Istio Envoy 速率限制对携带子路径的描述符不生效问题排查
Istio EnvoyFilter 路径级本地速率限制配置问题排查
问题现象
通过 Istio EnvoyFilter 实现速率限制功能时,服务级别的速率限制运行正常,但无法为服务子路径配置独立速率限制,例如 /productpage 和 /api/v1/products 仍共用服务级别的速率限制规则。
初始问题配置
以下是对接 Istio 演示项目 Bookinfo 的初始 EnvoyFilter 配置:
apiVersion: networking.istio.io/v1alpha3 kind: EnvoyFilter metadata: name: filter-local-ratelimit-svc namespace: istio-system spec: workloadSelector: labels: app: productpage configPatches: - applyTo: HTTP_FILTER match: context: SIDECAR_INBOUND listener: filterChain: filter: name: "envoy.filters.network.http_connection_manager" patch: operation: INSERT_BEFORE value: name: envoy.filters.http.local_ratelimit typed_config: "@type": type.googleapis.com/udpa.type.v1.TypedStruct type_url: type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit value: stat_prefix: http_local_rate_limiter - applyTo: HTTP_ROUTE match: context: SIDECAR_INBOUND routeConfiguration: vhost: name: "inbound|http|9080" route: action: ANY patch: operation: MERGE value: typed_per_filter_config: envoy.filters.http.local_ratelimit: "@type": type.googleapis.com/udpa.type.v1.TypedStruct type_url: type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit value: rate_limits: - actions: - request_headers: header_name: ":path" descriptor_key: path stat_prefix: http_local_rate_limiter token_bucket: max_tokens: 5 tokens_per_fill: 5 fill_interval: 60s filter_enabled: runtime_key: local_rate_limit_enabled default_value: numerator: 100 denominator: HUNDRED filter_enforced: runtime_key: local_rate_limit_enforced default_value: numerator: 100 denominator: HUNDRED response_headers_to_add: - append: false header: key: x-local-rate-limit value: "true" descriptors: - entries: - key: path value: /productpage token_bucket: max_tokens: 3 tokens_per_fill: 3 fill_interval: 60s - entries: - key: path value: /api/v1/products token_bucket: max_tokens: 2 tokens_per_fill: 2 fill_interval: 60s
问题根因
初始配置错误地将rate_limits动作定义在了本地限流过滤器的typed_per_filter_config配置段内,而 Envoy 本地限流逻辑要求,路由级的限流动作必须定义在路由规则本身的rate_limits字段下,才能正确生成请求描述符匹配后续的路径级限流规则。
修复方案
新增一个HTTP_ROUTE类型的配置补丁,将路径提取的限流动作挂载到路由规则下即可:
- applyTo: HTTP_ROUTE match: context: SIDECAR_INBOUND routeConfiguration: vhost: name: "inbound|http|9080" route: action: ANY patch: operation: MERGE value: route: rate_limits: - actions: - request_headers: header_name: ":path" descriptor_key: path
修复后即可正常实现多维度速率限制:
- 全局默认速率限制:每分钟允许5次请求
/productpage路径专属限制:每分钟允许3次请求/api/v1/products路径专属限制:每分钟允许2次请求
内容的提问来源于stack exchange,提问作者user16486569
相关产品推荐
相关产品推荐

