You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Google Cloud Armor中实现基于IP的客户端速率限流

基于单个客户端IP的速率限流实现方法

你当前的规则是全局速率限制(所有IP共享100次/60秒的阈值),要实现仅对达到速率限制的单个IP限流,只需在rate_limit_options中添加enforce_on_key参数,指定按客户端源IP作为速率统计维度即可。

修改后的代码示例

rules=[
        gcp.compute.SecurityPolicyRuleArgs(
            action="throttle",
            match=gcp.compute.SecurityPolicyRuleMatchArgs(
                config=gcp.compute.SecurityPolicyRuleMatchConfigArgs(
                    src_ip_ranges=['*'],
                ),
                versioned_expr="SRC_IPS_V1",
            ),
            priority=110,
            description='Rate based throttling per client IP. Currently, in preview mode.',
            preview=True,
            rate_limit_options=gcp.compute.SecurityPolicyRuleRateLimitOptionsArgs(
                conform_action="allow",
                exceed_action="deny(429)",
                # 指定按客户端IP统计速率
                enforce_on_key="IP",
                rate_limit_threshold=gcp.compute.SecurityPolicyRuleRateLimitOptionsRateLimitThresholdArgs(
                    count=100,
                    interval_sec=60
                )
            )
        ),
        gcp.compute.SecurityPolicyRuleArgs(
            action="allow",
            description="default rule",
            match=gcp.compute.SecurityPolicyRuleMatchArgs(
                config=gcp.compute.SecurityPolicyRuleMatchConfigArgs(
                    src_ip_ranges=["*"],
                ),
                versioned_expr="SRC_IPS_V1",
            ),
            priority=2147483647,
        ),
    ]

关键配置说明

  • enforce_on_key="IP":将速率统计维度设置为客户端源IP,每个IP独立计算请求次数,互不干扰
  • 保留src_ip_ranges=['*']即可覆盖所有客户端IP,无需手动指定单个IP
  • 当某个IP在60秒内请求次数超过100次时,会触发deny(429)动作,其他未达阈值的IP仍可正常访问

内容的提问来源于stack exchange,提问作者Aviral Srivastava

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 12:35:26