添加rate-limiting插件后Kong封禁全部IP问题求助
解决Kong速率限制全局封禁所有IP的问题
你的问题根源在于没有指定速率限制的统计维度,Kong的rate-limiting插件默认使用consumer(消费者)作为限流维度。如果没有配置消费者(比如你当前的场景),Kong会将所有请求归为同一个全局计数器,导致所有IP共享同一配额,一旦某个IP触发阈值,所有请求都会收到限流提示。
解决方法很简单,给每个rate-limiting插件的config部分添加limit_by: ip,让Kong按请求来源IP独立统计限流配额:
修改后的kong.yml配置:
_format_version: "2.1" _transform: true services: - name: auth-service url: http://xxxxxxxxxxx routes: - name: auth-routes paths: - /auth - name: audit-service url: http://xxxxxxxxxxx routes: - name: audit-routes paths: - /audits plugins: - name: rate-limiting service: auth-service config: limit_by: ip # 新增:按IP限流 minute: 100 hour: 1000 day: 10000 - name: rate-limiting service: audit-service config: limit_by: ip # 新增:按IP限流 minute: 100 hour: 1000 day: 10000
修改后重新加载Kong配置,再测试时每个IP会独立计算请求次数,不会出现一个IP触发限流导致所有IP被封禁的情况。
内容的提问来源于stack exchange,提问作者Tharindu Thisarasinghe
相关产品推荐
相关产品推荐

