API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) · レッスン

Nginxによるレート制限とスロットリング

レート制限を設定し、バックエンドサービスを悪用から守るとともに、リソースを公平に利用できるようにします。

レッスン 3/411 ステップ

「Nginxによるレート制限とスロットリング」はCoddyKit上の無料API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)レッスンです。 これはレッスン3/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはAPI Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)コースには全4レッスンが含まれています。

このレッスンの一部はまだ翻訳されておらず、英語で表示されています。

Why Rate Limiting Matters

Imagine a popular website or API. What happens if one user or a malicious bot sends thousands of requests per second?

This is where rate limiting comes in! It's a crucial technique to control the number of requests a client can make to your server within a specific timeframe.

  • Prevents abuse and DDoS attacks.
  • Ensures fair resource usage for all clients.
  • Protects your backend services from overload.

Nginx's Key Directives

Nginx provides powerful directives to implement rate limiting. We'll focus on two main ones:

  • limit_req_zone: Defines the parameters for a rate limiting zone. Think of it as setting up the rules for a specific type of traffic.
  • limit_req: Applies the defined rate limiting rules to requests within a specific location or server block. This is where the magic happens!

Defining Your Rate Limit Zone

The limit_req_zone directive is typically placed in the http block of your Nginx configuration. It defines a shared memory zone where Nginx keeps track of request states.

Here's its structure and what each part means:

  • key: What Nginx tracks (e.g., $binary_remote_addr for client IP).
  • zone: A name for your zone and its size (e.g., my_limit:10m). The size determines how many unique keys Nginx can track.
  • rate: The actual rate limit (e.g., rate=1r/s for 1 request per second).

Setting Up Your First Zone

Let's define a simple rate limiting zone that tracks requests by client IP address and allows 5 requests per second.

http {
    # ... other http settings ...

    limit_req_zone $binary_remote_addr zone=my_ip_limit:10m rate=5r/s;

    server {
        # ...
    }
}

Attaching Limits to Locations

After defining a limit_req_zone, you need to apply it to specific parts of your website or API using the limit_req directive.

This directive is placed inside a server or location block. It simply references the zone you created earlier.

For example, to apply the my_ip_limit zone to a specific location:

limit_req zone=my_ip_limit;

When a client exceeds the defined rate, Nginx will return a 503 Service Unavailable error by default.

A Complete Basic Rate Limit

Here's how you can combine both directives to limit requests to your /api/ endpoint to 2 requests per second per unique IP address.

http {
    limit_req_zone $binary_remote_addr zone=api_requests:10m rate=2r/s;

    server {
        listen 80;
        server_name example.com;

        location /api/ {
            limit_req zone=api_requests;
            proxy_pass http://backend_service;
        }
    }
}

Allowing Temporary Spikes

Strict rate limits can sometimes be too restrictive for legitimate users. The burst parameter allows a client to make requests exceeding the defined rate temporarily.

  • burst=N: Allows requests up to N more than the rate limit. These requests are queued and processed at the rate limit.
  • nodelay: When used with burst, Nginx processes burst requests immediately if possible. If the queue is full, subsequent requests are dropped (503 error) instead of being delayed.

Without nodelay, requests exceeding the rate will be delayed to conform to the rate.

Rate Limiting with Burst Tolerance

Let's update our previous example to allow a burst of up to 5 additional requests, processing them immediately if resources permit.

http {
    limit_req_zone $binary_remote_addr zone=api_requests:10m rate=2r/s;

    server {
        listen 80;
        server_name example.com;

        location /api/ {
            limit_req zone=api_requests burst=5 nodelay;
            proxy_pass http://backend_service;
        }
    }
}

Rate Limiting vs. Throttling

While often used interchangeably, there's a subtle difference:

  • Rate Limiting: Enforces a hard limit on the number of requests over a period (e.g., 100 requests per minute). Nginx's limit_req primarily implements rate limiting.
  • Throttling: Is a more dynamic process that might slow down requests rather than outright rejecting them. It often considers server load or resource availability. While Nginx can delay requests with burst (if nodelay is absent), it's more focused on strict limits.

For most API protection needs, Nginx's rate limiting capabilities are robust and highly effective.

Quick Check

You've learned about the core Nginx directives for rate limiting. Now, let's test your knowledge!

Summary: Protecting Your APIs

In this lesson, you've learned how to implement rate limiting with Nginx to protect your backend services and ensure fair usage.

  • We defined a rate limiting zone using limit_req_zone.
  • We applied these limits to specific locations using limit_req.
  • We explored the burst and nodelay options to handle temporary traffic spikes more gracefully.

Rate limiting is a fundamental security and performance pattern, especially when dealing with public APIs or high-traffic web applications.

無料で開始

AI チューターと学ぶ API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) — 無料

ブラウザでリアルコードを書いて実行し、24/7 の AI チューターから瞬時にサポートを受け、ウェブまたはアプリで続きから学習できます。

コース
12
レッスン
48

よくある質問

「Nginxによるレート制限とスロットリング」レッスンは無料ですか?

はい。「Nginxによるレート制限とスロットリング」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)コースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)コースには全4レッスンが含まれています。

「Nginxによるレート制限とスロットリング」で何を学びますか?

レート制限を設定し、バックエンドサービスを悪用から守るとともに、リソースを公平に利用できるようにします。 ブラウザで直接実行するハンズオンコードでAPI Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)を演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。

API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)を始めるのに経験は必要ですか?

事前経験は必要ありません。CoddyKitのAPI Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)は初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン3/4です。

「Nginxによるレート制限とスロットリング」レッスンにはどのくらい時間がかかりますか?

ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。

このAPI Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)レッスンでコードを書いて実行できますか?

はい。すべてのAPI Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)レッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。

このコースのすべてのレッスン

  1. NginxによるAPIバージョニング
  2. Cross-Origin Resource Sharing(CORS)
  3. Nginxによるレート制限とスロットリング
  4. パスベースのマイクロサービスルーティング
← API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)に戻る