build: package standalone DWH authentication service

This commit is contained in:
User
2026-08-21 02:32:26 +02:00
parent 134dc1977c
commit 87606c73c1
7 changed files with 299 additions and 0 deletions
+13
View File
@@ -0,0 +1,13 @@
# Include this file from the nginx http {} context. The map emits only a
# public key ID for canonical v1 keys; all other input is one opaque class.
map $http_x_api_key $dwh_public_key_class {
default opaque;
"~^thtdwh_v1\.([A-Za-z0-9_-]{16})\.[A-Za-z0-9_-]{43}$" v1:$1;
}
# The secret is never part of this key. This limits each remote address and
# public credential identity/class to 20 requests per second.
map "$remote_addr:$dwh_public_key_class" $dwh_auth_rate_key {
default "$remote_addr:$dwh_public_key_class";
}
limit_req_zone $dwh_auth_rate_key zone=dwh_auth:10m rate=20r/s;