如何在OpenShift HAProxy中按后端/路由限制连接数?
Hey Marek, great question—let's walk through how OpenShift objects map to HAProxy configs and the right ways to implement the traffic limiting you need.
OpenShift Object ↔ HAProxy Config Mapping
First, let's clarify the key mappings you're asking about:
- OpenShift Route → HAProxy Backend: Every Route in OpenShift gets its own dedicated backend in the HAProxy config. This backend includes all the pods that the Route routes traffic to (listed as
serverentries). - OpenShift Application/Project → HAProxy ACL/Backend Group: For multiple Routes under the same app or project, you can group them using HAProxy ACLs (based on host headers, path prefixes, etc.) and apply shared limits across the entire group.
Recommended Limiting Strategies
1. Limit by Individual Route (Backend Level)
If you want to cap traffic for a single Route, just add a maxconn directive directly to its corresponding HAProxy backend. This sets a total connection limit for all pods under that Route, preventing it from overwhelming the HAProxy instance.
Example config snippet:
backend be_route_my-cool-app server pod-abc 10.244.1.5:8080 maxconn 150 server pod-def 10.244.2.7:8080 maxconn 150 maxconn 600 # Total max connections for this entire Route
This ensures even if all pods under the Route are busy, the total connections won't exceed 600—isolating it from other Routes.
2. Limit by Application/Project (Group Level)
For grouping multiple Routes under an app or project, use HAProxy ACLs to identify traffic belonging to that group, then apply a global connection limit using a stick-table. This works well if you want to enforce a total cap across all Routes in a project.
First, create an ACL to match traffic for your project (e.g., matching hostnames ending with your project's domain):
acl belongs_to_my_project hdr(host) -m end .my-project.example.com
Then, set up a stick-table to track connections and enforce the limit:
# Create a table to track current connections for the project stick-table type string size 100k store conn_cur # Match the project ACL and track connections by host tcp-request content track-sc0 hdr(host) if belongs_to_my_project # Reject new connections if total exceeds your limit tcp-request content reject if { sc0_conn_cur gt 2000 } belongs_to_my_project
This will block new connections to any Route in your project once the total hits 2000, keeping it from impacting the rest of the cluster.
Implementing in OpenShift Router
Remember, OpenShift's default HAProxy Router lets you customize the config via:
- Using a custom router template (modify the
haproxy-config.templatein the router deployment) - Adding custom config snippets via environment variables or config maps
So you can inject these ACLs and backend directives without rebuilding the entire router—just update the router's configuration to include your limiting rules.
That should give you the right balance between isolation and granularity you're looking for.
内容的提问来源于stack exchange,提问作者Marek

