feat(security): add Redis-backed app-layer anti-DDoS rate limiting to proxy
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 31s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Successful in 1m47s
CI / tests-ui (push) Successful in 2m40s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m3s

This commit is contained in:
openhands committed 2026-09-22 21:48:40 +02:00
1 parent d8f2a21011
commit 98a184953a
5 files changed
+184 -8

No files matched your search

+6
View File
@@ -100,6 +100,12 @@ const schema = z
// Redis — strongly recommended in production (required for multi-instance).
// Without it, rate limits / shared caches are in-process only.
REDIS_URL: z.string().optional(),
// App-layer anti-DDoS gate (proxy rate limiter). On by default in
// production; set to "false" or "0" to disable without removing it.
ANTI_DDOS_ENABLED: z
.string()
.optional()
.transform((value) => value !== "false" && value !== "0"),
// Logging level.
LOG_LEVEL: z.enum(["debug", "info", "warn", "error"]).optional(),
APP_VERSION: z.string().optional(),