Add an IP blocklist and a per-client rate limit #8
Loading…
Reference in a new issue
No description provided.
Delete branch "ip-reputation-rate-limit"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Two checks that judge the client rather than the request. Both run before the WAF, cost no model call, and are off until configured.
Pipeline order is now: shunned client, IP blocklist, bypass prefix, rate limit, WAF, verdict cache, gate, model.
IP blocklist
CENTINELA_IP_BLOCKLISThttp(s)URLsCENTINELA_IP_BLOCKLIST_REFRESH1h#and;start a comment. Spamhaus DROP and FireHOL netsets load as published.403, sourceip-reputation, on every path including bypass prefixes.Rate limit
CENTINELA_RATE_LIMIT0(off)CENTINELA_RATE_WINDOW1mCENTINELA_RATE_LIMIT_EXEMPT429withRetry-After; the forward-auth endpoint answers403, the only refusal an auth subrequest carries. Sourcerate-limit.client rate limitedline per client per window, not one per refused request. Refused requests are still counted in/debug/vars.Limits
CENTINELA_CLIENT_IP_HEADER.CENTINELA_RATE_LIMIT_EXEMPT.Tests
internal/iplist: parsing both comment styles, IPv4/IPv6/mapped lookups, file and URL sources, refresh picking up changes, a failed refresh and an error page keeping the last good copy, startup with a missing file and with a feed that is down.429withRetry-Afterand never reaches the upstream.make vet,make buildandmake test(race detector) pass.Merging to
mainrunsbuild-and-push, which tags and publishes the next patch version.🔎 ojo scan results
Details (7)