You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Kong的API-KEY请求头限流配置组合需求咨询

组合Kong Rate-Limit插件的两种请求头限流方式(无需消费者配置)

可以直接组合这两种限流逻辑,不需要依赖消费者或消费者组,通过两个独立的KongPlugin实例+请求头匹配条件就能实现。

实现思路

  • 第一个插件:针对所有携带API-KEY请求头的请求,按头值做通用速率限制(对应需求1)。
  • 第二个插件:仅匹配指定的非活跃用户API-KEY,将速率设为0实现拦截(对应需求2)。

具体配置示例

1. 通用API-KEY限流插件(活跃用户速率控制)

这个插件会对所有携带API-KEY头的请求,按头值单独统计请求次数:

apiVersion: configuration.konghq.com/v1
kind: KongPlugin
metadata:
  name: rate-limit-api-key-general
config:
  key_names: ["API-KEY"]  # 指定用来限流的请求头
  limit_by: header        # 按请求头值做限流维度
  second: 5
  hour: 10000
  policy: local
plugin: rate-limiting

2. 特定API-KEY拦截插件(非活跃用户拦截)

这个插件仅对指定的API-KEY生效,将速率设为0直接拦截请求:

apiVersion: configuration.konghq.com/v1
kind: KongPlugin
metadata:
  name: rate-limit-api-key-block
config:
  key_names: ["API-KEY"]
  limit_by: header
  second: 0  # 速率设为0,直接拦截
  policy: local
plugin: rate-limiting
# 添加匹配条件,仅对指定API-KEY生效
annotations:
  konghq.com/match-request: |
    headers:
      API-KEY:
        - "inactive-key-1"
        - "inactive-key-2"  # 可以添加多个需要拦截的API-KEY

绑定到路由

将两个插件同时绑定到目标路由,确保请求会依次触发两个插件逻辑:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: your-api-ingress
  annotations:
    konghq.com/plugins: "rate-limit-api-key-general,rate-limit-api-key-block"
spec:
  rules:
  - host: your-api.example.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: your-api-service
            port:
              number: 80

逻辑说明

  • 当请求携带活跃用户的API-KEY时,只会触发第一个通用限流插件,按配置的速率限制请求。
  • 当请求携带指定的非活跃API-KEY时,会同时触发两个插件,第二个插件的速率0规则会优先拦截请求,直接返回429状态码。

内容的提问来源于stack exchange,提问作者Guneet Bhatia

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 20:31:02