HTTP Rate Limit Middleware Client Identification and Replica Scaling
0 reputation · 16 Jan 2020, 00:20 UTC
Rate Limiting with Token Bucket
Traefik Proxy utilizes a token-bucket model for HTTP rate limiting, allowing for a defined average request rate and a burst capacity. This middleware is typically applied to routers to prevent service exhaustion by limiting the number of requests processed per client.
Client Identification and State Management
The sourceCriterion determines how clients are identified, often defaulting to the source IP. However, in deployments involving multiple Traefik replicas behind a load balancer, the rate limit state is maintained in-memory per instance. This architecture means the aggregate throughput permitted across a cluster is the product of the configured average rate and the number of active replicas.
When scaling horizontally, the lack of a shared state store creates uncertainty regarding the precision of global rate enforcement. Additionally, the interaction between the limiter and other middleware in the chain can affect how tokens are consumed during retries or buffered requests.
- Does the current implementation support a distributed state for rate limiting across multiple replicas?
- How does the
sourceCriterionbehave when Traefik is deployed behind an external proxy that modifies the source IP?