如何使用登录信息对服务器指定端口进行负载测试?
Hey there! Let's figure out how to get your authenticated load testing sorted out. You mentioned Apache Bench (ab) didn't work for you when trying to hit a specific port with login credentials—let's start with fixing that, then cover some alternative tools that might make this easier.
Most authenticated flows rely on either cookies or bearer tokens, and ab can handle both with a bit of setup:
Grab your authentication cookie/token first
Usecurlto simulate a login request and capture the session cookie (or token) you need. For example, if your login is a POST form:curl -c cookies.txt -X POST -d "username=your_username&password=your_password" http://your-server:your-port/loginThe
-cflag saves the response cookies tocookies.txt. If your API uses a bearer token, extract it from the login response instead (e.g., usingjqto parse JSON output).Run ab with authentication
- For cookies: Extract the relevant cookie from the file and pass it to ab using the
-Cflag:
Here,ab -n 1000 -c 10 -C "$(grep -v '#' cookies.txt | awk '{print $6"="$7}')" http://your-server:your-port/target-endpoint-nis total requests,-cis concurrent requests, and-Csets the cookie header. - For bearer tokens: Use the
-Hflag to add an Authorization header:ab -n 1000 -c 10 -H "Authorization: Bearer your_auth_token" http://your-server:your-port/target-endpoint
- For cookies: Extract the relevant cookie from the file and pass it to ab using the
If ab feels clunky for authenticated flows, these tools are built to handle more complex scenarios with less friction:
wrk (lightweight, scriptable)
wrk uses Lua scripts to handle dynamic logic like login. Create a script (e.g.,login.lua):local session_cookie = nil request = function() -- First, log in if we don't have a cookie yet if not session_cookie then local login_resp = wrk.post("/login", nil, "username=your_user&password=your_pass") session_cookie = login_resp.headers["Set-Cookie"] end -- Send the test request with the cookie return wrk.format("GET", "/target-endpoint", {Cookie = session_cookie}) endRun it with:
wrk -t4 -c100 -d30s -s login.lua http://your-server:your-port-t= number of threads,-c= concurrent connections,-d= test duration.k6 (JS-based, user-friendly)
k6 uses JavaScript for test scripts, making it easy to write and maintain authenticated flows. Create atest.jsfile:import http from 'k6/http'; import { check, sleep } from 'k6'; export const options = { vus: 10, // Number of concurrent virtual users duration: '30s', // How long to run the test }; export default function () { // Step 1: Log in to get session const loginRes = http.post(`http://your-server:your-port/login`, { username: 'your_user', password: 'your_pass', }); check(loginRes, { 'Login succeeded': (r) => r.status === 200 }); // Step 2: Use the session cookie for the test request const testRes = http.get(`http://your-server:your-port/target-endpoint`, { cookies: loginRes.cookies, }); check(testRes, { 'Test request succeeded': (r) => r.status === 200 }); sleep(1); // Add a small delay between requests per user }Run with:
k6 run test.jsk6 also generates detailed, easy-to-read reports right in your terminal.
Gatling (enterprise-grade, scalable)
If you need to run large-scale tests with advanced reporting, Gatling is a great choice. It uses Scala (or a DSL) to define test scenarios, supports login flows out of the box, and produces interactive HTML reports. The learning curve is steeper, but it's perfect for complex performance testing needs.
内容的提问来源于stack exchange,提问作者Young4844

