{
  "id": 10355168,
  "title": "Defend your endorsement nodes: Token-bucket rate limiting for Fabric.",
  "url": "https://urgent.news/2026/09/28/defend-your-endorsement-nodes-token-bucket-rate-limiting-for-fabric",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-28T03:55:06.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/william_rodriguez_65a5898/defend-your-endorsement-nodes-token-bucket-rate-limiting-for-fabric-3bg0"
  },
  "original_language": "en",
  "account": "Preventing overload on endorsement nodes is crucial for maintaining the performance of Hyperledger Fabric clusters. One method for doing this is through token-bucket rate limiting, which is the focus of the wFabricSecurity project. ECDSA signature verification is a resource-intensive operation, and flooding an endorsement node with thousands of signature requests can cause it to become overwhelmed, leading to cryptographic CPU exhaustion and legitimate transactions being dropped due to peer resource starvation.\n\nTo address these issues, wFabricSecurity provides a token-bucket rate limiter. The limiter is configured to allow a maximum of 100 tokens, with 10 tokens refilled each second. Each participant is assigned a unique Common Name (CN) or IP address, and distinct limits are enforced for each. If the limiter's consume method is unable to grant a token for a particular participant, a RateLimitError is raised, preventing the expensive ECDSA verification process from being triggered.\n\nThis architecture offers several advantages. The token-bucket algorithm smoothly handles bursts of traffic while still enforcing sustained rate caps. By applying distinct limits per participant, the system can prevent a single rogue or looping worker from overwhelming the endorsement node. The RateLimitError mechanism traps abusive request spikes before they can cause damage. The implementation is compatible with Python 3.10 and above, and includes cryptographic identity management and code integrity hashing.\n\nFor more information, visit the project's GitHub repository at https://github.com/wisrovi/wFabricSecurity or install the package via PyPI at https://pypi.org/project/wFabricSecurity.",
  "summary": "Defend your endorsement nodes: Token-bucket rate limiting for Fabric. Day 07 of the wFabricSecurity Open-Source Engineering Series. ECDSA signature verification is computationally expensive. Flooding an endorsement node will bring it to its knees. wFabricSecurity defends your cluster with token-bucket rate limiting. The Pain Points We Faced A rogue or looping worker overwhelming endorsement peers…",
  "key_points": [
    "Token-bucket rate limiting prevents overload on Fabric endorsement nodes",
    "Allows 100 tokens with 10 tokens refilled per second",
    "Raises RateLimitError for participants exceeding limits"
  ],
  "editors_take": "Implementing token-bucket rate limiting in Hyperledger Fabric clusters protects endorsement nodes from overload and resource starvation, allowing them to maintain performance and prevent legitimate transactions from being dropped.",
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "Dev.to",
        "title": "Defiende tus nodos de endoso: Rate limiting token-bucket para Fabric.",
        "url": "https://urgent.news/2026/09/28/defiende-tus-nodos-de-endoso-rate-limiting-token-bucket-para-fabric",
        "published": "2026-09-28T03:55:36.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}