docs(self-hosting): document the v2 per-IP limit that applies without billing - #8453
Rajkumar2002-Rk wants to merge 1 commit into
Conversation
|
@Rajkumar2002-Rk is attempting to deploy a commit to the Sim Team on Vercel. A member of the Team first needs to authorize it. |
|
| </Callout> | ||
|
|
||
| <Callout type="info"> | ||
| One limit applies regardless of billing: the v2 API (`/api/v2/...`) allows each client IP a burst of 600 requests, then 300 per minute, checked before authentication. `BILLING_ENABLED` and the variables above don't change it. With Docker Compose, requests from the host machine all arrive from the bridge gateway address and share one budget. Behind a reverse proxy, set `AUTH_TRUSTED_PROXIES` so each client is counted by its own address. |
There was a problem hiding this comment.
“One limit applies regardless of billing” makes the v2 limit sound like the only exception. Other routes have independent limits too: the contact endpoint, for example, enforces a per-IP limit. Operators investigating a 429 on those routes could mistakenly look to the listed plan variables for a way to change it. Please avoid presenting the v2 limit as the sole exception.
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
Summary
The Limits section says self-hosted installs with billing disabled have "no rate limits", but the v2 API always enforces a fixed per-IP limit before auth (
V2_PREAUTH_IP_LIMITinapps/sim/lib/api/server/routes/v2-json-route.ts: 600 burst, 300 per minute). This changes "no rate limits" to "no plan rate limits" and adds a short note on that limit, how it behaves with Docker Compose, andAUTH_TRUSTED_PROXIESbehind a reverse proxy.Refs #8452
Type of Change
Testing
Docs only. Checked the numbers against
V2_PREAUTH_IP_LIMITonstaging, and reproduced the limit on a self-hosted install with billing off: 800 quick requests toPOST /api/v2/workflows/{id}/executewith an invalid key gave 600 × 401, then 429 withx-ratelimit-limit: 600.Checklist