feat: VDS stress test harness (edge-only) and load-test results
- deploy/test/stress/: multi-IP masked handshake flood (flood.py), legit client during attack (legit.py), full orchestration (run-stress.sh), edge Dockerfile with socat stub backend and high/defense configs - docs/research/load-test-report.md: v3 VDS loopback results (2026-08-04) - README.md: performance table update (4k conn/s raw, 99.6% blocked in defense, legit clients RTT 2-6ms during attack) - docs/testing.md: multi-IP masked stress-test procedure
This commit is contained in:
parent
d41bd6e815
commit
0b53ed720b
11 changed files with 660 additions and 0 deletions
14
README.md
14
README.md
|
|
@ -75,6 +75,20 @@ Tested on Hetzner CX31 (4 vCPU, 8GB, KVM), Ubuntu 22.04, kernel 5.15
|
|||
|
||||
Note: Real L7 throughput (handshake + HMAC + rate limit): ~60-70k conn/s (epoll), ~85-95k (io_uring).
|
||||
|
||||
#### VDS stress test (2026-08-04) — edge-only, loopback
|
||||
|
||||
VDS 2 vCPU / 3.8GB / Ubuntu 22.04, Docker bridge. Edge-only (слои 1–3), без Redis/Velocity/Paper.
|
||||
Атака маскировалась под обычный трафик: 100 source IP, валидные Minecraft handshake.
|
||||
Подробности: [load-test-report.md](docs/research/load-test-report.md), скрипты: [deploy/test/stress](deploy/test/stress).
|
||||
|
||||
| Scenario | Result |
|
||||
|----------|--------|
|
||||
| Raw L7 throughput (valid handshake → HMAC → backend) | ~4k conn/s proxied, 100% (121.5k/30s; edge CPU ~179%, 2 cores) |
|
||||
| Defense vs masked 100-IP flood (default 5 pps/IP) | **99.6% blocked** (528 allowed vs 119,376 blocked), CPU ~32% |
|
||||
| Legit clients during attack | 5/5 OK, RTT 2.2–5.8ms |
|
||||
| SYN flood (no XDP) | 0 impact — handled by kernel |
|
||||
| Active connections | 300 held trivially (CPU ~0%, 7MB); limit is backend/fd, not edge |
|
||||
|
||||
### Quick Start
|
||||
|
||||
```bash
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue