本地速率限制器无法处理描述符条目多键问题排查
在Istio环境配置Local Rate Limiter时,发现当描述符条目包含多个键值对时无法生效,移除任意一个键值对后速率限制功能恢复正常。本地环境(Istio v1.26.1)的多键配置可正常工作,但沙箱环境(Istio v1.26.2,Envoy v1.34.2)中该配置失效,且所有代理同步状态均为SYNCED。现有基础设施采用Gateway API,需排查补充配置或组件检查点以解决该问题。
完整EnvoyFilter配置
apiVersion: networking.istio.io/v1alpha3 kind: EnvoyFilter metadata: labels: app.kubernetes.io/instance: sandbox2-api-gw-configs name: rails-test-app-app-rate-limit-local namespace: istio-ingress-api spec: configPatches: - applyTo: HTTP_FILTER match: context: GATEWAY listener: filterChain: filter: name: envoy.filters.network.http_connection_manager patch: operation: INSERT_BEFORE value: name: envoy.filters.http.local_ratelimit_rails-test-app-app-rate-limit-local typed_config: '@type': type.googleapis.com/udpa.type.v1.TypedStruct type_url: type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit value: stat_prefix: http_local_rate_limiter_rails-test-app-app-rate-limit-local - applyTo: HTTP_ROUTE match: context: GATEWAY routeConfiguration: vhost: name: correct.vhost.com:443 route: {} patch: operation: MERGE value: route: rate_limits: - actions: - request_headers: descriptor_key: xff header_name: 'x-forwarded-for' - actions: - header_value_match: descriptor_key: endpointrl descriptor_value: :path headers: - name: :path string_match: safe_regex: google_re2: {} regex: ^/rails-test-app([/|?].*)?$ typed_per_filter_config: envoy.filters.http.local_ratelimit_rails-test-app-app-rate-limit-local: '@type': type.googleapis.com/udpa.type.v1.TypedStruct type_url: type.googleapis.com/envoy.extensions.filters.http.local_ratelimit.v3.LocalRateLimit value: descriptors: - entries: - key: endpointrl value: :path - key: xff value: "123.123.123.123" token_bucket: fill_interval: 100s max_tokens: 2 tokens_per_fill: 2 filter_enabled: default_value: denominator: HUNDRED numerator: 100 runtime_key: local_rate_limit_enabled_rails-test-app-app-rate-limit-local filter_enforced: default_value: denominator: HUNDRED numerator: 100 runtime_key: local_rate_limit_enforced_rails-test-app-app-rate-limit-local stat_prefix: http_local_rate_limiter_rails-test-app-app-rate-limit-local token_bucket: fill_interval: 10s max_tokens: 10000000 tokens_per_fill: 1000000 workloadSelector: labels: app: external-gateway-istio
沙箱环境代理状态
$ istioctl proxy-status NAME CLUSTER CDS LDS EDS RDS ECDS ISTIOD VERSION <...> external-gateway-istio-54cf8dcb87-trw78.istio-ingress-api sandbox2 SYNCED (22m) SYNCED (22m) SYNCED (22m) SYNCED (22m) IGNORED istiod-85c7fd5c7f-jlx4t 1.26.2 <...> gs1-front-sandbox-internal1.istio-ingress sandbox2 SYNCED (5m8s) SYNCED (5m8s) SYNCED (5m8s) SYNCED (5m8s) IGNORED istiod-85c7fd5c7f-l7788 1.26.2 <...> rails-test-app-app-sandbox2-common-deployment-ff667cc4fd8wxd.rails-test-app. sandbox2 SYNCED (16m) SYNCED (16m) SYNCED (104s) SYNCED (16m) IGNORED istiod-85c7fd5c7f-l7788 1.26.2
Envoy版本
k exec -it external-gateway-istio-54cf8dcb87-trw78 -n istio-ingress-api -- curl localhost:15000/server_info | grep version "version": "ad034036be91ff9f0cd1993e5053dd4f3ee64895/1.34.2-dev/Clean/RELEASE/BoringSSL",
排查与解决建议
修正描述符键的匹配顺序:
Envoy本地限流的描述符条目必须与路由中rate_limits.actions的定义顺序完全一致。当前路由动作先定义xff,再定义endpointrl,但描述符条目顺序相反,会导致匹配失败。调整描述符顺序如下:descriptors: - entries: - key: xff value: "123.123.123.123" - key: endpointrl value: :path token_bucket: fill_interval: 100s max_tokens: 2 tokens_per_fill: 2验证Gateway API兼容性配置:
确认Istio已启用Gateway API支持,检查IstioOperator配置:apiVersion: install.istio.io/v1alpha1 kind: IstioOperator spec: components: gatewayAPI: enabled: true同时确保Gateway API CRDs已正确安装,且版本与Istio v1.26.2适配。
检查Envoy过滤器插入位置:
确认Local Rate Limit过滤器插入位置在路由、认证等核心过滤器之前,避免请求被提前处理导致限流逻辑未触发。当前配置的INSERT_BEFORE到http_connection_manager需验证实际执行顺序。排查Envoy版本差异:
沙箱环境使用Envoy v1.34.2-dev,本地环境对应Envoy版本为v1.33.x,可尝试临时回退Envoy版本到v1.33.x,验证是否为版本引入的bug导致失效。查看Envoy日志与统计指标:
查看限流相关日志:kubectl logs -n istio-ingress-api external-gateway-istio-54cf8dcb87-trw78 -c istio-proxy | grep local_rate_limit检查限流统计指标,确认描述符匹配情况:
kubectl exec -n istio-ingress-api external-gateway-istio-54cf8dcb87-trw78 -c istio-proxy -- curl localhost:15000/stats | grep http_local_rate_limiter_rails-test-app-app-rate-limit-local验证路由匹配准确性:
确认vhost.name: correct.vhost.com:443与实际请求的域名、端口完全匹配,路径正则^/rails-test-app([/|?].*)?$能正确命中目标请求路径,避免因路由不匹配导致限流规则未生效。
内容的提问来源于stack exchange,提问作者Medardas

