DEV Community

Divinelab.io
Divinelab.io

Posted on

How to Stop API Floods and Rate Limit Endpoints in Under 5 Minutes

Exposing an API or web application to the public internet means dealing with credential stuffing, scraping bots, and sudden volumetric request surges.

If you don't enforce rate limits and connection thresholds at the network edge, an attacker can easily exhaust your database connection pools or CPU resources.

In this guide, we'll configure Aegis—an open-source, self-hosted edge reverse proxy and WAF—to rate limit abusive clients and prevent Layer 7 denial-of-service attacks directly from its web console.

Aegis Traffic Control & Rate Limiting


1. Configure Global Flood Protection

In the Aegis Admin Console (http://localhost:8081), navigate to Traffic Control > Application Flood.

Aegis tracks request velocity and active socket concurrency per client IP in real time:

  • HTTP Flood Threshold: Sets the maximum requests per second allowed per IP (e.g., 100 req/s).
  • In-Flight Connection Ceiling: Caps simultaneous concurrent TCP sockets per IP (e.g., 50 in-flight). This defends origin services against connection exhaustion attacks like Slowloris.
  • Burst Multiplier: Allows short traffic spikes (e.g., 2.0x) before throttling begins.
  • Temporary Ban: Automatically blacklists repeated threshold abusers for a set duration (e.g., 60 minutes).

When you click Save, Aegis applies the rules directly in memory with zero downtime—no proxy reloads or dropped connections.


2. Scope Tighter Limits on Sensitive Routes

Global rate limits are often too permissive for authentication endpoints. While 100 req/s makes sense for browsing a product catalog, allowing that on /api/login leaves you vulnerable to brute-force attacks.

In the Protected HTTP Objects panel:

  1. Click + Add Object.
  2. Specify the path: /api/v1/auth/login (Method: POST).
  3. Set a strict limit: 5 req/s with a max concurrency of 2.
  4. Choose the response action: HTTP 429 Too Many Requests or Browser Challenge.

3. Test the Rate Limiter

Send a burst of rapid requests to test edge enforcement:

for i in {1..20}; do
  curl -s -o /dev/null -w "%{http_code}\n" http://localhost:8080/api/v1/auth/login -X POST
done
Enter fullscreen mode Exit fullscreen mode

Output:

200
200
200
200
200
429
429
429
...
Enter fullscreen mode Exit fullscreen mode

Once the threshold is exceeded, Aegis drops excess requests at the edge with 429 Too Many Requests before they ever reach your origin database.


Resources

Aegis Community Edition is free and open-source under BSL 1.1:

Top comments (0)