public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
From: Michael Tremer <michael.tremer@ipfire.org>
To: Matthias Fischer <matthias.fischer@ipfire.org>
Cc: "IPFire: Development-List" <development@lists.ipfire.org>,
	"IPFire: Infrastructure-List" <infrastructure@lists.ipfire.org>
Subject: Re: Oh noes!
Date: Thu, 30 Apr 2026 10:18:23 +0100	[thread overview]
Message-ID: <6020CC4F-814B-4778-9E98-F002A960F1B9@ipfire.org> (raw)
In-Reply-To: <4d364274-4a77-438f-902c-f31a653630e9@ipfire.org>

[-- Attachment #1: Type: text/plain, Size: 1983 bytes --]

Hello Matthias,

I am adding the list to this conversation… The screenshot just contains a random ID and an error message. That is all.

So, what has happened here is the following:

Since we have so many people attacking us, I have added a large list of providers (mostly from the Middle East) and entire countries to use Anubis. That way, we completely deflect the attack from our web applications and that works well.

I never wanted Anubis to become a SPoF and therefore installed multiple machines that are handling the Anubis traffic. What I thought was stateless is actually not. So the problem that you were seeing was that one instance sent you the PoW challenge and another one received the response from your browser. Since it could not remember what challenge it sent you, it sent you the error message.

I have not made the sessions sticky in the load-balancer and the problem is gone.

As a separate issue, yes, loading the index page of git.ipfire.org <http://git.ipfire.org/> takes a little while. It isn’t very easy to cache. And in fact I have completely removed any kind of caching from git.ipfire.org <http://git.ipfire.org/> because we will only write stuff to disk that will never be read again. And in times of SSD prices that reach the moon, I don’t think we need to break our storage faster than we need to. You can use cgit.ipfire.org <http://cgit.ipfire.org/> which is a bit faster, but offers other features.

Please let me know if there are any problems remaining.

All the best,
-Michael

> On 27 Apr 2026, at 12:06, Matthias Fischer <matthias.fischer@ipfire.org> wrote:
> 
> Hi Michael,
> 
> I'm not sure if the attached screenshot contains any security-sensitive
> information, so I'm sending it to you directly via email instead of
> through the list.
> 
> I tried to open https://git.ipfire.org and was greeted with this message.
> 
> The "Go home"-Link opens GIT, but it takes a while...
> 
> Best
> Matthias

[-- Attachment #2: Oh noes!.pdf --]
[-- Type: application/pdf, Size: 179500 bytes --]

[-- Attachment #3: Type: text/plain, Size: 1 bytes --]



           reply	other threads:[~2026-04-30  9:18 UTC|newest]

Thread overview: expand[flat|nested]  mbox.gz  Atom feed
 [parent not found: <4d364274-4a77-438f-902c-f31a653630e9@ipfire.org>]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6020CC4F-814B-4778-9E98-F002A960F1B9@ipfire.org \
    --to=michael.tremer@ipfire.org \
    --cc=development@lists.ipfire.org \
    --cc=infrastructure@lists.ipfire.org \
    --cc=matthias.fischer@ipfire.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox