Skip to main content

Moderating gitGost

GitGost provides moderation tools to combat abuse while preserving user privacy.

Panic Button

The panic button immediately suspends all push operations when abuse is detected.

How It Works

When activated:
  • ✅ Service continues running (health checks pass)
  • ❌ All push operations are rejected
  • 📢 Users see suspension message
  • 🔄 Can be toggled on/off instantly

Activate Panic Mode

Suspend the service immediately:
Response:

Deactivate Panic Mode

Restore normal service:
Response:
Security: Store PANIC_PASSWORD securely. Anyone with this password can control service availability. Use a strong, randomly generated password.

Shell Aliases for Quick Access

Add to ~/.zshrc or ~/.bashrc for instant access:
Usage:

User Experience During Suspension

When users attempt to push while panic mode is active:
From internal/http/handlers.go:142-157:
The panic mode check occurs early in the push handler, before any processing:
This ensures zero resource consumption for suspended requests.

Burst Rollback

When bot attacks create many PRs, you can close them all in bulk.

How Burst Rollback Works

1

Detection

GitGost monitors push activity globally across all IPs. When suspicious patterns emerge:
  • 20+ pushes within 60 seconds, OR
  • 10+ distinct IPs pushing simultaneously
An alert is sent via ntfy with action buttons.
2

PR Tracking

During the burst window (2 hours), all PR URLs are tracked in memory.
3

Rollback

Trigger rollback to close all tracked PRs in parallel.

Execute Rollback

Response:
Rollback Window: Only PRs created within the last 2 hours are closed. Older PRs are unaffected.

Rollback Rate Limiting

To prevent abuse of the rollback endpoint:
  • Maximum: 5 rollback requests per minute per IP
  • Response: 429 Too Many Requests if exceeded
From internal/http/handlers.go:844-860

ntfy Alert Integration

Real-time alerts help you respond quickly to abuse.

Configure ntfy Alerts

Keep Secret: The ntfy admin topic is essentially an API key. Anyone who knows it can receive your alerts. Use a long, random string.

Alert Types

1. Rate Limit Exceeded

Triggered when a single IP exceeds 5 PRs/hour:

2. Suspicious Burst Activity

Triggered during coordinated attacks:
From internal/http/handlers.go:707-730

ntfy Action Buttons

Alerts include single-use tokens valid for 10 minutes:
  • Each alert generates unique tokens per button
  • Tokens expire after 10 minutes
  • Tokens are consumed on first use
  • Prevents accidental double-triggers
  • Never exposes your PANIC_PASSWORD in notifications
Implementation: internal/http/handlers.go:617-641
Token Expiry: If action buttons stop working after 10 minutes, use the manual curl commands with your PANIC_PASSWORD instead.

Subscribe to Alerts

On your phone:
  1. Install ntfy app (iOS/Android)
  2. Subscribe to your topic: https://ntfy.sh/secret-admin-channel-xyz
  3. Enable notifications
In your browser: Visit https://ntfy.sh/secret-admin-channel-xyz Via command line:

Hash Reporting System

GitGost includes a karma-based identity system for anonymous comments on issues/PRs.

How It Works

1

Anonymous comment

User posts comment anonymously, receives a unique hash (e.g., goster-a3f7b9c2)
2

Karma tracking

Each comment increases karma. Hash and karma are visible in comment footer.
3

Report link

Each comment includes a [report] link to report abusive content.
4

Moderation action

Reports trigger automated moderation:
  • 0-2 reports: Logged internally
  • 3-5 reports: Hash flagged, 6h cooldown, karma reset to 0
  • 6+ reports: Hash blocked, all comments deleted

Report Thresholds

From internal/http/handlers.go:610-614:

Report Workflow

User visits report link:
UI shows:
  • Current report count
  • Hash state (registered/flagged/blocked)
  • Moderation policy
  • Submit button (one report per IP)
After submission:
Privacy-Preserving: Reports are rate-limited by IP but IPs are not logged long-term. The system balances abuse prevention with user privacy.

Rate Limiting

Multiple rate limits protect against abuse:

1. Per-IP PR Rate Limit

  • Limit: 5 PRs per hour per IP
  • Window: Rolling 1-hour window
  • Enforcement: internal/http/handlers.go:733-759
User experience when exceeded:

2. Admin Endpoint Rate Limit

  • Limit: 10 requests per minute per IP
  • Applies to: /admin/panic, /admin/rollback
  • Enforcement: internal/http/router.go:22-46

3. Rollback Rate Limit

  • Limit: 5 rollback calls per minute
  • Purpose: Prevent accidental mass PR closures
  • Enforcement: internal/http/handlers.go:844-860

Moderation Best Practices

Response Workflow

When you receive an alert:
  1. Assess severity
    • Single IP rate limit → Monitor, may be legitimate
    • Burst from many IPs → Likely bot attack
  2. Activate panic if needed
    • Tap action button OR use shell alias
    • Stops attack immediately
  3. Review created PRs
    • Check GitHub for spam PRs
    • Verify if rollback is needed
  4. Execute rollback
    • Close all burst PRs in one operation
  5. Deactivate panic
    • Restore service once threat is neutralized
  6. Post-mortem
    • Review logs for patterns
    • Consider adjusting rate limits if needed

Prevention Tips

  • Monitor trends: Watch for gradual increases in push rates
  • Test alerts: Periodically test your ntfy subscription
  • Document incidents: Keep a log of abuse patterns
  • Update rate limits: Adjust thresholds based on traffic patterns

Moderation Commands Reference

Panic button:
Rollback burst:
Check service status:
Using action tokens (from ntfy alerts):

Next Steps

Monitoring

Set up health checks and metrics monitoring

Troubleshooting

Diagnose and fix common operational issues