# 保护 Discourse 免受大量请求的最佳免费方案

**URL:** <https://meta.discourse.org/t/best-free-option-to-protect-discourse-from-many-requests/113350>\
**Category:** Self-hosting\
**Created:** [2019年四月3日 14:35 UTC](https://meta.discourse.org/t/best-free-option-to-protect-discourse-from-many-requests/113350 "2019-04-03T14:35:11Z")\
**Posts on this page:** 11\
**Page:** 2

<div class="post-metadata">

**Author:** ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)\
**Post date:** [2019年四月3日 23:02 UTC](https://meta.discourse.org/t/best-free-option-to-protect-discourse-from-many-requests/113350/24 "2019-04-03T23:02:00Z")

</div>

> [@Jay91](#):
>
> but how about somebody can do the same and flood the website all day long ?

If they flood the web site, they will get that 429 message so that they will not be able to continue to flood your site. Just like it did for him. The server isn’t giving him that message because you “authorized” him. It is keeping him from accessing the site because he is being malicious. If they flood the web site all day long it will not affect your server because they will get only the 429 page.

You are already protected.

Often people get that 429 error when they should not, and they are unable to access their site. That is a problem. You have no problem. You are unable to access your site if you try to take it down. That is what you want.

---

<div class="post-metadata">

**Author:** ![Jay91](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jay91/32/135181_2.png) [@Jay91](https://meta.discourse.org/u/Jay91)\
**Post date:** [2019年四月4日 00:02 UTC](https://meta.discourse.org/t/best-free-option-to-protect-discourse-from-many-requests/113350/25 "2019-04-04T00:02:30Z")

</div>

This one is no longer working right ? - to activate the cloudflare ?

> [@How do you setup Cloudflare?](https://meta.discourse.org/t/how-do-you-setup-cloudflare/32258/6):
>
> Yes, just: add cloudflare.template.yml to the end of the templates section in app.yml. do not enable Rocket Loader or any other features that will interfere with JavaScript Here’s how to edit in a nutshell: cd /var/discourse nano containers/app.yml # Make sure to use spaces, not the tab key. # Ctrl-O to "write [O]ut" # Ctrl-X to "e[X]it" ./launcher rebuild app credit to @riking

---

<div class="post-metadata">

**Author:** ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)\
**Post date:** [2019年四月4日 00:28 UTC](https://meta.discourse.org/t/best-free-option-to-protect-discourse-from-many-requests/113350/26 "2019-04-04T00:28:02Z")

</div>

We will publish a new guide on cloudflare soon.

Although you seem to be ignoring the earlier statements that Cloudflare won’t do anything for you here.

---

<div class="post-metadata">

**Author:** ![Jay91](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jay91/32/135181_2.png) [@Jay91](https://meta.discourse.org/u/Jay91)\
**Post date:** [2019年四月4日 06:22 UTC](https://meta.discourse.org/t/best-free-option-to-protect-discourse-from-many-requests/113350/27 "2019-04-04T06:22:47Z")

</div>

> [@Stephen](#):
>
> Although you seem to be ignoring the earlier statements that Cloudflare won’t do anything for you here.

my apology to you, but i am not, you was clear enough at the part below:

> [@Best free option to protect discourse from many requests](https://meta.discourse.org/t/best-free-option-to-protect-discourse-from-many-requests/113350/17):
>
> You need to determine what’s causing the nginx rate limit to kick in. If your Discourse is correctly configured the only reason you should see that message is if there are a large number of users sat behind a single IP. Cloudflare can’t do anything to mitigate that kind of traffic either. Discourse isn’t a website, it loads a javascript payload into the browser, putting another hop in the network path between client and server will only slow things down.

And i can say absolutely you know better than me, i always wanted to connect my website to cloudflare even before this event so i took the advantage of this post to ask again.  
Again am sorry, and i do appreciate you guys effort in helping me, am fully aware of the fact that cloudflare will not help.

---

<div class="post-metadata">

**Author:** ![Jay91](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jay91/32/135181_2.png) [@Jay91](https://meta.discourse.org/u/Jay91)\
**Post date:** [2019年四月4日 10:28 UTC](https://meta.discourse.org/t/best-free-option-to-protect-discourse-from-many-requests/113350/28 "2019-04-04T10:28:10Z")

</div>

> [@pfaffman](#):
>
> If they flood the web site all day long it will not affect your server because they will get only the 429 page.

i fully understand what you saying, you mean the flood of requests cannot damage the data on the server !!  
ok, sounds well but what am gonna do with a server not affected if somebody can shutdown my website for 10 minutes 5 times a day with a small piece of software ?

what i need to know here, what is the best method to have all these requests without having 429 page ? i just wanna keep the website running smoothly under this scenario.  
because the users cares about no protected server but about getting to the website and see the content.

---

<div class="post-metadata">

**Author:** ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)\
**Post date:** [2019年四月4日 11:43 UTC](https://meta.discourse.org/t/best-free-option-to-protect-discourse-from-many-requests/113350/29 "2019-04-04T11:43:19Z")

</div>

This is the last time that I will try explain.

The only people who will not be able to see your site are people who are running a program that tries to make it inaccessible.

While the people who run software to crash your site see the 429 error, everyone else sees the site just fine.

---

<div class="post-metadata">

**Author:** ![Jay91](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jay91/32/135181_2.png) [@Jay91](https://meta.discourse.org/u/Jay91)\
**Post date:** [2019年四月4日 17:35 UTC](https://meta.discourse.org/t/best-free-option-to-protect-discourse-from-many-requests/113350/30 "2019-04-04T17:35:47Z")

</div>

> [@pfaffman](#):
>
> While the people who run software to crash your site see the 429 error, everyone else sees the site just fine.

You can’t imagine how stupid i am 😉  
For real am not a programmer this is why the people must talk to me in simple language.  
The part above is clear.  
Thanks a lot for your time sir.

---

<div class="post-metadata">

**Author:** ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)\
**Post date:** [2019年四月4日 18:04 UTC](https://meta.discourse.org/t/best-free-option-to-protect-discourse-from-many-requests/113350/31 "2019-04-04T18:04:30Z")

</div>

> [@Jay91](#):
>
> You can’t imagine how stupid i am 😉

You can find many, many stupid things that I’ve said here, I assure you!

Glad that I (think I) finally explained it in a way you could understand. Sorry it took me so many tries.

---

<div class="post-metadata">

**Author:** ![Bathinda](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/bathinda/32/135888_2.png) [@Bathinda](https://meta.discourse.org/u/Bathinda)\
**Post date:** [2019年十二月18日 05:46 UTC](https://meta.discourse.org/t/best-free-option-to-protect-discourse-from-many-requests/113350/33 "2019-12-18T05:46:45Z")

</div>

> [@pfaffman](#):
>
> 我希望我（认为我）终于用你能理解的方式解释清楚了。抱歉我试了这么多次。

如果这里要颁发“元社区最耐心男士奖”，  
我相信你肯定会获得最多的投票。

---

<div class="post-metadata">

**Author:** ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)\
**Post date:** [2023年十月7日 03:24 UTC](https://meta.discourse.org/t/best-free-option-to-protect-discourse-from-many-requests/113350/34 "2023-10-07T03:24:13Z")

</div>



---

<div class="post-metadata">

**Author:** ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)\
**Post date:** [2023年十月7日 05:41 UTC](https://meta.discourse.org/t/best-free-option-to-protect-discourse-from-many-requests/113350/35 "2023-10-07T05:41:12Z")

</div>



[上一頁](https://meta.discourse.org/t/best-free-option-to-protect-discourse-from-many-requests/113350.md?page=1)
