Skip to content

Repository files navigation

goalkeeper

Documentation crates.io Build unsafe forbidden

DoS and DDoS protection library.

Features

  • Custom tokio executor with task priorities
  • Connection count limits
  • Bandwidth limits/priorities
  • CPU limits/priorities
  • RAM limits/priorities
  • TLS handshake timeouts and concurrency limits
  • TCP timeouts, pacing, delaying, and buffer limits/priorities
  • HTTP timeouts and concurrency limits
  • Logging (log)
  • Metrics
  • nftables firewall configuration
  • OS network stack hardening

Protocols (feature flags)

  • HTTP/1 and HTTP/2 (hyper/axum)
  • WebSocket (axum-tws/tokio-websockets)
  • WebTransport (wtransport/quinn)
  • TLS for all of the above (rustls)

Limitations

  • Not optimized for multi-core runtimes
  • ~15% max throughput reduction

Status

Gradually migrating related functionality from other projects.

License

Licensed under either of

at your option.

Contribution

Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.

About

DDoS protection as a library

Resources

Stars

5 stars

Watchers

0 watching

Forks

Contributors

Languages