You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Istio Envoy 速率限制对携带子路径的描述符不生效问题排查

Istio EnvoyFilter 路径级本地速率限制配置问题排查

问题现象

通过 Istio EnvoyFilter 实现速率限制功能时,服务级别的速率限制运行正常,但无法为服务子路径配置独立速率限制,例如 /productpage 和 /api/v1/products 仍共用服务级别的速率限制规则。

初始问题配置

以下是对接 Istio 演示项目 Bookinfo 的初始 EnvoyFilter 配置:

apiVersion: networking.istio.io/v1alpha3
kind: EnvoyFilter
metadata:
  name: filter-local-ratelimit-svc
  namespace: istio-system
spec:
  workloadSelector:
    labels:
      app: productpage
  configPatches:
    - applyTo: HTTP_FILTER
      match:
        context: SIDECAR_INBOUND
        listener:
          filterChain:
            filter:
              name: "envoy.filters.network.http_connection_manager"
      patch:
        operation: INSERT_BEFORE
        value:
          name: envoy.filters.http.local_ratelimit
          typed_config:
            "@type": type.googleapis.com/udpa.type.v1.TypedStruct
            type_url: type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit
            value:
              stat_prefix: http_local_rate_limiter

    - applyTo: HTTP_ROUTE
      match:
        context: SIDECAR_INBOUND
        routeConfiguration:
          vhost:
            name: "inbound|http|9080"
            route:
              action: ANY
      patch:
        operation: MERGE
        value:
          typed_per_filter_config:
            envoy.filters.http.local_ratelimit:
              "@type": type.googleapis.com/udpa.type.v1.TypedStruct
              type_url: type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit
              value:
                rate_limits:
                  - actions:
                      - request_headers:
                          header_name: ":path"
                          descriptor_key: path
                stat_prefix: http_local_rate_limiter
                token_bucket:
                  max_tokens: 5
                  tokens_per_fill: 5
                  fill_interval: 60s
                filter_enabled:
                  runtime_key: local_rate_limit_enabled
                  default_value:
                    numerator: 100
                    denominator: HUNDRED
                filter_enforced:
                  runtime_key: local_rate_limit_enforced
                  default_value:
                    numerator: 100
                    denominator: HUNDRED
                response_headers_to_add:
                  - append: false
                    header:
                      key: x-local-rate-limit
                      value: "true" 
                descriptors:
                  - entries:
                      - key: path
                        value: /productpage
                    token_bucket:
                      max_tokens: 3
                      tokens_per_fill: 3
                      fill_interval: 60s
                  - entries:
                      - key: path
                        value: /api/v1/products
                    token_bucket:
                      max_tokens: 2
                      tokens_per_fill: 2
                      fill_interval: 60s

问题根因

初始配置错误地将rate_limits动作定义在了本地限流过滤器的typed_per_filter_config配置段内,而 Envoy 本地限流逻辑要求,路由级的限流动作必须定义在路由规则本身的rate_limits字段下,才能正确生成请求描述符匹配后续的路径级限流规则。

修复方案

新增一个HTTP_ROUTE类型的配置补丁,将路径提取的限流动作挂载到路由规则下即可:

- applyTo: HTTP_ROUTE
  match:
    context: SIDECAR_INBOUND
    routeConfiguration:
      vhost:
        name: "inbound|http|9080"
        route:
          action: ANY
  patch:
    operation: MERGE
    value:
      route:
          rate_limits:
          - actions:
            - request_headers:
                header_name: ":path"
                descriptor_key: path 

修复后即可正常实现多维度速率限制:

  • 全局默认速率限制:每分钟允许5次请求
  • /productpage路径专属限制:每分钟允许3次请求
  • /api/v1/products路径专属限制:每分钟允许2次请求

内容的提问来源于stack exchange,提问作者user16486569

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.06 04:06:02