You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

添加rate-limiting插件后Kong封禁全部IP问题求助

解决Kong速率限制全局封禁所有IP的问题

你的问题根源在于没有指定速率限制的统计维度,Kong的rate-limiting插件默认使用consumer(消费者)作为限流维度。如果没有配置消费者(比如你当前的场景),Kong会将所有请求归为同一个全局计数器,导致所有IP共享同一配额,一旦某个IP触发阈值,所有请求都会收到限流提示。

解决方法很简单,给每个rate-limiting插件的config部分添加limit_by: ip,让Kong按请求来源IP独立统计限流配额:

修改后的kong.yml配置:

_format_version: "2.1"
_transform: true

services:
  - name: auth-service
    url: http://xxxxxxxxxxx
    routes:
      - name: auth-routes
        paths:
          - /auth

  - name: audit-service
    url: http://xxxxxxxxxxx
    routes:
      - name: audit-routes
        paths:
          - /audits

plugins:
  - name: rate-limiting
    service: auth-service
    config:
      limit_by: ip  # 新增:按IP限流
      minute: 100
      hour: 1000
      day: 10000

  - name: rate-limiting
    service: audit-service
    config:
      limit_by: ip  # 新增:按IP限流
      minute: 100
      hour: 1000
      day: 10000

修改后重新加载Kong配置,再测试时每个IP会独立计算请求次数,不会出现一个IP触发限流导致所有IP被封禁的情况。

内容的提问来源于stack exchange,提问作者Tharindu Thisarasinghe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 01:47:03