3 ms·
What are approaches to you prevent DoS attacks with such an architecture? It seems trivial for an attacker to generate super expensive queries en masse. Strict
by polycaster 5y ago
What are approaches to you prevent DoS attacks with such an architecture? It seems trivial for an attacker to generate super expensive queries en masse.
Strict row limits could bring some relief but don't solve the problem.
I bet there are solutions for this but it's not very obvious. Would someone briefly explain?
- steve76 5y agoYou can put traefik in front of it and cache. Then setup a max limit on query execution. I don't use REST. Everything I need I write out as a postgres function. The other side is monitoring. Setup logging and run fail2ban, or an alarm to kick the user and require manual oversight.
- kiwicopple 5y agoSupabase uses Kong (https://konghq.com/kong/ https://konghq.com/kong/) as an API gateway, which has a Rate-limiting plugin (https://docs.konghq.com/hub/kong-inc/rate-limiting/ https://docs.konghq.com/hub/kong-inc/rate-limiting/) Our platform is also behind Cloudflare to protect agains DDoS, and we hope to use this to add some smart caching for the API service