Skip to content

Gateway: env-configurable rate-limit skip prefixes for shared-NAT deployments - #259

Merged
kh0pper merged 1 commit into
mainfrom
rate-limit-skip-prefixes
Jul 29, 2026
Merged

Gateway: env-configurable rate-limit skip prefixes for shared-NAT deployments#259
kh0pper merged 1 commit into
mainfrom
rate-limit-skip-prefixes

Conversation

@kh0pper

@kh0pper kh0pper commented Jul 29, 2026

Copy link
Copy Markdown
Owner

The gateway general limiter keys per IP (200 req / 15 min). Where many clients share one NAT egress IP and arrive through an allowlisted reverse proxy, every client lands in the same bucket, and a burst of legitimate traffic 429s everyone at once (observed live: a training room of phones first-loading a public surface exhausted the shared bucket in seconds).

Adds GATEWAY_RATE_LIMIT_SKIP_PREFIXES: comma-separated extra path prefixes the general limiter skips, alongside the existing hardcoded skips. Default unset; behavior unchanged unless a deployment opts in. Auth and dashboard limiters untouched.

Verified live on the affected deployment: 300 consecutive burst requests to an exempted surface return 200; non-exempted paths keep existing limits.

…loyments

GATEWAY_RATE_LIMIT_SKIP_PREFIXES (comma-separated path prefixes) exempts
matching paths from the general per-IP limiter. Needed where many clients
sit behind one NAT IP and reach the gateway through an allowlisted reverse
proxy: per-IP buckets collapse into one shared bucket and a burst of
legitimate clients exhausts it collectively. Default unset; behavior
unchanged unless the env var is provided.
@kh0pper
kh0pper merged commit 22dd5fc into main Jul 29, 2026
3 checks passed
kh0pper added a commit that referenced this pull request Jul 31, 2026
GATEWAY_FUNNEL_PUBLIC_PREFIXES (comma-separated, same trailing-slash
semantics as PUBLIC_FUNNEL_PREFIXES) lets a deployment expose additional
public surfaces over Tailscale Funnel without patching the static list.
Default unset: behavior unchanged. Entries not starting with '/' are
dropped. Mirrors the GATEWAY_RATE_LIMIT_SKIP_PREFIXES pattern (#259).

Co-authored-by: kh0pper <kevin.hopper@maestro.press>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant