Istio中Envoy Filter正则匹配限流不生效求助
Istio本地限流规则不生效的问题修复
问题根源分析
你的配置存在两个核心问题导致特定路径限流规则未生效:
HTTP过滤器插入位置错误
第一个HTTP_FILTER补丁的匹配规则错误,没有定位到HTTP过滤器链中的router过滤器,导致local_ratelimit过滤器未被正确添加到请求处理流程中。路径匹配正则不精确
路径匹配正则api/iam/.*未包含开头的斜杠和锚点,无法匹配实际请求的/api/iam/xxx格式路径,导致特定路径的限流规则永远不会触发。
修正后的EnvoyFilter配置
apiVersion: networking.istio.io/v1alpha3 kind: EnvoyFilter metadata: name: filter-local-ratelimit-svc namespace: istio-system spec: workloadSelector: labels: app: iam-authn-service env: az-dev configPatches: - applyTo: HTTP_FILTER match: context: SIDECAR_INBOUND listener: filterChain: filter: name: "envoy.filters.network.http_connection_manager" subFilter: name: "envoy.filters.http.router" patch: operation: INSERT_BEFORE value: name: envoy.filters.http.local_ratelimit typed_config: "@type": type.googleapis.com/udpa.type.v1.TypedStruct type_url: type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit value: stat_prefix: http_local_rate_limiter - applyTo: HTTP_ROUTE match: context: SIDECAR_INBOUND routeConfiguration: vhost: name: "inbound|http|8080" route: action: ANY patch: operation: MERGE value: route: rate_limits: - actions: - header_value_match: descriptor_value: two_legged_path headers: - name: ":path" string_match: safe_regex: google_re2: {} regex: "^/api/iam/.*$" typed_per_filter_config: envoy.filters.http.local_ratelimit: "@type": type.googleapis.com/udpa.type.v1.TypedStruct type_url: type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit value: stat_prefix: http_local_rate_limiter descriptors: - entries: - key: header_match value: two_legged_path token_bucket: max_tokens: 2 tokens_per_fill: 2 fill_interval: 60s token_bucket: max_tokens: 100 tokens_per_fill: 100 fill_interval: 1s filter_enabled: runtime_key: local_rate_limit_enabled default_value: numerator: 100 denominator: HUNDRED filter_enforced: runtime_key: local_rate_limit_enforced default_value: numerator: 100 denominator: HUNDRED response_headers_to_add: - append: false header: key: x-local-rate-limit value: 'true'
关键修改说明
- 调整过滤器插入位置:在
HTTP_FILTER补丁中添加subFilter: { name: "envoy.filters.http.router" },确保local_ratelimit过滤器被插入到请求路由前的正确位置,保证限流逻辑先于路由执行。 - 修正路径匹配正则:将正则改为
^/api/iam/.*$,精确匹配以/api/iam/开头的所有路径。
验证步骤
- 应用修正后的配置:
kubectl apply -f your-envoyfilter.yaml - 等待Sidecar配置刷新,或手动重启目标Pod:
kubectl rollout restart deployment/iam-authn-service -n your-namespace - 测试限流规则:
- 对
/api/iam/xxx路径发起3次请求,第3次应返回429状态码。 - 对其他路径发起超过100次/秒的请求,验证默认限流是否生效。
- 对
- 查看Envoy统计信息确认规则触发:
istioctl pc stats <pod-name> -n your-namespace | grep local_rate
内容的提问来源于stack exchange,提问作者Nikhil Dhirmalani
相关产品推荐
相关产品推荐

