Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Failing after 17s
CI / tests-unit (push) Skipped
CI / tests-integration (push) Skipped
CI / tests-ui (push) Skipped
CI / preflight (push) Skipped
CI / deploy (push) Skipped
- new crowdsec-api lib: CTI lookup (GET /smoke/{ip}, freemium x-api-key), verdict parser with false-positive veto, 1h Redis + in-memory verdict cache, NX lock dedupe, 403/429 backoff; writes only the shared antiddos:block:{ip} key (value "crowdsec") and never touches Cloudflare
- gate fires it fire-and-forget for IPs that already tripped a rate bucket, so known-bad IPs are hard-blocked before the local maxViolations threshold
- runtime config: crowdsecAutoBlock toggle, score threshold (0-5, default 4), block TTL (default 24h); boot defaults CROWDSEC_AUTO_BLOCK_ENABLED / CROWDSEC_BLOCK_SCORE / CROWDSEC_BLOCK_TTL_SECONDS
- admin panel: CrowdSec stat card, verify-connection action, score/TTL settings, CrowdSec source badge in the blocked-IPs list
- credentials live in env only (CROWDSEC_API_KEY); block is enforced per-request via proxy on the resolved X-Forwarded-For / CF-Connecting-IP
- tests: crowdsec-api unit suite + ddos-guard integration suite (early-block, threshold, cache dedupe, backoff)
137 lines
5.1 KiB
Bash
137 lines
5.1 KiB
Bash
# ==============================================================================
|
|
# Epicnextcms — Ultimate Speed & Low-Latency Example Configuration
|
|
# ==============================================================================
|
|
|
|
# --- DATABASE (High Performance Pooling & Strict Timeouts) ---
|
|
DATABASE_URL="mysql://user:password@localhost:3306/dbname?charset=utf8mb4&connection_limit=150&connect_timeout=5"
|
|
DATABASE_POOL_SIZE=150
|
|
DATABASE_IDLE_TIMEOUT_MS=60000
|
|
DATABASE_CONNECT_TIMEOUT_MS=5000
|
|
|
|
# --- REDIS (Lightning Fast Caching & Sessions) ---
|
|
REDIS_URL=redis://127.0.0.1:6379?connect_timeout=2
|
|
REDIS_CACHE_TTL_DEFAULT=7200
|
|
|
|
# --- CORE RUNTIME & PERFORMANCE FLAGS ---
|
|
NODE_ENV=production
|
|
PORT=3002
|
|
NEXT_TELEMETRY_DISABLED=1
|
|
UV_THREADPOOL_SIZE=16
|
|
# Production requires this kill switch plus housekeeping.preview.access.
|
|
HOUSEKEEPING_NEXT_PREVIEW_ENABLED=false
|
|
|
|
# --- HOTEL & URLS ---
|
|
HOTEL_NAME=EPIC WEB CONTROL
|
|
APP_URL=http://localhost:3002
|
|
AUTH_URL=http://localhost:3002
|
|
|
|
# --- IMAGER ---
|
|
# Avatar imager: Polaris-imager (avatar-imaging-pixinode) serves /avatarimage on 8082.
|
|
IMAGING_UPSTREAM_URL=http://127.0.0.1:8082/avatarimage
|
|
# Runtime values: changing these only requires recreating the container.
|
|
IMAGER_URL=http://127.0.0.1:8082/avatarimage
|
|
BADGE_URL=/swf/c_images/album1584
|
|
# Legacy NEXT_PUBLIC_IMAGER_URL / NEXT_PUBLIC_BADGE_URL are still read at runtime.
|
|
|
|
# --- SECURITY & HASHING ---
|
|
AUTH_SECRET=your-super-secret-auth-key-change-this-min-32-chars
|
|
APP_KEY=base64:your-app-key-here=
|
|
# Bcrypt cost factor for new password hashes.
|
|
BCRYPT_COST=12
|
|
|
|
# --- ANTI-DDOS (app-layer gate, production only) ---
|
|
# On by default in production. Set to "false" to disable (not recommended).
|
|
ANTI_DDOS_ENABLED=true
|
|
# Per-category request thresholds over the given window (per client IP).
|
|
ANTI_DDOS_PAGES_LIMIT=300
|
|
ANTI_DDOS_PAGES_WINDOW_SEC=60
|
|
ANTI_DDOS_API_LIMIT=600
|
|
ANTI_DDOS_API_WINDOW_SEC=60
|
|
ANTI_DDOS_AUTH_LIMIT=20
|
|
ANTI_DDOS_AUTH_WINDOW_SEC=60
|
|
# Whole-site safety valve per window (sheds everything for global_halt_ms when hit).
|
|
ANTI_DDOS_GLOBAL_LIMIT=18000
|
|
ANTI_DDOS_GLOBAL_WINDOW_SEC=60
|
|
ANTI_DDOS_GLOBAL_HALT_MS=10000
|
|
# Violations accumulate inside this window before an IP is hard-blocked.
|
|
ANTI_DDOS_VIOLATION_WINDOW_SEC=600
|
|
ANTI_DDOS_MAX_VIOLATIONS=10
|
|
# Escalation tiers "minViolations:ttlSeconds" — how long an offender stays blocked.
|
|
ANTI_DDOS_BLOCK_TIERS=5:600,20:3600,50:86400
|
|
|
|
# --- CLOUDFLARE API (automatic edge blocks, optional) ---
|
|
# When set, the anti-DDoS gate automatically mirrors hard-blocked IPs to the
|
|
# zone's IP Access Rules so repeat offenders are dropped at the Cloudflare
|
|
# edge (works on every plan, incl. Free). Token permissions required:
|
|
# Zone > Zone > Read and Zone > Firewall > Edit
|
|
CLOUDFLARE_API_TOKEN=
|
|
CLOUDFLARE_ZONE_ID=
|
|
# Runtime toggle; leave true to auto-create Cloudflare blocks at the block
|
|
# threshold. Also overridable live from the admin panel.
|
|
CLOUDFLARE_AUTO_BLOCK_ENABLED=true
|
|
# Override for tests/staging (production uses the public endpoint by default).
|
|
CLOUDFLARE_API_BASE_URL=https://api.cloudflare.com/client/v4
|
|
|
|
# --- CROWDSEC API (community reputation auto-block, optional) ---
|
|
# Free CTI API key: https://app.crowdsec.net/ → Settings → CTI API Keys.
|
|
# When set, the anti-DDoS gate checks the community reputation of repeat
|
|
# offenders (CTI GET /smoke/{ip}) and immediately hard-blocks known-bad IPs.
|
|
# Lookups only happen for IPs that already tripped a rate bucket and are
|
|
# cached in Redis for 1h, so quota usage stays minimal.
|
|
CROWDSEC_API_KEY=
|
|
# Runtime toggle for reputation-based auto-blocking (also overridable live
|
|
# from the admin panel). Requires CROWDSEC_API_KEY.
|
|
CROWDSEC_AUTO_BLOCK_ENABLED=true
|
|
# Minimum malevolence score 0-5 (CrowdSec scale; 4-5 = "malicious") before an
|
|
# IP is treated as known-bad. IPs with false-positive tags are never blocked.
|
|
CROWDSEC_BLOCK_SCORE=4
|
|
# How long a CrowdSec-confirmed bad IP stays blocked (seconds).
|
|
CROWDSEC_BLOCK_TTL_SECONDS=86400
|
|
# Endpoint — override only for tests/staging.
|
|
CROWDSEC_CTI_BASE_URL=https://cti.api.crowdsec.net/v2
|
|
|
|
# --- PATHS ---
|
|
BADGE_UPLOAD_DIR=./public/assets/images/badges
|
|
EMULATOR_JAR_PATH=./emulator/Arcturus.jar
|
|
EMULATOR_BACKUP_DIR=./backups/emulator
|
|
EMULATOR_BACKUP_KEEP=7
|
|
# Optional mysqldump (jobs-worker daily 03:30). Requires mysqldump on PATH.
|
|
DB_BACKUP_DIR=
|
|
DB_BACKUP_KEEP=7
|
|
# Minutes between repeat health-fail alerts from jobs-worker (default 15).
|
|
HEALTH_ALERT_COOLDOWN_MIN=15
|
|
|
|
# --- RCON (Low Latency Loop) ---
|
|
RCON_HOST=127.0.0.1
|
|
RCON_PORT=3003
|
|
EMU_PORT=3004
|
|
RCON_TIMEOUT_MS=2000
|
|
|
|
# --- EMAIL & NOTIFICATIONS ---
|
|
SMTP_HOST=
|
|
SMTP_PORT=587
|
|
SMTP_USER=
|
|
SMTP_PASSWORD=
|
|
SMTP_FROM=[email protected]
|
|
|
|
# --- ALERTING & MONITORING ---
|
|
DISCORD_WEBHOOK_URL=
|
|
ALERT_EMAIL=
|
|
|
|
# --- MODERATION & PAYMENTS ---
|
|
OPENAI_API_KEY=
|
|
PAYPAL_CLIENT_ID=
|
|
PAYPAL_SECRET=
|
|
PAYPAL_API=https://api-m.sandbox.paypal.com
|
|
|
|
# --- LOGGING ---
|
|
LOG_LEVEL=error
|
|
|
|
# --- BYPARR (Cloudflare bypass for clone sources) ---
|
|
BYPARR_URL=http://localhost:8191
|
|
|
|
# Catalog Studio export: dedicated clean clone on Beta-3 with Git push credentials.
|
|
CATALOG_GIT_CHECKOUT=
|
|
# Persistent directory shared by CMS and worker, outside the catalog clone.
|
|
CATALOG_GIT_STATE_DIR=
|