You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为HTTPS端点配置Istio出口速率限制器?

Istio 外部HTTPS端点出口速率限制示例

前提条件

  • Istio 1.10+版本已安装并运行
  • 目标应用已部署且注入Istio Sidecar
  • Istio速率限制功能已启用

1. 将外部服务纳入Istio管控

首先通过ServiceEntry定义外部HTTPS服务,让Istio能识别并拦截对应流量:

apiVersion: networking.istio.io/v1alpha3
kind: ServiceEntry
metadata:
  name: google-external
spec:
  hosts:
  - www.google.com
  ports:
  - number: 443
    name: https
    protocol: HTTPS
  resolution: DNS
  location: MESH_EXTERNAL

2. 配置TLS通信规则

创建DestinationRule确保Sidecar与外部HTTPS服务的通信加密:

apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
  name: google-destination
spec:
  host: www.google.com
  trafficPolicy:
    tls:
      mode: SIMPLE # 直接发起HTTPS请求到外部服务

方案一:单实例本地速率限制

适用于限制单个Sidecar实例的出口请求速率,通过EnvoyFilter配置:

apiVersion: networking.istio.io/v1alpha3
kind: EnvoyFilter
metadata:
  name: google-local-rate-limit
  namespace: istio-system
spec:
  workloadSelector:
    labels:
      app: my-app # 替换为你要限制的应用标签
  configPatches:
  - applyTo: HTTP_FILTER
    match:
      context: SIDECAR_OUTBOUND
      listener:
        portNumber: 443
        filterChain:
          filter:
            name: "envoy.filters.network.http_connection_manager"
            subFilter:
              name: "envoy.filters.http.router"
    patch:
      operation: INSERT_BEFORE
      value:
        name: envoy.filters.http.local_ratelimit
        typed_config:
          "@type": type.googleapis.com/udpa.type.v1.TypedStruct
          type_url: type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit
          value:
            stat_prefix: http_local_rate_limiter
            token_bucket:
              max_tokens: 10        # 最大并发令牌数
              tokens_per_fill: 10   # 每次填充令牌数
              fill_interval: 60s    # 令牌填充间隔(每分钟)
            filter_enabled:
              runtime_key: local_rate_limit_enabled
              default_value:
                numerator: 100
                denominator: HUNDRED
            filter_enforced:
              runtime_key: local_rate_limit_enforced
              default_value:
                numerator: 100
                denominator: HUNDRED
            response_headers_to_add:
            - append: false
              header:
                key: x-local-rate-limit
                value: 'true'

说明:配置生效后,该应用实例每分钟最多发起10次到www.google.com的请求,超出时会返回429状态码。


方案二:集群级全局速率限制

适用于限制集群内所有应用访问该外部服务的总速率,需结合Istio全局配额系统:

4.1 定义配额规则与绑定

# 定义配额规格
apiVersion: config.istio.io/v1alpha2
kind: QuotaSpec
metadata:
  name: google-global-quota
spec:
  rules:
  - quotas:
    - charge: 1
      quota: google-requests
---
# 将配额绑定到外部服务
apiVersion: config.istio.io/v1alpha2
kind: QuotaSpecBinding
metadata:
  name: google-quota-binding
spec:
  quotaSpecs:
  - name: google-global-quota
    namespace: default
  services:
  - name: google-external
    namespace: default
    service: www.google.com

4.2 配置全局速率限制规则

# 定义配额实例维度
apiVersion: config.istio.io/v1alpha2
kind: QuotaInstance
metadata:
  name: google-quota-instance
spec:
  dimensions:
    destination: destination.service.name | "unknown"
---
# 配置速率限制阈值
apiVersion: config.istio.io/v1alpha2
kind: RateLimit
metadata:
  name: google-rate-limit
spec:
  actions:
  - destination: {}
  quotas:
  - name: google-requests
    maxAmount: 50
    validDuration: 60s
    overrides:
    - dimensions:
        destination: www.google.com
      maxAmount: 50
      validDuration: 60s

说明:该配置限制集群内所有应用每分钟最多发起50次到www.google.com的请求,超出时返回429状态码。


验证配置

部署所有资源后,通过应用发起请求测试:

# 连续发起请求测试速率限制
for i in {1..20}; do curl -I https://www.google.com; done

当超出限制时,会收到429 Too Many Requests响应,同时可通过Sidecar日志或Istio监控确认规则生效。

内容的提问来源于stack exchange,提问作者n0rm4l

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.26 07:18:19