# Include this file from the nginx http {} context. The map emits only a # public key ID for canonical v1 keys; all other input is one opaque class. map $http_x_api_key $dwh_public_key_class { default opaque; "~^thtdwh_v1\.([A-Za-z0-9_-]{16})\.[A-Za-z0-9_-]{43}$" v1:$1; } # The secret is never part of this key. This limits each remote address and # public credential identity/class to 20 requests per second. map "$remote_addr:$dwh_public_key_class" $dwh_auth_rate_key { default "$remote_addr:$dwh_public_key_class"; } limit_req_zone $dwh_auth_rate_key zone=dwh_auth:10m rate=20r/s;