Add TLS handshake timeout (review #010 C3)
tls_handshake_timeout_secs (default 10s, must be > 0) wraps tls_acceptor.accept() in tokio::time::timeout so stalled handshakes (slowloris / crawler slow-handshake vector) can no longer hold an FD + semaphore permit indefinitely. Config plumbing through FullConfig / StaticConfig / validation / reload diff + docs.
This commit is contained in:
1 parent
978a362536
commit
9e26295cf7
11 files changed
+352
-19
No files matched your search
@@ -116,6 +116,7 @@ Configuration uses TOML and is split into **static** (requires restart) and
|
||||
| `admin_key_path` | `/etc/reverse-proxy/admin-key` | Path to admin Bearer token file (empty string to disable) |
|
||||
| `shutdown_timeout_secs` | `30` | Graceful shutdown timeout |
|
||||
| `connection_idle_timeout_secs` | `60` | Server-side idle timeout for client TLS connections (prevents FD exhaustion from abandoned connections) |
|
||||
| `tls_handshake_timeout_secs` | `10` | Max seconds to complete the TLS handshake; stalled handshakes are closed (prevents slowloris FD/permit exhaustion) |
|
||||
| `max_connections` | `1024` | Max concurrent client TLS connections (backpressure via semaphore) |
|
||||
| `logging.level` | `"info"` | Log level |
|
||||
| `logging.format` | `"text"` | Log format (`"text"` or `"json"`) |
|
||||
|
||||
Reference in new issue
Block a user