Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -98,7 +98,7 @@ jobs:
node-version: "22"
- uses: astral-sh/setup-uv@v5
- name: Install wrangler
run: npm install -g wrangler@3
run: npm install -g wrangler@4
- name: Generate test secrets
# Required by `load_config` in src/config.rs (`JwtSigner::from_pem` and
# `TokenKey::from_base64` validate at startup). The signing key is a
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/deploy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -91,7 +91,7 @@ jobs:
name: worker-build-${{ github.run_id }}-${{ github.run_attempt }}
path: build/
# Installed separately so the package resolution is uncredentialed too.
- run: npm install -g wrangler@3
- run: npm install -g wrangler@4

- name: Override service bindings
if: inputs.service_overrides != ''
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/preview.yml
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,7 @@ jobs:
runs-on: ubuntu-latest
steps:
# Installed separately so the package resolution is uncredentialed too.
- run: npm install -g wrangler@3
- run: npm install -g wrangler@4
- name: Delete preview worker
env:
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
Expand Down
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ The proxy supports `GET`, `HEAD`, and S3-compatible `LIST` operations with anony
```sh
rustup target add wasm32-unknown-unknown
cargo install worker-build@0.7.5
npm install -g wrangler@3
npm install -g wrangler@4
```

### Run Locally
Expand Down Expand Up @@ -120,7 +120,7 @@ Set in `wrangler.toml` or via the Cloudflare dashboard:

| Binding | Kind | Description |
| -------------------- | ----------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| `KEY_EXCHANGE_LIMIT` | `ratelimit` | Per-client-IP limit on API-key exchanges at `/.sts` (ADR-013). Declared under `[[unsafe.bindings]]` in every `wrangler*.toml`; a deployment without it logs an error and exchanges without a limit |
| `KEY_EXCHANGE_LIMIT` | `ratelimit` | Per-client-IP limit on API-key exchanges at `/.sts` (ADR-013). Declared under `[[ratelimits]]` in every `wrangler*.toml`; a deployment without it logs an error and exchanges without a limit |

### API keys

Expand Down
3 changes: 1 addition & 2 deletions wrangler.preview.toml
Original file line number Diff line number Diff line change
Expand Up @@ -49,8 +49,7 @@ binding = "PUBLIC_LOG_STREAM"
service = "public-log-stream-staging"

# API-key exchange rate limit, per client IP; see wrangler.toml.
[[unsafe.bindings]]
[[ratelimits]]
name = "KEY_EXCHANGE_LIMIT"
type = "ratelimit"
namespace_id = "1003"
simple = { limit = 100, period = 60 }
6 changes: 2 additions & 4 deletions wrangler.toml
Original file line number Diff line number Diff line change
Expand Up @@ -71,9 +71,8 @@ service = "public-log-stream"
# API one lookup for a distinct key, so this bounds a flood of junk keys from
# one place; a legitimate client exchanges about once a session, so even a
# cluster behind one NAT stays far under it. See src/lib.rs `api_key_exchange`.
[[unsafe.bindings]]
[[ratelimits]]
name = "KEY_EXCHANGE_LIMIT"
type = "ratelimit"
namespace_id = "1001"
simple = { limit = 100, period = 60 }

Expand All @@ -100,9 +99,8 @@ dataset = "source_data_proxy_staging"
binding = "PUBLIC_LOG_STREAM"
service = "public-log-stream-staging"

[[env.staging.unsafe.bindings]]
[[env.staging.ratelimits]]
name = "KEY_EXCHANGE_LIMIT"
type = "ratelimit"
namespace_id = "1002"
simple = { limit = 100, period = 60 }

Expand Down
Loading