docs(env): document anti-DDoS thresholds and Cloudflare API auto-block vars
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 31s
CI / tests-integration (push) Successful in 1m44s
CI / tests-unit (push) Successful in 1m53s
CI / tests-ui (push) Successful in 3m0s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 18s

This commit is contained in:
openhands committed 2026-09-22 23:37:39 +02:00
1 parent 6264f9fb20
commit c56696b230
1 file changed
+33
+33
View File
@@ -39,6 +39,39 @@ APP_KEY=base64:your-app-key-here=
# Bcrypt cost factor for new password hashes.
BCRYPT_COST=12
# --- ANTI-DDOS (app-layer gate, production only) ---
# On by default in production. Set to "false" to disable (not recommended).
ANTI_DDOS_ENABLED=true
# Per-category request thresholds over the given window (per client IP).
ANTI_DDOS_PAGES_LIMIT=300
ANTI_DDOS_PAGES_WINDOW_SEC=60
ANTI_DDOS_API_LIMIT=600
ANTI_DDOS_API_WINDOW_SEC=60
ANTI_DDOS_AUTH_LIMIT=20
ANTI_DDOS_AUTH_WINDOW_SEC=60
# Whole-site safety valve per window (sheds everything for global_halt_ms when hit).
ANTI_DDOS_GLOBAL_LIMIT=18000
ANTI_DDOS_GLOBAL_WINDOW_SEC=60
ANTI_DDOS_GLOBAL_HALT_MS=10000
# Violations accumulate inside this window before an IP is hard-blocked.
ANTI_DDOS_VIOLATION_WINDOW_SEC=600
ANTI_DDOS_MAX_VIOLATIONS=10
# Escalation tiers "minViolations:ttlSeconds" — how long an offender stays blocked.
ANTI_DDOS_BLOCK_TIERS=5:600,20:3600,50:86400
# --- CLOUDFLARE API (automatic edge blocks, optional) ---
# When set, the anti-DDoS gate automatically mirrors hard-blocked IPs to the
# zone's IP Access Rules so repeat offenders are dropped at the Cloudflare
# edge (works on every plan, incl. Free). Token permissions required:
# Zone > Zone > Read and Zone > Firewall > Edit
CLOUDFLARE_API_TOKEN=
CLOUDFLARE_ZONE_ID=
# Runtime toggle; leave true to auto-create Cloudflare blocks at the block
# threshold. Also overridable live from the admin panel.
CLOUDFLARE_AUTO_BLOCK_ENABLED=true
# Override for tests/staging (production uses the public endpoint by default).
CLOUDFLARE_API_BASE_URL=https://api.cloudflare.com/client/v4
# --- PATHS ---
BADGE_UPLOAD_DIR=./public/assets/images/badges
EMULATOR_JAR_PATH=./emulator/Arcturus.jar