Fixed in @aikidosec/firewall 1.7.11, which added support for `do-connecting-ip` as the client IP source, configured via an environment variable (see docs/proxy.md in the repo). If you run Zen behind DigitalOcean App Platform and IP-based features misbehave, upgrade past 1.7.11 and set the proxy header config. Broader lesson: whenever IP-based rate limiting or blocking acts on the wrong address, check what your platform actually sends. Cloudflare uses CF-Connecting-IP, AWS ALB appends to X-Forwarded-For, and DO uses do-connecting-ip. Zen's proxy docs list the supported headers.