Skip to content

Add API rate limiting #669

Description

@bencap

Rate limiting is already enforced at the load balancer's firewall (AWS WAF). What's left is writing the setup down in the deployment repo, giving staging the same rule, deciding on a stricter limit for CSV downloads, and documenting the limit for API users.

Status

Prod enforces a per-IP rate limit at the WAF. The regional web ACL mavedb-prod-rate-limit, on the prod-api ALB, has:

  • rate-limit-ip: Block at 1500 requests per 5 minutes per IP, returning 429 with Retry-After: 300.
  • block-ai-crawlers-on-csv: Block. deployment#33 replaces it.
  • shadow-csv-endpoints: Count at 100 per 5 minutes on the CSV endpoints.
  • shadow-requests: Count at 300 per minute.

The limit was sized from a 90-day per-IP baseline, in which the mavedb.org UI peaked at 739 requests per IP per minute and browser embeds at 840.

Remaining scope

  • Record the web ACL and its rules in mavedb-deployment. It's managed in the console today and isn't in procedure.md.
  • Give staging the same enforced rule, so a change can be tested there first.
  • Decide whether to enforce the CSV limit, using the shadow-csv-endpoints counts.
  • Document the limit and the 429 response in the API Quickstart docs.

Acceptance criteria

  • The prod and staging web ACLs are described in mavedb-deployment, and the two match apart from thresholds.
  • The API docs state the per-IP limit and the Retry-After behavior.
  • The CSV-limit decision and its numbers are recorded in this issue.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

app: backendTask implementation touches the backend

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions