Repository navigation
Remove iroh rate limiting: make limiter optional and fail open - #8714
Conversation
CMUX_IROH_RATE_LIMIT_ID was required on prod, and routeHandler ran the
Vercel firewall check whenever it was set. When the rate-limit rule was
deleted, the .well-known check returns 404 -> "not-found", and the old
`if (error)` branch turned that into a 503 iroh_service_unavailable on
every authed discover/challenge/register for every account. That blocked
off-tailnet iroh discovery entirely (the review Mac could not publish an
iroh binding; phones could not discover it).
Two changes so the limit can be removed cleanly:
- env: make CMUX_IROH_RATE_LIMIT_ID optional (z.string().min(1).optional()),
matching CMUX_PUSH_RATE_LIMIT_ID / CMUX_RELAY_PREFERENCES_RATE_LIMIT_ID.
Unsetting the var now skips the firewall gate instead of failing env
validation at boot.
- routeHandler: treat a missing rule ("not-found") as "no limit" and fail
open (continue to the broker) instead of 503. A deleted rule means the
operator removed the limit, not that the service is down. Genuine
unavailability (timeout / unexpected status) still fails closed via the
existing catch.
This makes the deploy itself clear the outage even before the env var is
unset, and prevents a deleted rule from ever bricking iroh again. Adds a
regression test asserting not-found fails open with a 200.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
📝 WalkthroughWalkthroughIroh rate-limit configuration is now optional. When the configured firewall rule is missing, the route logs a warning and continues the discovery request instead of returning 503. ChangesIroh rate-limit handling
Estimated code review effort: 2 (Simple) | ~10 minutes 🚥 Pre-merge checks | ✅ 25✅ Passed checks (25 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Greptile SummaryThis PR fixes a production outage where deleting the Vercel firewall rate-limit rule for iroh caused every
Confidence Score: 5/5Safe to merge — the change is narrowly scoped to the firewall error-handling path and restores the intended fail-open behaviour for a deleted rule while keeping the fail-closed path intact for genuine unavailability. The logic change is correct: the only reachable error values after the blocked check are not-found and undefined, so replacing the old catch-all with an explicit not-found guard covers the full type space. The catch block still returns 503 for throws, blocked/rateLimited still returns 429, and the env change is consistent with existing optional rate-limit IDs. The new test verifies the fail-open path end-to-end. No files require special attention. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Incoming iroh request] --> B{CMUX_IROH_RATE_LIMIT_ID set?}
B -- No --> G[Proceed to broker]
B -- Yes --> C[Run Vercel firewall check]
C -- throws / timeout --> D[503 iroh_service_unavailable]
C -- rateLimited=true or error=blocked --> E[429 rate_limited]
C -- error=not-found --> F[warn + fail open]
C -- no error --> G
F --> G
G --> H[Broker call]
H -- success --> I[200/201 response]
H -- error --> J[4xx/5xx error response]
Reviews (2): Last reviewed commit: "Assert firewall check ran in the fail-op..." | Re-trigger Greptile |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@web/tests/iroh-route-handler.test.ts`:
- Around line 68-94: Update the test “fails open when the configured rate-limit
rule no longer exists” to track a firewallCalled flag within the injected
firewall.check implementation, then assert it is true alongside the existing
response and broker assertions. Preserve the current not-found result and
fail-open behavior.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 2f9a0eff-636d-4253-8511-5e78ed21dc40
📒 Files selected for processing (3)
web/app/env.tsweb/services/iroh/routeHandler.tsweb/tests/iroh-route-handler.test.ts
Addresses CodeRabbit: the not-found fail-open test would still pass if handleIrohRoute skipped the injected firewall entirely. Track a firewallCalled flag inside check and assert it, so the regression proves the not-found path specifically (firewall ran, returned not-found, handler failed open to the broker). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Problem
CMUX_IROH_RATE_LIMIT_IDwas required on prod, androuteHandler.tsran the Vercel firewall check on every authed iroh op whenever that env was set. When the rate-limit rule was deleted from the Vercel firewall (the owner removed iroh limiting), the.well-known/vercel/rate-limit-api/<id>check returns 404 →firewall.tsmaps it toerror: "not-found"→ the oldif (error)branch returned 503iroh_service_unavailableon everydiscover/challenge/register, for all accounts, before the broker was ever reached.That took off-tailnet iroh discovery down entirely: the review Mac could not publish an iroh binding, and phones off the tailnet could not discover it.
/api/devices(a plain registry read) kept returning 200, which is why only the iroh endpoints were affected.Fix
CMUX_IROH_RATE_LIMIT_IDoptional (z.string().min(1).optional()), matching the existing optional rate-limit IDs (CMUX_PUSH_RATE_LIMIT_ID,CMUX_RELAY_PREFERENCES_RATE_LIMIT_ID). Unsetting the var now skips the firewall gate instead of failing env validation at boot."not-found") as "no limit" and fail open (continue to the broker) instead of 503. A deleted rule means the operator removed the limit, not that the service is down. Genuine unavailability (firewall timeout / unexpected status) still fails closed via the existingcatch, and"blocked"/rateLimitedstill return 429.Deploying this clears the outage on its own, even before the env var is unset, and prevents a deleted rule from ever bricking iroh again. After deploy the owner can unset
CMUX_IROH_RATE_LIMIT_IDin Vercel prod to fully remove the gate.Test
Adds
fails open when the configured rate-limit rule no longer exists— asserts anot-foundresult reaches the broker and returns 200. Existing fail-closed tests (firewall reject / never-settles → 503) and the 429/blocked path are unchanged. Full file: 14 pass,bun run typecheckclean.Need help on this PR? Tag
/codesmithwith what you need. Autofix is disabled.Summary by cubic
Make iroh rate limiting optional and fail open when the Vercel firewall rule is missing. This prevents 503s and restores off‑tailnet iroh discovery when a rate-limit rule is deleted.
CMUX_IROH_RATE_LIMIT_IDoptional; when unset, the firewall check is skipped.error: "not-found"as “no limit” and continued to the broker; still return 429 forblocked/rate-limited and fail closed on timeouts/unexpected errors.not-foundreaches the broker and the firewall check ran, returning 200.Written for commit feaeb36. Summary will update on new commits.
Summary by CodeRabbit
Bug Fixes
Tests