Edge rate limiting: custom Caddy build + rate_limit block #48
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#48
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Custom Caddy build (xcaddy + caddy-ratelimit), distributed like the on-host kanidm-provision image; add a
rate_limitblock on thewwwhost covering /api/signup and /api/invites. Record a new ADR (amends ADR 0005).Epic: gitborg/gitborg-docs#7
Design/plan drafted (in bitborg-internal
plans/2026-07-21-edge-rate-limiting-design.md). Summary:Getting
rate_limitin:mholt/caddy-ratelimitisn't in the official image, so build a custom Caddy. Recommend an on-host build (mirror the kanidm-provision pattern: staged Containerfile +podman_image state: build, native amd64, rebuild only on version bump) using Caddy's officialcaddy:2.11.4-builder-alpine(ships xcaddy) → copy the binary ontocaddy:2.11.4-alpine. Pin the custom tag in the caddy role vars so the monitoring VM stays on stock upstream. CI+registry (ADR 0019 style) is deferred to Phase 3 — infra has no CI pipeline yet. Renovate tracks both the base Caddy version and the (pre-1.0) module ref; the existing #63 running-image verify guards a green apply.Policy (numbers = maintainer's call): per-surface zones keyed by
{remote_host}(real IP via #81/#129,ipv6_prefix 56) — sign-up + Cap captcha (~10/min, the original scope), auth/login (~20/min), API (~120/min), general www (~300/min); git-over-HTTPS +/v2registry NOT limited (protects clones/CI/runner egress — same reason as the fail2ban/v2exclusion #179). Note the invite flow is retired (ADR 0029) — no invite zone needed.Layering: nftables → fail2ban (reactive 401 ban, #127) → Caddy rate_limit (proactive 429) → app-layer limiter (already in bitborg-web
src/lib/rate-limit.ts, complementary). Do NOT feed 429s into fail2ban in Phase 1 (false-positive risk for shared-NAT/CI); revisit as a separate loose jail later.Rollout: build+pin with no zones (prove drop-in) → add sign-up/captcha zone generously → observe via Loki 429s + a Grafana panel (module exposes Prometheus metrics) → tune → extend. Record a new ADR amending 0005.
Phase 1 shipped + live (PR #186, ADR 0032): custom caddy-ratelimit build + the sign-up/captcha rate_limit zone, keyed by real client IP (#81/#129). Phase 2 — auth/API/general zones + git/registry exemptions — is future tuning under epic bitborg-docs#7. Closing the Phase-1 scope of this issue.