如何为HTTPS端点配置Istio出口速率限制器?
Istio 外部HTTPS端点出口速率限制示例
前提条件
- Istio 1.10+版本已安装并运行
- 目标应用已部署且注入Istio Sidecar
- Istio速率限制功能已启用
1. 将外部服务纳入Istio管控
首先通过ServiceEntry定义外部HTTPS服务,让Istio能识别并拦截对应流量:
apiVersion: networking.istio.io/v1alpha3 kind: ServiceEntry metadata: name: google-external spec: hosts: - www.google.com ports: - number: 443 name: https protocol: HTTPS resolution: DNS location: MESH_EXTERNAL
2. 配置TLS通信规则
创建DestinationRule确保Sidecar与外部HTTPS服务的通信加密:
apiVersion: networking.istio.io/v1alpha3 kind: DestinationRule metadata: name: google-destination spec: host: www.google.com trafficPolicy: tls: mode: SIMPLE # 直接发起HTTPS请求到外部服务
方案一:单实例本地速率限制
适用于限制单个Sidecar实例的出口请求速率,通过EnvoyFilter配置:
apiVersion: networking.istio.io/v1alpha3 kind: EnvoyFilter metadata: name: google-local-rate-limit namespace: istio-system spec: workloadSelector: labels: app: my-app # 替换为你要限制的应用标签 configPatches: - applyTo: HTTP_FILTER match: context: SIDECAR_OUTBOUND listener: portNumber: 443 filterChain: filter: name: "envoy.filters.network.http_connection_manager" subFilter: name: "envoy.filters.http.router" patch: operation: INSERT_BEFORE value: name: envoy.filters.http.local_ratelimit typed_config: "@type": type.googleapis.com/udpa.type.v1.TypedStruct type_url: type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit value: stat_prefix: http_local_rate_limiter token_bucket: max_tokens: 10 # 最大并发令牌数 tokens_per_fill: 10 # 每次填充令牌数 fill_interval: 60s # 令牌填充间隔(每分钟) filter_enabled: runtime_key: local_rate_limit_enabled default_value: numerator: 100 denominator: HUNDRED filter_enforced: runtime_key: local_rate_limit_enforced default_value: numerator: 100 denominator: HUNDRED response_headers_to_add: - append: false header: key: x-local-rate-limit value: 'true'
说明:配置生效后,该应用实例每分钟最多发起10次到www.google.com的请求,超出时会返回429状态码。
方案二:集群级全局速率限制
适用于限制集群内所有应用访问该外部服务的总速率,需结合Istio全局配额系统:
4.1 定义配额规则与绑定
# 定义配额规格 apiVersion: config.istio.io/v1alpha2 kind: QuotaSpec metadata: name: google-global-quota spec: rules: - quotas: - charge: 1 quota: google-requests --- # 将配额绑定到外部服务 apiVersion: config.istio.io/v1alpha2 kind: QuotaSpecBinding metadata: name: google-quota-binding spec: quotaSpecs: - name: google-global-quota namespace: default services: - name: google-external namespace: default service: www.google.com
4.2 配置全局速率限制规则
# 定义配额实例维度 apiVersion: config.istio.io/v1alpha2 kind: QuotaInstance metadata: name: google-quota-instance spec: dimensions: destination: destination.service.name | "unknown" --- # 配置速率限制阈值 apiVersion: config.istio.io/v1alpha2 kind: RateLimit metadata: name: google-rate-limit spec: actions: - destination: {} quotas: - name: google-requests maxAmount: 50 validDuration: 60s overrides: - dimensions: destination: www.google.com maxAmount: 50 validDuration: 60s
说明:该配置限制集群内所有应用每分钟最多发起50次到www.google.com的请求,超出时返回429状态码。
验证配置
部署所有资源后,通过应用发起请求测试:
# 连续发起请求测试速率限制 for i in {1..20}; do curl -I https://www.google.com; done
当超出限制时,会收到429 Too Many Requests响应,同时可通过Sidecar日志或Istio监控确认规则生效。
内容的提问来源于stack exchange,提问作者n0rm4l
相关产品推荐
相关产品推荐

