ratestore

package
v0.13.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 17, 2026 License: Apache-2.0 Imports: 6 Imported by: 0

Documentation

Overview

Package ratestore provides cross-pod detection of unauthenticated request bursts. A RateStore counts observations for an identity within a tumbling window and reports, exactly once per (window, identity) across the whole fleet, when the count first crosses a threshold.

The Valkey-backed implementation performs the count-and-latch atomically in a single Lua script evaluated on the server, so no distributed lock or leader election is needed and pod clock skew does not affect window boundaries.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Noop

type Noop struct{}

Noop is a RateStore that never fires. It is used when rate detection is disabled so call sites can invoke Observe unconditionally.

func (Noop) Close

func (Noop) Close() error

func (Noop) Observe

func (Noop) Observe(_ context.Context, _ string) (bool, error)

type Options

type Options struct {
	// Client is a connected Valkey client. Required.
	Client valkey.Client

	// KeyPrefix namespaces all keys written by this store (cfg.Valkey.Prefix).
	KeyPrefix string

	// Threshold is the number of observations within Window that triggers a
	// single fired result.
	Threshold int64

	// Window is the tumbling window size.
	Window time.Duration

	// Cooldown suppresses further fired results for the same identity/window
	// after one has fired. Defaults to Window when zero.
	Cooldown time.Duration
}

Options configures a ValkeyStore.

type RateStore

type RateStore interface {
	// Observe records one unauthenticated request for hkey. It returns fired ==
	// true for exactly one observation per (window, identity) across the fleet:
	// the one that first crosses the threshold and wins the emit latch.
	Observe(ctx context.Context, hkey string) (fired bool, err error)

	// Close releases any resources held by the store.
	Close() error
}

RateStore observes an unauthenticated request for the given identity key and reports whether this observation is the one that should emit the burst audit event. Implementations must be safe for concurrent use.

type ValkeyStore

type ValkeyStore struct {
	// contains filtered or unexported fields
}

ValkeyStore is a RateStore backed by a Valkey server (single, sentinel or cluster, depending on the addresses supplied at construction).

func New

func New(opts Options) (*ValkeyStore, error)

New creates a ValkeyStore from the given options.

func (*ValkeyStore) Close

func (s *ValkeyStore) Close() error

Close implements RateStore.

func (*ValkeyStore) Observe

func (s *ValkeyStore) Observe(ctx context.Context, hkey string) (bool, error)

Observe implements RateStore.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL