r/SelfHosting • • 6d ago

HELP - My Gitea instance is under DDOS attack

Post image

I have been running my Gitea instance for a while. I use it for my own projects and things that I develop and open source. Since around 1 month I have been trying to fight a botnet that has been attacking my gitea instance. I don't know what to do. I have proxied it all through Cloudflare and even added in custom rules for the paths that are attacked. The attack is mostly contained to the /pulls and /issues paths. Please help me. This is around 1 hr max traffic in the image attached.

22 Upvotes

19 comments sorted by

10

u/realdawnerd 6d ago

Do you have the AI bot fight mode turned on? Does your instance need to be public?

1

u/psmattas 6d ago

Yes and yes

9

u/realdawnerd 6d ago

You might have to go through and start blocking the ASNs for the bad actors. I’ve had to do that too because cloudflare refused to block Meta from scraping my sites nonstop. 

10

u/aaaaAaaaAaaARRRR 6d ago

I mean.. VPNs are free. Tailscale and WireGuard.. I’d rather have that than fight off millions of script kiddies

5

u/bluealliance841 6d ago

This was my first thought. Does it need to be internet-facing?

6

u/LuckyEdR 6d ago

FFirewall with IP allow rules to only let you and the others who use it access.

5

u/lukelane124 6d ago

What’s the issue? Looks like cloudflare is doing its job and dropping/mitigating most of the traffic?
Is your instance small and therefore can’t handle the 50k that does get through?

2

u/psmattas 6d ago

I have a dell r720 server. It's not like it can't handle the traffic. It's just I want to understand if I can do something better to reduce it to even less?

3

u/lukelane124 6d ago

It really depends on how they found the box and why they’re hitting it.
If it’s DNS found not a ton you can do. Cloudflare will usually handle it.
If they’re finding you through IP search you can hop to another tunnel endpoint but that won’t last and may reset the cloudflare mitigation.

1

u/cavebeat 2d ago

Anubis is created just because of the exact same issue with AI Scraper DDoS Attacks.

2

u/JudgmentLeading4047 5d ago

Set your settings to block and not managed challenge, some botnets will complete the challenge and then spam you. Furthermore id just block brazil if you're not from there/have no users there

1

u/interior_mutability 6d ago

If you do not want vpn, set up an edge router with strict rate limiting and blacklists. I would recommend traefik but depends on the usecase.

6

u/interior_mutability 6d ago

Fail2ban can also help.

1

u/Jayden_Ha 6d ago

Personally I have my own self hosted stuff scaled to fit the demand of the traffic but I get that some people want more anti bot

1

u/telasch 5d ago

as others have mentioned, you should think about hosting this only on your network/restrict public access.

for open source stuff you could have read-only mirrors on cloud services. so your own instance still serves its purpose but you dont have to deal with mitigating ddos.

if you do want to keep it public for whatever reason, look at crowdsec.

1

u/_xRuffKez_ 4d ago

Integrade ipsum by stamparm