Help Center/ Cloud Container Engine/ User Guide/ Networking/ Ingresses/ LoadBalancer Ingresses/ Protocol and Listening Configuration/ Configuring Rate Limiting on New and Concurrent Connections for a LoadBalancer Ingress Listener
Updated on 2026-09-21 GMT+08:00

Configuring Rate Limiting on New and Concurrent Connections for a LoadBalancer Ingress Listener

This section describes how to use the kubernetes.io/elb.cps and kubernetes.io/elb.connection annotations to configure rate limiting for new and concurrent connections on a LoadBalancer ingress listener. This prevents backend services from being overloaded by burst traffic.

Prerequisites

  • A CCE standard or Turbo cluster is available, and the cluster version meets the following requirements:
    • v1.30: v1.30.14-r100 or later
    • v1.31: v1.31.14-r60 or later
    • v1.32: v1.32.13-r30 or later
    • v1.33: v1.33.12-r10 or later
    • v1.34: v1.34.8-r10 or later
    • v1.35: v1.35.5-r10 or later
    • v1.36: v1.36.2-r0 or later
    • Clusters of later versions
  • An available workload has been deployed in the cluster for external access. If no workload is available, deploy a workload by referring to Creating a Deployment, Creating a StatefulSet, or Creating a DaemonSet.
  • A Service for external access has been configured for the workload. Services Supported by LoadBalancer Ingresses lists the Service types supported by LoadBalancer ingresses.

Constraints

Only dedicated load balancers are supported.

Using kubectl

  1. Use kubectl to access the cluster. For details, see Accessing a Cluster Using kubectl.
  2. Create a YAML file named ingress-test.yaml. The file name can be customized.

    vi ingress-test.yaml

    The following shows an example configuration using an existing load balancer:

    apiVersion: networking.k8s.io/v1
    kind: Ingress
    metadata:
      annotations:
        kubernetes.io/elb.id: 2c623150-17bf-45f1-ae6f-384b03******     # ID of an existing load balancer
        kubernetes.io/elb.class: performance    # Load balancer type
        kubernetes.io/elb.port: '443'
        kubernetes.io/elb.tls-certificate-ids: 6cfb43c9de1a41a18478b868e3******,6cfb43c9de1a41a18478b868e*****   # HTTPS certificate configuration
        kubernetes.io/elb.connection: '10'  # Rate limit on concurrent connections to the listener
        kubernetes.io/elb.cps: '100' # Rate limit on new connections to the listener
      name: ingress-test
      namespace: default
    spec:
      ingressClassName: cce
      rules:
      - host: example.com
        http:
          paths:
          - backend:
              service:
                name: test
                port:
                  number: 8888
            path: /
            pathType: ImplementationSpecific
            property:
              ingress.beta.kubernetes.io/url-match-mode: STARTS_WITH

    The involved parameters are described in the table below.

    Parameter

    Type

    Description

    kubernetes.io/elb.cps

    Integer

    Definition: The maximum number of new connections that a listener can handle per second.

    Constraints: If this value exceeds the limit defined in the load balancer, the load balancer's limit takes precedence.

    Range: 0 to 1000000

    Default value: 0, indicating no limit.

    kubernetes.io/elb.connection

    Integer

    Definition: The maximum number of concurrent connections that a listener can handle.

    Constraints: If this value exceeds the limit defined in the load balancer, the load balancer's limit takes precedence.

    Range: 0 to 1000000

    Default value: 0, indicating no limit.

  3. Create the ingress.

    kubectl create -f ingress-test.yaml

    If information similar to the following is displayed, the ingress has been created:

    ingress.networking.k8s.io/ingress-test created

  4. Check the created ingress.

    kubectl get ingress

    If information similar to the following is displayed, the ingress has been created:

    NAME          CLASS    HOSTS           ADDRESS          PORTS   AGE
    ingress-test  cce      example.com     121.**.**.**     80,443  10s

  5. On the ELB console, view the currently effective rate limiting configuration for the listener on port 443.

    The listener limits new connections to 100 per second and concurrent connections to 10 in the specified AZ.