Outcome
Protect the administration API and its database from excessive inbound requests, accidental client loops and bursts, while retaining the existing Entra authentication and owner authorization boundary.
Use ASP.NET Core's built-in rate-limiting middleware in the API adapter. Keep HTTP throttling concerns out of Domain and Application handlers.
Target iteration
Iteration 3, M1 — Configuration Foundation. Deliver after the revision API in #45 as part of completing the configuration foundation. #32 remains the next implementation task.
Project planning: Ready; priority Next; size M.
Acceptance criteria
Policies and resource protection
HTTP and probe behaviour
Observability and verification
Dependencies and related work
Out of scope
- Changes to Domain rules, revision semantics or database optimistic concurrency
- Price-provider and broker request limits or retries
- Paid API Management, Front Door/WAF or other new Azure resources
- Distributed quota storage and multi-instance coordination
- Comprehensive DDoS mitigation, public registration, customer tiers or billing quotas
Application rate limiting is an additional resource-protection control; it does not replace authentication, authorization or edge/network DDoS protection.
Reference
Outcome
Protect the administration API and its database from excessive inbound requests, accidental client loops and bursts, while retaining the existing Entra authentication and owner authorization boundary.
Use ASP.NET Core's built-in rate-limiting middleware in the API adapter. Keep HTTP throttling concerns out of Domain and Application handlers.
Target iteration
Iteration 3, M1 — Configuration Foundation. Deliver after the revision API in #45 as part of completing the configuration foundation. #32 remains the next implementation task.
Project planning: Ready; priority Next; size M.
Acceptance criteria
Policies and resource protection
HTTP and probe behaviour
Observability and verification
Dependencies and related work
Out of scope
Application rate limiting is an additional resource-protection control; it does not replace authentication, authorization or edge/network DDoS protection.
Reference