You are browsing documentation for an outdated plugin version.
Configuration
This plugin is partially compatible with DB-less mode.
The plugin will run fine with the local
policy (which doesn’t use the database) or
the redis
policy (which uses an independent Redis, so it is compatible with DB-less).
The plugin will not work with the cluster
policy, which requires writes to the database.
Compatible protocols
The Rate Limiting plugin is compatible with the following protocols:
grpc
, grpcs
, http
, https
Parameters
Here's a list of all the parameters which can be used in this plugin's configuration:
-
name or plugin
string requiredThe name of the plugin, in this case
rate-limiting
.- If using the Kong Admin API, Konnect API, declarative configuration, or decK files, the field is
name
. - If using the KongPlugin object in Kubernetes, the field is
plugin
.
- If using the Kong Admin API, Konnect API, declarative configuration, or decK files, the field is
-
service.name or service.id
stringThe name or ID of the service the plugin targets. Set one of these parameters if adding the plugin to a service through the top-level
/plugins
endpoint. Not required if using/services/{serviceName|Id}/plugins
. -
route.name or route.id
stringThe name or ID of the route the plugin targets. Set one of these parameters if adding the plugin to a route through the top-level
/plugins
endpoint. Not required if using/routes/{routeName|Id}/plugins
. -
consumer.name or consumer.id
stringThe name or ID of the consumer the plugin targets. Set one of these parameters if adding the plugin to a consumer through the top-level
/plugins
endpoint. Not required if using/consumers/{consumerName|Id}/plugins
. -
enabled
boolean default:true
Whether this plugin will be applied.
-
config
record required-
second
numberThe number of HTTP requests that can be made per second.
-
minute
numberThe number of HTTP requests that can be made per minute.
-
hour
numberThe number of HTTP requests that can be made per hour.
-
day
numberThe number of HTTP requests that can be made per day.
-
month
numberThe number of HTTP requests that can be made per month.
-
year
numberThe number of HTTP requests that can be made per year.
-
limit_by
string default:consumer
Must be one of:consumer
,credential
,ip
,service
,header
,path
The entity that is used when aggregating the limits. Available values are:
consumer
credential
ip
service
-
header
(Theheader_name
configuration must be provided.) -
path
(Thepath
configuration must be provided.)
If the entity value for aggregating the limits cannot be determined, the system falls back to
ip
.
-
header_name
stringHeader name to be used if
limit_by
is set toheader
.
-
path
string starts_with:/
Path to be used if
limit_by
is set topath
.
-
policy
string default:local
len_min:0
Must be one of:local
,cluster
,redis
The rate-limiting policies to use for retrieving and incrementing the limits. Available values are:
-
local
: Counters are stored locally in-memory on the node. -
cluster
: Counters are stored in the Kong data store and shared across the nodes. -
redis
: Counters are stored on a Redis server and shared across the nodes.
In DB-less, hybrid mode, and Konnect, the
cluster
config policy is not supported. For DB-less mode or Konnect, use one ofredis
orlocal
; for hybrid mode, useredis
, orlocal
for data planes only.For details on which policy should be used, refer to the implementation considerations.
-
-
fault_tolerant
boolean required default:true
A boolean value that determines if the requests should be proxied even if Kong has troubles connecting a third-party data store. If
true
, requests will be proxied anyway, effectively disabling the rate-limiting function until the data store is working again. Iffalse
, then the clients will see500
errors.
-
redis_host
stringWhen using the
redis
policy, this property specifies the address to the Redis server.
-
redis_port
integer default:6379
between:0
65535
When using the
redis
policy, this property specifies the port of the Redis server. By default is6379
.
-
redis_password
string referenceable len_min:0
When using the
redis
policy, this property specifies the password to connect to the Redis server.
-
redis_username
string referenceableWhen using the
redis
policy, this property specifies the username to connect to the Redis server when ACL authentication is desired.This requires Redis v6.0.0+. The username cannot be set to
default
.
-
redis_ssl
boolean required default:false
When using the
redis
policy, this property specifies if SSL is used to connect to the Redis server.
-
redis_ssl_verify
boolean required default:false
When using the
redis
policy withredis_ssl
set totrue
, this property specifies it server SSL certificate is validated. Note that you need to configure the lua_ssl_trusted_certificate to specify the CA (or server) certificate used by your Redis server. You may also need to configure lua_ssl_verify_depth accordingly.
-
redis_server_name
stringWhen using the
redis
policy withredis_ssl
set totrue
, this property specifies the server name for the TLS extension Server Name Indication (SNI)
-
redis_timeout
number default:2000
When using the
redis
policy, this property specifies the timeout in milliseconds of any command submitted to the Redis server.
-
redis_database
integer default:0
When using the
redis
policy, this property specifies the Redis database to use.
-
hide_client_headers
boolean required default:false
Optionally hide informative response headers.
-
error_code
number default:429
Set a custom error code to return when the rate limit is exceeded.
-
error_message
string default:API rate limit exceeded
Set a custom error message to return when the rate limit is exceeded.
-