You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Istio中Envoy Filter正则匹配限流不生效求助

Istio本地限流规则不生效的问题修复

问题根源分析

你的配置存在两个核心问题导致特定路径限流规则未生效:

  1. HTTP过滤器插入位置错误
    第一个HTTP_FILTER补丁的匹配规则错误,没有定位到HTTP过滤器链中的router过滤器,导致local_ratelimit过滤器未被正确添加到请求处理流程中。

  2. 路径匹配正则不精确
    路径匹配正则api/iam/.*未包含开头的斜杠和锚点,无法匹配实际请求的/api/iam/xxx格式路径,导致特定路径的限流规则永远不会触发。

修正后的EnvoyFilter配置

apiVersion: networking.istio.io/v1alpha3
kind: EnvoyFilter
metadata:
  name: filter-local-ratelimit-svc
  namespace: istio-system
spec:
  workloadSelector:
    labels:
      app: iam-authn-service
      env: az-dev
  configPatches:
    - applyTo: HTTP_FILTER
      match:
        context: SIDECAR_INBOUND
        listener:
          filterChain:
            filter:
              name: "envoy.filters.network.http_connection_manager"
              subFilter:
                name: "envoy.filters.http.router"
      patch:
        operation: INSERT_BEFORE
        value:
          name: envoy.filters.http.local_ratelimit
          typed_config:
            "@type": type.googleapis.com/udpa.type.v1.TypedStruct
            type_url: type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit
            value:
              stat_prefix: http_local_rate_limiter
    - applyTo: HTTP_ROUTE
      match:
        context: SIDECAR_INBOUND
        routeConfiguration:
          vhost:
            name: "inbound|http|8080"
            route:
              action: ANY
      patch:
        operation: MERGE
        value:
          route:
            rate_limits:
              - actions:
                 - header_value_match:
                    descriptor_value: two_legged_path
                    headers:
                    - name: ":path"
                      string_match:
                        safe_regex:
                          google_re2: {}
                          regex: "^/api/iam/.*$"
          typed_per_filter_config:
            envoy.filters.http.local_ratelimit:
              "@type": type.googleapis.com/udpa.type.v1.TypedStruct
              type_url: type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit
              value:
                stat_prefix: http_local_rate_limiter
                descriptors:
                - entries:
                  - key: header_match
                    value: two_legged_path
                  token_bucket:
                    max_tokens: 2
                    tokens_per_fill: 2
                    fill_interval: 60s
                token_bucket:
                  max_tokens: 100
                  tokens_per_fill: 100
                  fill_interval: 1s
                filter_enabled:
                  runtime_key: local_rate_limit_enabled
                  default_value:
                    numerator: 100
                    denominator: HUNDRED
                filter_enforced:
                  runtime_key: local_rate_limit_enforced
                  default_value:
                    numerator: 100
                    denominator: HUNDRED
                response_headers_to_add:
                  - append: false
                    header:
                      key: x-local-rate-limit
                      value: 'true'

关键修改说明

  • 调整过滤器插入位置:在HTTP_FILTER补丁中添加subFilter: { name: "envoy.filters.http.router" },确保local_ratelimit过滤器被插入到请求路由前的正确位置,保证限流逻辑先于路由执行。
  • 修正路径匹配正则:将正则改为^/api/iam/.*$,精确匹配以/api/iam/开头的所有路径。

验证步骤

  1. 应用修正后的配置:
    kubectl apply -f your-envoyfilter.yaml
    
  2. 等待Sidecar配置刷新,或手动重启目标Pod:
    kubectl rollout restart deployment/iam-authn-service -n your-namespace
    
  3. 测试限流规则:
    • 对/api/iam/xxx路径发起3次请求,第3次应返回429状态码。
    • 对其他路径发起超过100次/秒的请求,验证默认限流是否生效。
  4. 查看Envoy统计信息确认规则触发:
    istioctl pc stats <pod-name> -n your-namespace | grep local_rate
    

内容的提问来源于stack exchange,提问作者Nikhil Dhirmalani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 02:25:38