You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

本地速率限制器无法处理描述符条目多键问题排查

Istio本地速率限制多键描述符失效排查与解决

在Istio环境配置Local Rate Limiter时,发现当描述符条目包含多个键值对时无法生效,移除任意一个键值对后速率限制功能恢复正常。本地环境(Istio v1.26.1)的多键配置可正常工作,但沙箱环境(Istio v1.26.2,Envoy v1.34.2)中该配置失效,且所有代理同步状态均为SYNCED。现有基础设施采用Gateway API,需排查补充配置或组件检查点以解决该问题。

完整EnvoyFilter配置

apiVersion: networking.istio.io/v1alpha3
kind: EnvoyFilter
metadata:
  labels:
    app.kubernetes.io/instance: sandbox2-api-gw-configs
  name: rails-test-app-app-rate-limit-local
  namespace: istio-ingress-api
spec:
  configPatches:
  - applyTo: HTTP_FILTER
    match:
      context: GATEWAY
      listener:
        filterChain:
          filter:
            name: envoy.filters.network.http_connection_manager
    patch:
      operation: INSERT_BEFORE
      value:
        name: envoy.filters.http.local_ratelimit_rails-test-app-app-rate-limit-local
        typed_config:
          '@type': type.googleapis.com/udpa.type.v1.TypedStruct
          type_url: type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit
          value:
            stat_prefix: http_local_rate_limiter_rails-test-app-app-rate-limit-local
  - applyTo: HTTP_ROUTE
    match:
      context: GATEWAY
      routeConfiguration:
        vhost:
          name: correct.vhost.com:443
          route: {}
    patch:
      operation: MERGE
      value:
        route:
          rate_limits:
          - actions:
            - request_headers:
                descriptor_key: xff
                header_name: 'x-forwarded-for'
          - actions:
            - header_value_match:
                descriptor_key: endpointrl
                descriptor_value: :path
                headers:
                - name: :path
                  string_match:
                    safe_regex:
                      google_re2: {}
                      regex: ^/rails-test-app([/|?].*)?$
        typed_per_filter_config:
          envoy.filters.http.local_ratelimit_rails-test-app-app-rate-limit-local:
            '@type': type.googleapis.com/udpa.type.v1.TypedStruct
            type_url: type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit
            value:
              descriptors:
              - entries:
                - key: endpointrl
                  value: :path
                - key: xff
                  value: "123.123.123.123"
                token_bucket:
                  fill_interval: 100s
                  max_tokens: 2
                  tokens_per_fill: 2
              filter_enabled:
                default_value:
                  denominator: HUNDRED
                  numerator: 100
                runtime_key: local_rate_limit_enabled_rails-test-app-app-rate-limit-local
              filter_enforced:
                default_value:
                  denominator: HUNDRED
                  numerator: 100
                runtime_key: local_rate_limit_enforced_rails-test-app-app-rate-limit-local
              stat_prefix: http_local_rate_limiter_rails-test-app-app-rate-limit-local
              token_bucket:
                fill_interval: 10s
                max_tokens: 10000000
                tokens_per_fill: 1000000
  workloadSelector:
    labels:
      app: external-gateway-istio

沙箱环境代理状态

$ istioctl proxy-status
NAME                                                                                       CLUSTER         CDS                LDS                EDS               RDS                ECDS        ISTIOD                      VERSION
<...>
external-gateway-istio-54cf8dcb87-trw78.istio-ingress-api                                  sandbox2     SYNCED (22m)       SYNCED (22m)       SYNCED (22m)      SYNCED (22m)       IGNORED     istiod-85c7fd5c7f-jlx4t     1.26.2
<...>
gs1-front-sandbox-internal1.istio-ingress                                                  sandbox2     SYNCED (5m8s)      SYNCED (5m8s)      SYNCED (5m8s)     SYNCED (5m8s)      IGNORED     istiod-85c7fd5c7f-l7788     1.26.2
<...>
rails-test-app-app-sandbox2-common-deployment-ff667cc4fd8wxd.rails-test-app.               sandbox2     SYNCED (16m)       SYNCED (16m)       SYNCED (104s)     SYNCED (16m)       IGNORED     istiod-85c7fd5c7f-l7788     1.26.2

Envoy版本

k exec -it external-gateway-istio-54cf8dcb87-trw78 -n istio-ingress-api -- curl localhost:15000/server_info | grep version
"version": "ad034036be91ff9f0cd1993e5053dd4f3ee64895/1.34.2-dev/Clean/RELEASE/BoringSSL",

排查与解决建议

  • 修正描述符键的匹配顺序:
    Envoy本地限流的描述符条目必须与路由中rate_limits.actions的定义顺序完全一致。当前路由动作先定义xff,再定义endpointrl,但描述符条目顺序相反,会导致匹配失败。调整描述符顺序如下:

    descriptors:
    - entries:
      - key: xff
        value: "123.123.123.123"
      - key: endpointrl
        value: :path
      token_bucket:
        fill_interval: 100s
        max_tokens: 2
        tokens_per_fill: 2
    
  • 验证Gateway API兼容性配置:
    确认Istio已启用Gateway API支持,检查IstioOperator配置:

    apiVersion: install.istio.io/v1alpha1
    kind: IstioOperator
    spec:
      components:
        gatewayAPI:
          enabled: true
    

    同时确保Gateway API CRDs已正确安装,且版本与Istio v1.26.2适配。

  • 检查Envoy过滤器插入位置:
    确认Local Rate Limit过滤器插入位置在路由、认证等核心过滤器之前,避免请求被提前处理导致限流逻辑未触发。当前配置的INSERT_BEFORE到http_connection_manager需验证实际执行顺序。

  • 排查Envoy版本差异:
    沙箱环境使用Envoy v1.34.2-dev,本地环境对应Envoy版本为v1.33.x,可尝试临时回退Envoy版本到v1.33.x,验证是否为版本引入的bug导致失效。

  • 查看Envoy日志与统计指标:
    查看限流相关日志:

    kubectl logs -n istio-ingress-api external-gateway-istio-54cf8dcb87-trw78 -c istio-proxy | grep local_rate_limit
    

    检查限流统计指标,确认描述符匹配情况:

    kubectl exec -n istio-ingress-api external-gateway-istio-54cf8dcb87-trw78 -c istio-proxy -- curl localhost:15000/stats | grep http_local_rate_limiter_rails-test-app-app-rate-limit-local
    
  • 验证路由匹配准确性:
    确认vhost.name: correct.vhost.com:443与实际请求的域名、端口完全匹配,路径正则^/rails-test-app([/|?].*)?$能正确命中目标请求路径,避免因路由不匹配导致限流规则未生效。

内容的提问来源于stack exchange,提问作者Medardas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 17:29:54