Skip to main content

WEBHOOK_VALIDATION_MEMORY_BUDGET_BYTES

Constant WEBHOOK_VALIDATION_MEMORY_BUDGET_BYTES 

Source
pub const WEBHOOK_VALIDATION_MEMORY_BUDGET_BYTES: Config<usize>;
Expand description

Maximum temporary storage a webhook CHECK expression may allocate while validating one request. A CHECK that exceeds it fails the request with HTTP 400 rather than holding the memory.

A CHECK can allocate a multiple of the request body, and environmentd evaluates one per in-flight request. Without a bound proportionate to the request, bounded network input becomes unbounded heap on a process shared by every connection. The default is 4x WEBHOOK_MAX_REQUEST_SIZE_BYTES, well above what a realistic CHECK (an HMAC, a decode, a concat with a secret) needs and well below the 100 MiB per-call ceiling used in a cluster.

NOTE: this is runtime-reconfigurable, so it must only bound a single webhook validation. Do not feed it (or any mutable budget) to a RowArena used in a compute dataflow (see mz_repr::RowArena::with_budget).