diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 61b6f174..fe7fe6dc 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -98,7 +98,7 @@ jobs: node-version: "22" - uses: astral-sh/setup-uv@v5 - name: Install wrangler - run: npm install -g wrangler@3 + run: npm install -g wrangler@4 - name: Generate test secrets # Required by `load_config` in src/config.rs (`JwtSigner::from_pem` and # `TokenKey::from_base64` validate at startup). The signing key is a diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 39261721..2ea48fb5 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -91,7 +91,7 @@ jobs: name: worker-build-${{ github.run_id }}-${{ github.run_attempt }} path: build/ # Installed separately so the package resolution is uncredentialed too. - - run: npm install -g wrangler@3 + - run: npm install -g wrangler@4 - name: Override service bindings if: inputs.service_overrides != '' diff --git a/.github/workflows/preview.yml b/.github/workflows/preview.yml index 4aac62be..860fe623 100644 --- a/.github/workflows/preview.yml +++ b/.github/workflows/preview.yml @@ -76,7 +76,7 @@ jobs: runs-on: ubuntu-latest steps: # Installed separately so the package resolution is uncredentialed too. - - run: npm install -g wrangler@3 + - run: npm install -g wrangler@4 - name: Delete preview worker env: CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} diff --git a/README.md b/README.md index f502c343..088bf527 100644 --- a/README.md +++ b/README.md @@ -14,7 +14,7 @@ The proxy supports `GET`, `HEAD`, and S3-compatible `LIST` operations with anony ```sh rustup target add wasm32-unknown-unknown cargo install worker-build@0.7.5 -npm install -g wrangler@3 +npm install -g wrangler@4 ``` ### Run Locally @@ -120,7 +120,7 @@ Set in `wrangler.toml` or via the Cloudflare dashboard: | Binding | Kind | Description | | -------------------- | ----------- | -------------------------------------------------------------------------------------------------------------------------------------------- | -| `KEY_EXCHANGE_LIMIT` | `ratelimit` | Per-client-IP limit on API-key exchanges at `/.sts` (ADR-013). Declared under `[[unsafe.bindings]]` in every `wrangler*.toml`; a deployment without it logs an error and exchanges without a limit | +| `KEY_EXCHANGE_LIMIT` | `ratelimit` | Per-client-IP limit on API-key exchanges at `/.sts` (ADR-013). Declared under `[[ratelimits]]` in every `wrangler*.toml`; a deployment without it logs an error and exchanges without a limit | ### API keys diff --git a/wrangler.preview.toml b/wrangler.preview.toml index 323e9f6f..b5ae42fb 100644 --- a/wrangler.preview.toml +++ b/wrangler.preview.toml @@ -49,8 +49,7 @@ binding = "PUBLIC_LOG_STREAM" service = "public-log-stream-staging" # API-key exchange rate limit, per client IP; see wrangler.toml. -[[unsafe.bindings]] +[[ratelimits]] name = "KEY_EXCHANGE_LIMIT" -type = "ratelimit" namespace_id = "1003" simple = { limit = 100, period = 60 } diff --git a/wrangler.toml b/wrangler.toml index 6b10f65d..da445edf 100644 --- a/wrangler.toml +++ b/wrangler.toml @@ -71,9 +71,8 @@ service = "public-log-stream" # API one lookup for a distinct key, so this bounds a flood of junk keys from # one place; a legitimate client exchanges about once a session, so even a # cluster behind one NAT stays far under it. See src/lib.rs `api_key_exchange`. -[[unsafe.bindings]] +[[ratelimits]] name = "KEY_EXCHANGE_LIMIT" -type = "ratelimit" namespace_id = "1001" simple = { limit = 100, period = 60 } @@ -100,9 +99,8 @@ dataset = "source_data_proxy_staging" binding = "PUBLIC_LOG_STREAM" service = "public-log-stream-staging" -[[env.staging.unsafe.bindings]] +[[env.staging.ratelimits]] name = "KEY_EXCHANGE_LIMIT" -type = "ratelimit" namespace_id = "1002" simple = { limit = 100, period = 60 }