Pembatasan Laju dan Pengendalian Arus dengan Nginx
Siapkan pembatasan laju untuk melindungi layanan backend dari penyalahgunaan dan memastikan penggunaan sumber daya yang adil.
Pembatasan Laju dan Pengendalian Arus dengan Nginx adalah pelajaran API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) gratis di CoddyKit. Ini adalah pelajaran 3 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway), dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) mencakup 4 pelajaran total.
Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.
Why Rate Limiting Matters
Imagine a popular website or API. What happens if one user or a malicious bot sends thousands of requests per second?
This is where rate limiting comes in! It's a crucial technique to control the number of requests a client can make to your server within a specific timeframe.
- Prevents abuse and DDoS attacks.
- Ensures fair resource usage for all clients.
- Protects your backend services from overload.
Nginx's Key Directives
Nginx provides powerful directives to implement rate limiting. We'll focus on two main ones:
limit_req_zone: Defines the parameters for a rate limiting zone. Think of it as setting up the rules for a specific type of traffic.limit_req: Applies the defined rate limiting rules to requests within a specificlocationorserverblock. This is where the magic happens!
Defining Your Rate Limit Zone
The limit_req_zone directive is typically placed in the http block of your Nginx configuration. It defines a shared memory zone where Nginx keeps track of request states.
Here's its structure and what each part means:
key: What Nginx tracks (e.g.,$binary_remote_addrfor client IP).zone: A name for your zone and its size (e.g.,my_limit:10m). The size determines how many unique keys Nginx can track.rate: The actual rate limit (e.g.,rate=1r/sfor 1 request per second).
Setting Up Your First Zone
Let's define a simple rate limiting zone that tracks requests by client IP address and allows 5 requests per second.
http {
# ... other http settings ...
limit_req_zone $binary_remote_addr zone=my_ip_limit:10m rate=5r/s;
server {
# ...
}
}Attaching Limits to Locations
After defining a limit_req_zone, you need to apply it to specific parts of your website or API using the limit_req directive.
This directive is placed inside a server or location block. It simply references the zone you created earlier.
For example, to apply the my_ip_limit zone to a specific location:
limit_req zone=my_ip_limit;When a client exceeds the defined rate, Nginx will return a 503 Service Unavailable error by default.
A Complete Basic Rate Limit
Here's how you can combine both directives to limit requests to your /api/ endpoint to 2 requests per second per unique IP address.
http {
limit_req_zone $binary_remote_addr zone=api_requests:10m rate=2r/s;
server {
listen 80;
server_name example.com;
location /api/ {
limit_req zone=api_requests;
proxy_pass http://backend_service;
}
}
}Allowing Temporary Spikes
Strict rate limits can sometimes be too restrictive for legitimate users. The burst parameter allows a client to make requests exceeding the defined rate temporarily.
burst=N: Allows requests up to N more than the rate limit. These requests are queued and processed at the rate limit.nodelay: When used withburst, Nginx processes burst requests immediately if possible. If the queue is full, subsequent requests are dropped (503error) instead of being delayed.
Without nodelay, requests exceeding the rate will be delayed to conform to the rate.
Rate Limiting with Burst Tolerance
Let's update our previous example to allow a burst of up to 5 additional requests, processing them immediately if resources permit.
http {
limit_req_zone $binary_remote_addr zone=api_requests:10m rate=2r/s;
server {
listen 80;
server_name example.com;
location /api/ {
limit_req zone=api_requests burst=5 nodelay;
proxy_pass http://backend_service;
}
}
}Rate Limiting vs. Throttling
While often used interchangeably, there's a subtle difference:
- Rate Limiting: Enforces a hard limit on the number of requests over a period (e.g., 100 requests per minute). Nginx's
limit_reqprimarily implements rate limiting. - Throttling: Is a more dynamic process that might slow down requests rather than outright rejecting them. It often considers server load or resource availability. While Nginx can delay requests with
burst(ifnodelayis absent), it's more focused on strict limits.
For most API protection needs, Nginx's rate limiting capabilities are robust and highly effective.
Quick Check
You've learned about the core Nginx directives for rate limiting. Now, let's test your knowledge!
Summary: Protecting Your APIs
In this lesson, you've learned how to implement rate limiting with Nginx to protect your backend services and ensure fair usage.
- We defined a rate limiting zone using
limit_req_zone. - We applied these limits to specific locations using
limit_req. - We explored the
burstandnodelayoptions to handle temporary traffic spikes more gracefully.
Rate limiting is a fundamental security and performance pattern, especially when dealing with public APIs or high-traffic web applications.
Belajar API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) dengan tutor AI — gratis
Tulis dan jalankan kode asli di browser kamu, dapatkan bantuan instan dari tutor AI 24/7, dan lanjutkan di mana kamu tinggalkan di web atau aplikasi.
- Kursus
- 12
- Pelajaran
- 48
Pertanyaan yang Sering Diajukan
Apakah pelajaran “Pembatasan Laju dan Pengendalian Arus dengan Nginx” gratis?
Ya — teks lengkap “Pembatasan Laju dan Pengendalian Arus dengan Nginx” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway), upgrade ke CoddyKit PRO. Kursus API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) mencakup 4 pelajaran total.
Apa yang akan aku pelajari di “Pembatasan Laju dan Pengendalian Arus dengan Nginx”?
Siapkan pembatasan laju untuk melindungi layanan backend dari penyalahgunaan dan memastikan penggunaan sumber daya yang adil. Kamu berlatih API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.
Apakah aku perlu pengalaman untuk memulai API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)?
Tidak diperlukan pengalaman sebelumnya. API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 3 dari 4.
Berapa lama pelajaran “Pembatasan Laju dan Pengendalian Arus dengan Nginx” memakan waktu?
Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.
Bisakah aku menulis dan menjalankan kode dalam pelajaran API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) ini?
Ya. Setiap pelajaran API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.
Semua pelajaran dalam kursus ini
- Pembuatan Versi API dengan Nginx
- Berbagi Sumber Daya Lintas Asal (CORS)
- Pembatasan Laju dan Pengendalian Arus dengan Nginx
- Perutean Berbasis Jalur ke Layanan Mikro