Configuring Rate Limiting on New and Concurrent Connections for a LoadBalancer Ingress Listener
This section describes how to use the kubernetes.io/elb.cps and kubernetes.io/elb.connection annotations to configure rate limiting for new and concurrent connections on a LoadBalancer ingress listener. This prevents backend services from being overloaded by burst traffic.
Prerequisites
- A CCE standard or Turbo cluster is available, and the cluster version meets the following requirements:
- v1.30: v1.30.14-r100 or later
- v1.31: v1.31.14-r60 or later
- v1.32: v1.32.13-r30 or later
- v1.33: v1.33.12-r10 or later
- v1.34: v1.34.8-r10 or later
- v1.35: v1.35.5-r10 or later
- v1.36: v1.36.2-r0 or later
- Clusters of later versions
- An available workload has been deployed in the cluster for external access. If no workload is available, deploy a workload by referring to Creating a Deployment, Creating a StatefulSet, or Creating a DaemonSet.
- A Service for external access has been configured for the workload. Services Supported by LoadBalancer Ingresses lists the Service types supported by LoadBalancer ingresses.
Constraints
Only dedicated load balancers are supported.
Using kubectl
- Use kubectl to access the cluster. For details, see Accessing a Cluster Using kubectl.
- Create a YAML file named ingress-test.yaml. The file name can be customized.
vi ingress-test.yaml
The following shows an example configuration using an existing load balancer:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: annotations: kubernetes.io/elb.id: 2c623150-17bf-45f1-ae6f-384b03****** # ID of an existing load balancer kubernetes.io/elb.class: performance # Load balancer type kubernetes.io/elb.port: '443' kubernetes.io/elb.tls-certificate-ids: 6cfb43c9de1a41a18478b868e3******,6cfb43c9de1a41a18478b868e***** # HTTPS certificate configuration kubernetes.io/elb.connection: '10' # Rate limit on concurrent connections to the listener kubernetes.io/elb.cps: '100' # Rate limit on new connections to the listener name: ingress-test namespace: default spec: ingressClassName: cce rules: - host: example.com http: paths: - backend: service: name: test port: number: 8888 path: / pathType: ImplementationSpecific property: ingress.beta.kubernetes.io/url-match-mode: STARTS_WITHThe involved parameters are described in the table below.
Parameter
Type
Description
kubernetes.io/elb.cps
Integer
Definition: The maximum number of new connections that a listener can handle per second.
Constraints: If this value exceeds the limit defined in the load balancer, the load balancer's limit takes precedence.
Range: 0 to 1000000
Default value: 0, indicating no limit.
kubernetes.io/elb.connection
Integer
Definition: The maximum number of concurrent connections that a listener can handle.
Constraints: If this value exceeds the limit defined in the load balancer, the load balancer's limit takes precedence.
Range: 0 to 1000000
Default value: 0, indicating no limit.
- Create the ingress.
kubectl create -f ingress-test.yaml
If information similar to the following is displayed, the ingress has been created:
ingress.networking.k8s.io/ingress-test created
- Check the created ingress.
kubectl get ingress
If information similar to the following is displayed, the ingress has been created:
NAME CLASS HOSTS ADDRESS PORTS AGE ingress-test cce example.com 121.**.**.** 80,443 10s
- On the ELB console, view the currently effective rate limiting configuration for the listener on port 443.
The listener limits new connections to 100 per second and concurrent connections to 10 in the specified AZ.

What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot