GNOME GitLab - Bot management migration to Fastly

Hello,

As you may be aware from your previous interactions with gitlab.gnome.org, the GNOME Infrastructure has been leveraging Anubis to protect our GitLab installation from bots and AI scrapers. While this solution has provided good results, we decided to take the next step and utilize our partner’s services—Fastly, who kindly sponsors GNOME through their Fast Forward program—to receive more advanced bot management features directly at the edge.

During the next couple of weeks, we will start the migration to Fastly’s edge-based security services.


What to Expect

  • Minimal Downtime: We do not anticipate any significant downtime for the GitLab instance.

  • Improved Performance: Offloading bot mitigation to the edge will reduce the load on our core infrastructure.

  • Stricter Scraper Controls: You may notice slight changes in how automated tools interact with the site as we fine-tune our WAF and bot detection rules.

If you encounter any unexpected “Access Denied” errors or issues accessing repositories during this transition, please reach out via the Infrastructure channel on GNOME Matrix or file an issue in the infrastructure tracker.

Thanks!

7 Likes

Hello,

An update on this side: we applied a set of rules at the WAF level and are currently monitoring their impact. At the same time we’ve disabled Anubis and are currently relying on the protection Fastly WAF at the edge is providing to us.

If you experience a 406 status code while you were expecting a successful gitlab.gnome.org page load, please report it through the Infrastructure channel on GNOME Matrix or file an issue in the infrastructure tracker.

Please bear with us while we fine tune the rules on our side, thanks!

1 Like