docs: D1 Operations/Rate limiting and D2 env reference (README)

Close documentation-plan findings 1-3 and part of 10: panel operations
guide, two-level rate limits, public env table with TRUSTED_PROXY_CIDR
warning, and compose wiring for the proxy CIDR variable.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-08-05 00:26:03 +03:00
parent a63e5c9b23
commit b041e279b0
4 changed files with 132 additions and 0 deletions
+15
View File
@@ -5,6 +5,21 @@ Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); version
## [Unreleased]
### Added
- docs (D1): README *Operations* — panel screens (`/status`, domains,
deliveries, mail queue, system log, backup, account), upgrade procedure,
session behaviour (sliding idle, monitoring polls do not extend, password
change signs out other sessions), and `mail.log` rotation cadence.
- docs (D1): README *Rate limiting* — level-1 anvil limits
(`RATE_LIMIT_MESSAGES_PER_IP`, `RATE_LIMIT_WINDOW_SECONDS`) and level-2
per-domain/application limits from the panel; fixes the `.env.example` link
that pointed at a missing section.
- docs (D2): README environment-variable reference — public `.env` table with
code-accurate defaults, `TRUSTED_PROXY_CIDR` security note, explicit
internal-variable list; `TRUSTED_PROXY_CIDR` wired through
`deploy/docker-compose.yml`.
### Changed
- docs: documentation plan now targets retiring `specification.md` after D9 —