Compare commits

..
Author SHA1 Message Date
fauno 21ea1dd698 feat: implement basic rate limiting by ip address
continuous-integration/drone/pr Build is failing
2026-10-03 01:31:30 -03:00
5 changed files with 22 additions and 4 deletions
+9
View File
@@ -249,3 +249,12 @@ WRITE_TIMEOUT=0s
#
# https://doc.traefik.io/traefik/reference/install-configuration/entrypoints/#opt-forwardedHeaders-trustedIPs
#TRUSTED_IPS="['10.13.12.1']" # 10.13.12.1 is an example
## Rate limits
# You can enable universal rate limits by setting RATE_LIMIT_EVERYTHING
# to true, otherwise each app needs to export their own middleware labels.
#
# https://doc.traefik.io/traefik/reference/routing-configuration/http/middlewares/ratelimit/
#RATE_LIMIT_EVERYTHING=false
#RATE_LIMIT_AVERAGE=100
#RATE_LIMIT_BURST=200
+2 -2
View File
@@ -1,4 +1,4 @@
export TRAEFIK_YML_VERSION=v36
export FILE_PROVIDER_YML_VERSION=v13
export TRAEFIK_YML_VERSION=v37
export FILE_PROVIDER_YML_VERSION=v14
export ENTRYPOINT_VERSION=v5
export ANUBIS_YML_VERSION=v1
+1 -1
View File
@@ -3,7 +3,7 @@ version: "3.8"
services:
app:
image: "traefik:v3.7.14"
image: "traefik:v3.7.13"
# Note(decentral1se): *please do not* add any additional ports here.
# Doing so could break new installs with port conflicts. Please use
# the usual `compose.$app.yml` approach for any additional ports
+6 -1
View File
@@ -22,6 +22,11 @@ http:
basicAuth:
usersFile: "/run/secrets/usersfile"
{{ end }}
ip-rate-limit:
rateLimit:
average: {{ or (env "RATE_LIMIT_AVERAGE") "100" }}
burst: {{ or (env "RATE_LIMIT_BURST") "200" }}
period: "1s"
security:
headers:
frameDeny: true
@@ -70,4 +75,4 @@ tls:
certificates:
- certFile: /run/secrets/ssl_cert
keyFile: /run/secrets/ssl_key
{{ end }}
{{ end }}
+4
View File
@@ -65,6 +65,10 @@ entrypoints:
allowEncodedPercent: true
allowEncodedQuestionMark: true
allowEncodedHash: true
{{ if eq (env "RATE_LIMIT_EVERYTHING") "true" }}
middlewares:
- "ip-rate-limit@file"
{{ end }}
{{- if eq (env "GITEA_SSH_ENABLED") "1" }}
gitea-ssh:
address: ":2222"