The discussion revolves around setting set_real_ip_from in Discourse. parisa wants to set custom IPs using set_real_ip_from but is unsure how to do it in Discourse. Major suggests using the Cloudflare template, but parisa points out that this is for Cloudflare IPs and not suitable for custom IPs.
After some back-and-forth, parisa finds a solution by creating a custom template (customip.template.yml) and adding it to app.yml. This template adds custom IPs to the discourse.conf file and sets real_ip_header and real_ip_recursive accordingly.
sam reviews parisa’s solution and finds it good, highlighting the importance of not trusting any IP address with the X-Forwarded-For header to prevent IP spoofing. sam also mentions an alternative approach used in HAProxy, where the IP is set only if a top-secret header is present.
Sorry but as far as I know its for cloudflare IPs. However, I have my own IP. And even if I would change this file for a little, I don’t know if my changes would be overwritten in future or not.
My use case is that I have a php file for login/sign-up using api calls and it is in one of my servers. Assuming that the public IP of that server is 1.2.3.4, all IPs inside discourse is reported to be also 1.2.3.4. And it would pass all limits very soon.
I know about this part. I just don’t know how to implement it in discourse nginx. There is a template for cloudflare ips. but there is not a template for custom ips or any instructions, as far as I know.
Looks good to me, you highlight the super important fact there that you can not just trust any IP address with that header, cause if you did, user IPs can be spoofed.
An alternative I have seen (that we use in haproxy) is setting the IP only if we see some top secret header that we have the CDN always send us.