如何获取EnvoyProxy/RateLimit特定用户名的限流指标?
为特定用户获取Envoy RateLimit限流指标的方法
问题根源在于当前配置仅将USERNAME作为限流规则的key,但未把请求头中实际的用户名值传递给RateLimit服务作为descriptor的value,导致指标只能统计整个USERNAME维度的聚合数据,无法拆分到具体用户。以下是解决步骤:
1. 调整EnvoyFilter配置,传递用户名实际值
需要在EnvoyFilter的限流过滤器配置中,添加value_extractor提取请求头里的username值,作为descriptor的value发送给RateLimit服务。示例配置如下:
apiVersion: networking.istio.io/v1alpha3 kind: EnvoyFilter metadata: name: ratelimit-username-extractor namespace: istio-system spec: workloadSelector: labels: istio: ingressgateway # 替换为你的目标服务标签 configPatches: - applyTo: HTTP_FILTER match: context: GATEWAY listener: filterChain: filter: name: "envoy.filters.network.http_connection_manager" subFilter: name: "envoy.filters.http.router" patch: operation: INSERT_BEFORE value: name: "envoy.filters.http.ratelimit" typed_config: "@type": type.googleapis.com/udpa.type.v1.TypedStruct type_url: type.googleapis.com/envoy.extensions.filters.http.ratelimit.v3.RateLimit value: domain: ratelimit rate_limit_service: grpc_service: envoy_grpc: cluster_name: outbound|8081||ratelimit.xxx.svc.cluster.local timeout: 10s enable_x_ratelimit_headers: DRAFT_VERSION_03 request_type: EXTERNAL descriptors: - entry: key: USERNAME value_extractor: header_value_extractor: name: username element_separator: "," default_value: "unknown-user"
核心是value_extractor部分,它会提取请求头username的实际值,若请求无该头则使用default_value兜底。
2. 确认RateLimit服务配置兼容
原有的RateLimit配置无需修改结构,只需确保服务能接收并识别Envoy传递的descriptor value:
domain: ratelimit descriptors: - key: USERNAME rate_limit: unit: second requests_per_unit: 100 shadow_mode: true
RateLimit服务默认会将descriptor的value作为指标标签输出,标签格式为valueN(N为descriptor层级)。
3. 验证指标效果
重新部署EnvoyFilter和RateLimit配置后,发送带不同username请求头的请求,查看RateLimit服务的指标,会发现新增value1标签对应具体用户名:
ratelimit_service_rate_limit_within_limit{app="ratelimit",domain="ratelimit",key1="USERNAME",value1="user1",...} ratelimit_service_rate_limit_within_limit{app="ratelimit",domain="ratelimit",key1="USERNAME",value1="user2",...}
此时即可按value1标签筛选特定用户的限流统计数据。
内容的提问来源于stack exchange,提问作者Marina Salmen
相关产品推荐
相关产品推荐

