Supplement · Nginx
Rate limiting và security
limit_req dùng leaky bucket theo key; rate điều tiết trung bình, burst/nodelay quyết định burst được queue hay cho qua. limit_conn bound concurrent connections theo key.
Trust boundary
- Key theo IP chỉ đúng khi real client IP được lấy từ trusted proxy; không trust header trực tiếp từ Internet.
- NAT có thể gom nhiều user vào một key; IPv6 privacy làm key biến động. Với authenticated API, tenant/user key thường tốt hơn.
- Giới hạn body/header, method, URI; không lộ dotfile, config, backup và internal location.
- Drop privilege, read-only filesystem khi có thể, patch module và giảm module surface.
- Trả 429/Retry-After có chủ đích; đo rejected/delayed để tuning.