Skip to content

fix(ingest): resolve visitor IP behind APIM - #13

Merged
danieltruong merged 1 commit into
mainfrom
fix-client-ip
Sep 7, 2026
Merged

danieltruong merged 1 commit into
mainfrom
fix-client-ip

Conversation

@danieltruong

Copy link
Copy Markdown
Collaborator

Every event geolocated to Toronto and the per-IP cap keyed on one address: the Function took the right-most X-Forwarded-For hop, which is the APIM gateway's outbound address once the Functions front end appends it. Front Door is not in the request path on either env yet, so the X-Azure-FDID branch never fires.

  • Resolve the caller from APIM's X-Client-Ip (stamped with override, so not caller-writable behind the gateway header check). When it is one of our cluster egress addresses, the visitor is the X-Forwarded-For hop the OpenShift router appended (index -2); with no such hop the caller is a server producer.
  • Server producers skip the per-IP event cap. They share one egress with every browser, which is what produced the 429 bursts on prod on 2026-09-07.
  • New TRUSTED_PROXY_IPS app setting, set to the four measured egress addresses in both param files.
  • Audit rows now carry the cluster egress as SourceIp instead of APIM's address.

Verified on test with hand-set headers: the Front Door branch already works end to end when the headers arrive.

APIM stamps X-Client-Ip and appends nothing to X-Forwarded-For, so the
last hop is the one Azure's Functions front end added for APIM itself.
Reading that hop located every event in Toronto and put the whole
OpenShift cluster in one rate-cap bucket, which is what gave eagle-api
429 bursts on prod.

The visitor is the hop before it, read only when X-Client-Ip is an
address in TRUSTED_PROXY_IPS: APIM sets that header with override and
every route here sits behind the gateway guard, so a caller cannot
forge it. A caller with no hop of its own is a server producer sharing
the cluster's egress address with every browser behind it, and is
exempt from the cap rather than sharing its bucket.
@danieltruong
danieltruong merged commit 1596228 into main Sep 7, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant