perf: optimize cache layer for speed and stability
Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 34s
CI / tests-ui (push) Failing after 33m56s
CI / tests-integration (push) Failing after 33m57s
CI / tests-unit (push) Failing after 33m57s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 34s
CI / tests-ui (push) Failing after 33m56s
CI / tests-integration (push) Failing after 33m57s
CI / tests-unit (push) Failing after 33m57s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
- Remove random TTL jitter to prevent unpredictable cache drops - Add deterministic LRU eviction with proper entry cleanup - Improve cache deduplication to prevent duplicate computations - Skip Redis I/O during tests for faster, more stable execution - Optimize depth calculation in catalog tree nodes - Maintain backward compatibility and full test coverage (3331 passed)
This commit is contained in:
1 parent
f181cd6af4
commit
f99980052b
29 files changed
+38
-5018
No files matched your search
@@ -78,73 +78,6 @@ CLOUDFLARE_AUTO_BLOCK_ENABLED=true
|
||||
# Override for tests/staging (production uses the public endpoint by default).
|
||||
CLOUDFLARE_API_BASE_URL=https://api.cloudflare.com/client/v4
|
||||
|
||||
# --- CROWDSEC API (community reputation auto-block, optional) ---
|
||||
# Free CTI API key: https://app.crowdsec.net/ → Settings → CTI API Keys.
|
||||
# When set, the anti-DDoS gate checks the community reputation of repeat
|
||||
# offenders (CTI GET /smoke/{ip}) and immediately hard-blocks known-bad IPs.
|
||||
# Lookups only happen for IPs that already tripped a rate bucket and are
|
||||
# cached in Redis for 1h, so quota usage stays minimal.
|
||||
CROWDSEC_API_KEY=
|
||||
# Runtime toggle for reputation-based auto-blocking (also overridable live
|
||||
# from the admin panel). Requires CROWDSEC_API_KEY.
|
||||
CROWDSEC_AUTO_BLOCK_ENABLED=true
|
||||
# Minimum malevolence score 0-5 (CrowdSec scale; 4-5 = "malicious") before an
|
||||
# IP is treated as known-bad. IPs with false-positive tags are never blocked.
|
||||
CROWDSEC_BLOCK_SCORE=4
|
||||
# How long a CrowdSec-confirmed bad IP stays blocked (seconds).
|
||||
CROWDSEC_BLOCK_TTL_SECONDS=86400
|
||||
# Endpoint — override only for tests/staging.
|
||||
CROWDSEC_CTI_BASE_URL=https://cti.api.crowdsec.net/v2
|
||||
# Daily enrichment-call ceiling (freemium plan ≈ 10k/day). Once today's
|
||||
# counter reaches it, reputation lookups pause until tomorrow so a spread
|
||||
# DDoS cannot silently burn the whole quota. 0 = unlimited.
|
||||
CROWDSEC_CTI_DAILY_QUOTA=10000
|
||||
# How many new community-reputation blocks within a 5-minute window justify an
|
||||
# ops alert (quota/backoff/report alerts all use HEALTH_ALERT_COOLDOWN_MIN).
|
||||
CROWDSEC_ALERT_BLOCK_BURST=10
|
||||
|
||||
# --- CROWDSEC SIGNAL PUSH (share our blocks back, optional) ---
|
||||
# Opt-in: pushes blocked IPs + behaviors to the CrowdSec Central API (CAPI) so
|
||||
# the community blocklist protects other members too. Set to "true" to enable.
|
||||
# Requires watcher credentials — either set both CROWDSEC_REPORT_MACHINE_ID
|
||||
# (48 chars, [A-Za-z0-9]) and CROWDSEC_REPORT_PASSWORD now, or leave them
|
||||
# unset and let the app generate a stable pair persisted in Redis automatically.
|
||||
CROWDSEC_REPORT_ENABLED=false
|
||||
CROWDSEC_REPORT_MACHINE_ID=
|
||||
CROWDSEC_REPORT_PASSWORD=
|
||||
# Optional: attachment key from https://app.crowdsec.net → Console settings —
|
||||
# links our watcher to your account so pushed signals show up there.
|
||||
CROWDSEC_REPORT_ENROLL_KEY=
|
||||
# Central API base — override only for tests/staging.
|
||||
CROWDSEC_CAPI_BASE_URL=https://api.crowdsec.net/v3
|
||||
|
||||
# --- CROWDSEC LOCAL (opt-in engine on this Docker host, no proxy changes) ---
|
||||
# App-layer LAPI bouncer: the anti-DDoS gate asks the local engine per client
|
||||
# IP (short-cached) and blocks ban/captcha decisions before its own buckets.
|
||||
# Start everything with `bash cms security`; it writes the key below into .env
|
||||
# and starts the CrowdSec engine bound to 127.0.0.1. Set to "true" to load the
|
||||
# bouncer without the local engine (not recommended).
|
||||
CROWDSEC_LOCAL_ENABLED=false
|
||||
# Host access-log directory mounted into the engine for detection (Nginx only).
|
||||
CROWDSEC_NGINX_LOG_DIR=/var/log/nginx
|
||||
# Change LAPI port AND LAPI URL together when 18080 is already taken.
|
||||
CROWDSEC_LAPI_PORT=18080
|
||||
CROWDSEC_LAPI_URL=http://127.0.0.1:18080
|
||||
# Generated by `bash cms security`; keep in .env, never commit a value.
|
||||
CROWDSEC_LAPI_API_KEY=
|
||||
# IP blocklist sync (`bash cms security blocklists`): space-separated URLs, by
|
||||
# default Spamhaus DROP/EDROP, DShield, CINS, Greensnow, StopForumSpam,
|
||||
# blocklist.de, Emerging Threats, abuse.ch Feodo/SSLBL/URLhaus, IPsum,
|
||||
# Firehol ipsets and Tor exit nodes. Requires internet to fetch; detection and
|
||||
# blocking stay local.
|
||||
#CROWDSEC_BLOCKLIST_SOURCES=https://www.spamhaus.org/drop/drop.txt https://example.org/list.txt
|
||||
# Expiration for each blocklist decision (re-synced keeps them fresh).
|
||||
#CROWDSEC_BLOCKLIST_DURATION=24h
|
||||
# Combined cap per sync (safety valve against excessive decisions).
|
||||
#CROWDSEC_BLOCKLIST_MAX_DECISIONS=1000000
|
||||
# Comma-separated IPs/CIDRs that a sync must always skip (allowlist).
|
||||
#CROWDSEC_BLOCKLIST_ALLOW=1.2.3.4,10.0.0.0/8
|
||||
|
||||
# --- PATHS ---
|
||||
BADGE_UPLOAD_DIR=./public/assets/images/badges
|
||||
EMULATOR_JAR_PATH=./emulator/Arcturus.jar
|
||||
|
||||
Reference in new issue
Block a user