Details
| Title | Reference | Author | Source Branch | Dest Branch | |
|---|---|---|---|---|---|
| definitions: Add Z581/Reached outbound rate limit in orchestrator | repos/abstract-wiki/wikifunctions/function-schemata!366 | jforrester | T282922-error | main | |
| routes: Re-classify Z576/evaluator_wasi_limit as 422 at orchestrator edge | repos/abstract-wiki/wikifunctions/function-orchestrator!662 | jforrester | T423383 | main |
| Status | Subtype | Assigned | Task | ||
|---|---|---|---|---|---|
| Resolved | Jdforrester-WMF | T338522 Implement agreed post-launch security and control measures in the Wikifunctions system | |||
| Resolved | Jdforrester-WMF | T282922 Implement system-wide overall request rate / resource consumption limits in the orchestrator |
Event Timeline
Security and SRE were worried about out-of-control processes in Wikifunctions adding significant load to the production machines (especially if e.g. the calls from the orchestrator to Wikifunctions.org's MW API, or Wikidata.org's, got into a runaway loop) and could imperil the overall cluster stability.
Check with Security if it is OK to simply use the Docker rate limits, instead of implementing our own solution. Contingent on that, moving this to nice to have.
James's estimated effort: 10+ days? Mostly blocked by tracking data about usage in the orchestrator.
Are there any updates on this? What resources we want to track, strategies for avoiding the runaway cases mentioned by James?
This is mostly moot until we have external resources we're requesting (i.e. Wikidata and Commons); I suppose we could build it as-is for requests to Wikifunctions's wiki API for now?
In my mind we'd just have all requests go through a request proxy, either just using the existing network service (which I think we have to use anyway?) or more smartly some code inside the orchestrator which keeps a running track of request rates and rejects/slows down requests over some threshold?
jforrester opened https://gitlab.wikimedia.org/repos/abstract-wiki/wikifunctions/function-orchestrator/-/merge_requests/662
routes: Re-classify Z576/evaluator_wasi_limit as 422 at orchestrator edge
gengh merged https://gitlab.wikimedia.org/repos/abstract-wiki/wikifunctions/function-orchestrator/-/merge_requests/662
routes: Re-classify Z576/evaluator_wasi_limit as 422 at orchestrator edge
Change #1289373 had a related patch set uploaded (by Jforrester; author: Jforrester):
[operations/deployment-charts@master] wikifunctions: Upgrade orchestrator from 2026-05-12-210548 to 2026-05-19-145724
Change #1289373 merged by jenkins-bot:
[operations/deployment-charts@master] wikifunctions: Upgrade orchestrator from 2026-05-12-210548 to 2026-05-19-145724
jforrester opened https://gitlab.wikimedia.org/repos/abstract-wiki/wikifunctions/function-orchestrator/-/merge_requests/704
fetchObject: Cap (per-pod) concurrent requests to external APIs
jforrester opened https://gitlab.wikimedia.org/repos/abstract-wiki/wikifunctions/function-schemata/-/merge_requests/366
definitions: Add Z581/Reached outbound rate limit in orchestrator
dmartin merged https://gitlab.wikimedia.org/repos/abstract-wiki/wikifunctions/function-schemata/-/merge_requests/366
definitions: Add Z581/Reached outbound rate limit in orchestrator
jforrester opened https://gitlab.wikimedia.org/repos/abstract-wiki/wikifunctions/function-orchestrator/-/merge_requests/712
Update function-schemata sub-module to HEAD (rECTXe8e00967df6a)
dmartin merged https://gitlab.wikimedia.org/repos/abstract-wiki/wikifunctions/function-orchestrator/-/merge_requests/712
Update function-schemata sub-module to HEAD (rECTXe8e00967df6a)
dmartin merged https://gitlab.wikimedia.org/repos/abstract-wiki/wikifunctions/function-orchestrator/-/merge_requests/704
fetchObject: Cap (per-pod) concurrent requests to external APIs
Change #1300860 had a related patch set uploaded (by Jforrester; author: Jforrester):
[operations/deployment-charts@master] wikifunctions: Upgrade orchestrator from 2026-06-09-215338 to 2026-06-11-171152
Change #1300860 merged by jenkins-bot:
[operations/deployment-charts@master] wikifunctions: Upgrade orchestrator from 2026-06-09-215338 to 2026-06-11-171152
Change #1302868 had a related patch set uploaded (by Jforrester; author: Jforrester):
[mediawiki/extensions/WikiLambda@master] Update function-schemata sub-module to HEAD (054c288)
jforrester opened https://gitlab.wikimedia.org/repos/abstract-wiki/wikifunctions/wikilambda-cli/-/merge_requests/119
Update function-schemata sub-module to HEAD (054c288)
jforrester opened https://gitlab.wikimedia.org/repos/abstract-wiki/wikifunctions/function-evaluator/-/merge_requests/569
Update function-schemata sub-module to HEAD (054c288)
apine merged https://gitlab.wikimedia.org/repos/abstract-wiki/wikifunctions/wikilambda-cli/-/merge_requests/119
Update function-schemata sub-module to HEAD (054c288)
apine merged https://gitlab.wikimedia.org/repos/abstract-wiki/wikifunctions/function-evaluator/-/merge_requests/569
Update function-schemata sub-module to HEAD (054c288)
Change #1303433 had a related patch set uploaded (by Jforrester; author: Jforrester):
[operations/deployment-charts@master] wikifunctions: Upgrade evaluators from 2026-06-09-174730 to 2026-06-16-205705
Change #1303433 merged by jenkins-bot:
[operations/deployment-charts@master] wikifunctions: Upgrade evaluators from 2026-06-09-174730 to 2026-06-16-205705
Change #1303482 had a related patch set uploaded (by Jforrester; author: Jforrester):
[operations/deployment-charts@master] wikifunctions: Upgrade evaluators from 2026-06-09-174730 to 2026-06-17-154210
Change #1303482 merged by jenkins-bot:
[operations/deployment-charts@master] wikifunctions: Upgrade evaluators from 2026-06-09-174730 to 2026-06-17-184727
Change #1302868 merged by jenkins-bot:
[mediawiki/extensions/WikiLambda@master] Update function-schemata sub-module to HEAD (4583bb7)