Skip to main content

Overview

The panic mode endpoint allows administrators to immediately suspend or restore the gitGost service. When activated, all push attempts are rejected with an explanatory message. This feature is designed to mitigate bot submissions, coordinated spam, or other abusive activity.
This endpoint is protected by admin authentication and strict rate limiting (10 requests/minute per IP).

Endpoint

Authentication

The endpoint accepts two forms of authentication:
  1. Static password - The PANIC_PASSWORD environment variable configured during deployment
  2. Single-use action token - Time-limited tokens (10 minutes TTL) generated for ntfy alert action buttons

Request Body

string
Admin password for panic mode control. Must match the PANIC_PASSWORD environment variable.
string
Single-use action token generated by the system. Expires after 10 minutes.
boolean
required
  • true - Activate panic mode (suspend service)
  • false - Deactivate panic mode (restore service)
You must provide either password or token, but not both.

Response

boolean
Current state of panic mode after the request.
string
Human-readable status: "activated" or "deactivated".

Behavior When Active

When panic mode is activated:
  • All push requests to /v1/gh/:owner/:repo/git-receive-pack are immediately rejected
  • Users receive a Git protocol error message:
  • The service status endpoint (/api/status) returns {"panic_mode": true}
  • The deployment badge shows “suspended” in red

Rate Limiting

The admin endpoints enforce strict rate limiting:
  • 10 requests per minute per IP
  • Exceeding this limit returns 429 Too Many Requests

Examples

Shell Aliases

For convenience, add these aliases to your ~/.zshrc or ~/.bashrc:
Then simply run:

ntfy Integration

When abusive activity is detected, the system sends alerts to the configured ntfy admin topic with action buttons:
  • Activate Panic - Immediately suspend the service
  • Close Burst PRs - Close all PRs created during the attack window
  • Deactivate Panic - Restore normal operation
Action buttons use single-use tokens that expire after 10 minutes. If the tokens expire, use the curl commands with your PANIC_PASSWORD instead.

Implementation Details

From handlers.go:789-815: