From 4a722259a588715bc96b73fd9de890ead9992285 Mon Sep 17 00:00:00 2001 From: loki5512344 Date: Fri, 9 Oct 2026 22:26:27 +0200 Subject: [PATCH] deploy(nginx): serve the mod jar from nginx with a speed cap (750k per connection) and 2 connections per IP --- backend/deploy/nginx-lovisual-downloads.conf | 2 ++ backend/deploy/nginx-visual.loki-code.dev.conf | 17 +++++++++++++++++ 2 files changed, 19 insertions(+) create mode 100644 backend/deploy/nginx-lovisual-downloads.conf diff --git a/backend/deploy/nginx-lovisual-downloads.conf b/backend/deploy/nginx-lovisual-downloads.conf new file mode 100644 index 00000000..7c312800 --- /dev/null +++ b/backend/deploy/nginx-lovisual-downloads.conf @@ -0,0 +1,2 @@ +# Per-client-IP connection counter for the capped jar download (see the site conf). +limit_conn_zone $binary_remote_addr zone=lv_downloads:10m; diff --git a/backend/deploy/nginx-visual.loki-code.dev.conf b/backend/deploy/nginx-visual.loki-code.dev.conf index 133701b4..20f0b15f 100644 --- a/backend/deploy/nginx-visual.loki-code.dev.conf +++ b/backend/deploy/nginx-visual.loki-code.dev.conf @@ -18,6 +18,23 @@ server { add_header Cache-Control "public, max-age=60" always; } + # The mod jar is served by nginx itself (not through the gateway) so the + # speed can be capped: ~6 Mbit/s per connection and at most 2 connections + # per client IP keep a flood of downloads from saturating the link. + location = /api/downloads/lovisual.jar { + alias /opt/lovisual/backend/downloads/lovisual.jar; + default_type application/java-archive; + add_header Content-Disposition 'attachment; filename="lovisual.jar"' always; + limit_rate 750k; + limit_conn lv_downloads 2; + limit_conn_status 429; + } + + location = /api/downloads/lovisual.jar.sha256 { + alias /opt/lovisual/backend/downloads/lovisual.jar.sha256; + default_type text/plain; + } + location /api/ { proxy_pass http://127.0.0.1:8080/; proxy_http_version 1.1;