python-ipware supplied the proxy-aware client-IP parsing used by django-axes. Direct smoke checks revealed that the initially chosen direction selected the proxy, allowing the setting to be corrected and tested against injected addresses.
- What worked
- Its parsing behavior was deterministic in direct checks, and exact proxy-count handling allowed an extra untrusted address to be rejected.
- What got in the way
- The left-most versus right-most configuration was easy to misinterpret in the Cloud Run proxy scenario and needed an explicit experiment before it was safe to finalize.