plugin/https: Add max_streams to limit HTTP/2 concurrent streams (#8522)

Add a max_streams option to the *https* plugin to limit the number of
concurrent HTTP/2 streams per DoH connection. This lets operators cap
per-connection concurrency (guarding against resource exhaustion) or
raise it above the Go default for high-fan-in clients that multiplex
many requests over a single connection.

Semantics match the existing *https3* plugin's max_streams:
- omitted  -> Go HTTP/2 server default is used
- 0        -> use the underlying HTTP/2 transport default
- positive -> advertise exactly that many concurrent streams
- negative -> rejected at config parse time

The limit is applied via the standard library http.Server.HTTP2
(HTTP2Config.MaxConcurrentStreams) so it is advertised in the server's
SETTINGS frame.

Signed-off-by: Mekias Yohannes <mmyohannes@gmail.com>
This commit is contained in:
myohannes
2026-09-06 22:16:44 -04:00
committed by GitHub
parent 558c9757a9
commit 2b8c305203
9 changed files with 392 additions and 3 deletions

View File

@@ -1,6 +1,7 @@
package https
import (
"math"
"strconv"
"github.com/coredns/caddy"
@@ -54,6 +55,25 @@ func parseDOH(c *caddy.Controller) error {
return c.Err("max_connections already defined for this server block")
}
config.MaxHTTPSConnections = &val
case "max_streams":
args := c.RemainingArgs()
if len(args) != 1 {
return c.ArgErr()
}
val, err := strconv.Atoi(args[0])
if err != nil {
return c.Errf("invalid max_streams value '%s': %v", args[0], err)
}
if val < 0 {
return c.Errf("max_streams must be a non-negative integer: %d", val)
}
if int64(val) > math.MaxUint32 {
return c.Errf("max_streams must not exceed %d: %d", uint64(math.MaxUint32), val)
}
if config.MaxHTTPSStreams != nil {
return c.Err("max_streams already defined for this server block")
}
config.MaxHTTPSStreams = &val
default:
return c.Errf("unknown property '%s'", c.Val())
}