feat(proxy): add per-IP rate and connection limits
The edge had no limit_req/limit_conn at all, so a single client could flood the Next.js backend and the Nitro client with unbounded parallel requests. Traefik's logs already showed this: bursts of gamedata icon requests answered with 429. Add limit_req (30r/s, burst 60, nodelay) and limit_conn (30) zones keyed on the real client IP, applied at server scope so both cached assets and proxied API routes share one budget. The burst is deliberately generous because the Nitro client fetches gamedata and icons in bursts when loading a room.
This commit is contained in:
1 parent
e3c010f383
commit
4a1211a931
2 files changed
+13
No files matched your search
@@ -192,6 +192,13 @@ server {
|
||||
keepalive_timeout 30s;
|
||||
send_timeout 10s;
|
||||
|
||||
# Abuse limits. Applied per server, not per location, so cached assets and
|
||||
# proxied API routes are all covered by the same budget. nodelay keeps the
|
||||
# 60-request burst responsive: allowed requests pass immediately, only the
|
||||
# excess is rejected with 503 instead of being queued.
|
||||
limit_req zone=cms_req_per_ip burst=60 nodelay;
|
||||
limit_conn cms_conn_per_ip 30;
|
||||
|
||||
# Traefik health-check route herstellen
|
||||
location = /health {
|
||||
access_log off;
|
||||
|
||||
Reference in new issue
Block a user