Rate limits on note creation (FREE SELF)

Introduced in GitLab 13.9.

You can configure the per-user rate limit for requests to the note creation endpoint.

To change the note creation rate limit:

  1. On the top bar, select Main menu > Admin.
  2. On the left sidebar, select Settings > Network.
  3. Expand Notes rate limit.
  4. In the Maximum requests per minute box, enter the new value.
  5. Optional. In the Users to exclude from the rate limit box, list users allowed to exceed the limit.
  6. Select Save changes.

This limit is:

  • Applied independently per user.
  • Not applied per IP address.

The default value is 300.

Requests over the rate limit are logged into the auth.log file.

For example, if you set a limit of 300, requests using the Projects::NotesController#create action exceeding a rate of 300 per minute are blocked. Access to the endpoint is allowed after one minute.