We are getting DoSed. I deployed an update with stricter rate limits and things seem to be improved.

Reply to this note

Please Login to reply.

Discussion

Traffic details pls. Just curious

It's just one IP hammering the Mastodon API. But this has never happened before so I didn't configure rate limits. It was easy to fix.

The blue spikes on the right are 429 errors after applying rate limits.

Are layer 7 attacks possible? I assume so, but idk the codebase. Just curious if you can horizontally scale away that problem.