image.roles/caddy/templates/{caddy.container.j2,Caddyfile.j2}— run the custom image;order rate_limit+ guarded sign-up/captcha zone.renovate.json— customManager trackingmholt/caddy-ratelimit.Notes
{remote_host}) — correct at the edge via #81 + #129.