fix: sliding-window rate limits and TCP connection cap

This commit is contained in:
randogoth 2026-10-06 22:13:59 +03:00
parent 0c7311b068
commit fd847d035f
7 changed files with 198 additions and 48 deletions

View file

@ -323,6 +323,12 @@
description = "Max SEND operations per minute, per accept token.";
};
maxConnections = mkOption {
type = types.ints.unsigned;
default = 100;
description = "Max concurrently served TCP connections; past the cap connections are refused. 0 means unlimited.";
};
inviteToken = mkOption {
type = types.nullOr types.str;
default = null;
@ -476,6 +482,7 @@
rate_connections = cfg.rateConnections;
rate_sends = cfg.rateSends;
rate_tokens = cfg.rateTokens;
max_connections = cfg.maxConnections;
}
// lib.optionalAttrs (cfg.inviteToken != null) { invite_token = cfg.inviteToken; }
// lib.optionalAttrs (cfg.inviteTokenFile != null) {
@ -523,6 +530,7 @@
--rate-connections ${toString cfg.rateConnections}
--rate-sends ${toString cfg.rateSends}
--rate-tokens ${toString cfg.rateTokens}
--max-connections ${toString cfg.maxConnections}
)
${lib.optionalString cfg.rns.enable ''
args+=(