From 50000cd9d47681390c3c45feef98fe51c7b79a0f Mon Sep 17 00:00:00 2001 From: DanConwayDev Date: Wed, 14 Jan 2026 11:42:05 +0000 Subject: Add explicit rate limits and total connection limit MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Make RateLimit explicit in relay builder (500 subs, 60 events/min) - Add NGIT_MAX_CONNECTIONS config option (default: 500) - Update all 4 config locations (src, nix, docs, .env.example) - Fix documentation error: filter limit 5000→500 - Document Phase 2 deferral decision (per-IP enforcement) Addresses primary DoS vector (connection exhaustion) with minimal code. Per-IP rate limiting deferred until abuse detected in production. Related: issue ff38 (git endpoint throttling - separate concern) --- .env.example | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) (limited to '.env.example') diff --git a/.env.example b/.env.example index 707efd4..953ae93 100644 --- a/.env.example +++ b/.env.example @@ -277,4 +277,14 @@ # Examples: # NGIT_EVENT_BLACKLIST=npub1spam... # NGIT_EVENT_BLACKLIST=npub1spam...,npub1abuser... -# NGIT_EVENT_BLACKLIST= \ No newline at end of file +# NGIT_EVENT_BLACKLIST= + +# ============================================================================ +# RATE LIMITING & DOS PROTECTION +# ============================================================================ + +# Maximum total connections to the relay +# Prevents connection exhaustion DoS attacks +# CLI: --max-connections +# Default: 500 +# NGIT_MAX_CONNECTIONS=500 \ No newline at end of file -- cgit v1.2.3