fix(auth): 公开登录门按来源限速并设全站发信上限,冷却表定期清理

This commit is contained in:
Lemon-miaow committed 2026-09-24 15:51:42 +08:00
1 parent 15f729ffea
commit c4e4953f3d
26 files changed
+1141 -64

No files matched your search

+46
View File
@@ -98,3 +98,49 @@ spec:
--collector.textfile.directory at the directory of
FELIS_DB_BACKUP_METRICS (default /var/lib/node_exporter/textfile_collector)
(troubleshooting §16).
- name: felis.auth.rules
rules:
- alert: FelisMailBudgetExhausted
expr: sum(increase(felis_mail_total{result="throttled"}[15m])) > 0
labels:
severity: warning
annotations:
summary: "the install-wide mail budget refused mail"
description: >-
felis_mail_total{result="throttled"} increased: [smtp] max_per_hour is
spent, and every sign-in code is refused with 429 mail_rate_limited until
it refills. Check felis_rate_limited_total for a flood before raising the
budget (troubleshooting §17).
- alert: FelisMailDeliveryFailing
expr: sum(increase(felis_mail_total{result="failed"}[15m])) > 0
labels:
severity: warning
annotations:
summary: "the SMTP relay refused mail in the last 15m"
description: >-
felis_mail_total{result="failed"} increased: sign-in codes are not being
delivered (502 mail_undeliverable). The relay's reason is in the
felis-api log (troubleshooting §17).
- alert: FelisSignInFlood
expr: sum(rate(felis_rate_limited_total{scope="auth_door"}[5m])) * 60 > 10
for: 10m
labels:
severity: warning
annotations:
summary: "sign-in doors refusing over 10 requests a minute"
description: >-
The per-address sign-in limit has been refusing callers for 10 minutes.
A script is hammering the auth doors; if real users report rate_limited
at once instead, [auth] client_ip_header is missing and everyone shares
the proxy's address (troubleshooting §17).
- alert: FelisOTPAccountLocked
expr: sum by (purpose) (increase(felis_auth_otp_lockouts_total[1h])) > 0
labels:
severity: warning
annotations:
summary: "an account's email-code sign-in locked after 10 wrong codes"
description: >-
Someone entered 10 wrong codes for one account within 24h ({{ $labels.purpose }}).
The audit log names the account (action auth.otp.locked); the owner was
mailed. Unless they fumbled codes, someone is guessing at it
(troubleshooting §17).