You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为指定前缀路径配置Envoy本地速率限制?

Envoy本地速率限制:匹配指定路径前缀的配置方案

你的配置无法生效的核心原因是:当前速率限制规则使用精确路径匹配,只有路径完全等于/swagger-ui/的请求才会触发限制,而/swagger-ui/index.html这类子路径请求无法匹配。

以下提供两种可行的解决方法:

方法一:通过正则匹配统一处理路径前缀

修改路由中的速率限制规则,用正则提取所有以/swagger-ui/开头的路径,并映射为统一的描述符,让这类请求共享同一个速率限制桶。

修改后的关键配置片段:

route_config:
  name: local_route
  virtual_hosts:
  - name: backend
    domains: ["*"]
    routes:
    - match: { prefix: "/"}
      route: 
        cluster: middleware
        timeout: { seconds: 120 }
        rate_limits:
        - actions:
          - request_headers:
              header_name: ":path"
              descriptor_key: path_prefix
              # 匹配所有以/swagger-ui/开头的路径
              regex_match: "^/swagger-ui/.*$"
              # 将匹配到的路径统一替换为固定值,用于后续描述符匹配
              regex_substitution: "swagger-ui_prefix"
          # 保留原有的/user/create匹配规则
          - request_headers:
              header_name: ":path"
              descriptor_key: path
      typed_per_filter_config:
        envoy.filters.http.local_ratelimit:
          "@type": type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit
          stat_prefix: test
          token_bucket:
            max_tokens: 300
            tokens_per_fill: 1
            fill_interval: 600s
          filter_enabled:
            runtime_key: test_enabled
            default_value:
              numerator: 100
              denominator: HUNDRED
          filter_enforced:
            runtime_key: test_enforced
            default_value:
              numerator: 100
              denominator: HUNDRED
          descriptors:
          - entries:
            - key: path_prefix
              value: "swagger-ui_prefix"
            token_bucket:
              max_tokens: 15
              tokens_per_fill: 1
              fill_interval: 600s
          - entries:
            - key: path
              value: /user/create
            token_bucket:
              max_tokens: 3
              tokens_per_fill: 1
              fill_interval: 600s

核心说明:

  • regex_match: "^/swagger-ui/.*$":精准匹配所有以/swagger-ui/开头的请求路径
  • regex_substitution: "swagger-ui_prefix":将匹配到的路径统一替换为固定标识,确保所有符合前缀的请求对应同一个速率限制描述符
  • 描述符中key: path_prefix和value: "swagger-ui_prefix"与上述配置对应,让这类请求共享15/600s的速率限制

方法二:拆分路由单独配置(更直观)

直接为/swagger-ui/前缀的请求单独配置路由和速率限制,无需正则处理,适合规则明确的场景。

修改后的关键配置片段:

route_config:
  name: local_route
  virtual_hosts:
  - name: backend
    domains: ["*"]
    routes:
    # 优先匹配/swagger-ui/前缀的请求
    - match: { prefix: "/swagger-ui/" }
      route: 
        cluster: middleware
        timeout: { seconds: 120 }
      # 单独配置该路由的本地速率限制
      typed_per_filter_config:
        envoy.filters.http.local_ratelimit:
          "@type": type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit
          stat_prefix: swagger_ui_local_rate_limit
          token_bucket:
            max_tokens: 15
            tokens_per_fill: 1
            fill_interval: 600s
          filter_enabled:
            runtime_key: test_enabled
            default_value:
              numerator: 100
              denominator: HUNDRED
          filter_enforced:
            runtime_key: test_enforced
            default_value:
              numerator: 100
              denominator: HUNDRED
    # 处理其他所有请求
    - match: { prefix: "/"}
      route: 
        cluster: middleware
        timeout: { seconds: 120 }
        rate_limits:
        - actions:
          - request_headers:
              header_name: ":path"
              descriptor_key: path
      typed_per_filter_config:
        envoy.filters.http.local_ratelimit:
          "@type": type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit
          stat_prefix: test
          token_bucket:
            max_tokens: 300
            tokens_per_fill: 1
            fill_interval: 600s
          filter_enabled:
            runtime_key: test_enabled
            default_value:
              numerator: 100
              denominator: HUNDRED
          filter_enforced:
            runtime_key: test_enforced
            default_value:
              numerator: 100
              denominator: HUNDRED
          descriptors:
          - entries:
            - key: path
              value: /user/create
            token_bucket:
              max_tokens: 3
              tokens_per_fill: 1
              fill_interval: 600s

核心说明:

  • Envoy路由匹配遵循优先匹配原则,因此将/swagger-ui/前缀的路由放在前面
  • 该路由单独配置本地速率限制,所有以/swagger-ui/开头的请求都会使用这个规则
  • 其他请求走默认路由,保留原有的速率限制规则

内容的提问来源于stack exchange,提问作者Yonoss

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.23 11:09:56