速率限制与访问控制
约 727 字大约 2 分钟
布欧-Lewyon
2026-05-15
首页 › Nginx › 高级配置(在新窗口打开) › 速率限制与访问控制
请求速率限制(limit_req)
限制客户端的请求频率,防止滥用和 DDoS。
http {
# 定义限制区域
# $binary_remote_addr:按客户端 IP 限制
# rate=10r/s:每秒最多 10 个请求
limit_req_zone $binary_remote_addr zone=api_limit:10m rate=10r/s;
server {
location /api/ {
limit_req zone=api_limit;
limit_req_status 429;
proxy_pass http://backend:3000;
}
}
}burst 和 nodelay
# burst:允许瞬时超过限额的请求排队
# nodelay:排队的请求也不等待,立刻处理(但会消耗 burst 配额)
limit_req zone=api_limit burst=20 nodelay;| 配置 | 行为 |
|---|---|
rate=10r/s | 每秒平均 10 个请求 |
burst=20 | 瞬时最多允许 20 个额外请求排队 |
| 无 nodelay | 超过 10r/s 的请求排队,以 10r/s 的速率处理 |
nodelay | 突发请求立刻处理(消耗 burst 配额),超出的返回 429 |
# 多个限制区域组合
limit_req_zone $binary_remote_addr zone=per_ip:10m rate=5r/s;
limit_req_zone $server_name zone=per_domain:10m rate=100r/s;
location /api/ {
limit_req zone=per_ip burst=10 nodelay;
limit_req zone=per_domain burst=200 nodelay;
limit_req_status 429;
proxy_pass http://backend:3000;
}并发连接限制(limit_conn)
限制同一客户端的并发连接数:
http {
limit_conn_zone $binary_remote_addr zone=conn_limit:10m;
server {
location /downloads/ {
limit_conn conn_limit 5; # 同一 IP 最多 5 个并发连接
limit_conn_status 503;
}
}
}IP 访问控制
location /admin/ {
# 允许特定网段
allow 192.168.1.0/24;
allow 10.0.0.0/8;
allow 203.0.113.5; # 特定 IP
# 拒绝其他所有
deny all;
proxy_pass http://admin-backend:3000;
}
# 拒绝爬虫
location / {
deny 1.2.3.4; # 阻止特定 IP
satisfy any; # IP 或 Basic Auth 任一通过即可
allow 192.168.1.0/24;
deny all;
auth_basic "Restricted";
auth_basic_user_file /etc/nginx/.htpasswd;
}基本认证(Basic Auth)
# 创建密码文件
sudo apt install apache2-utils
htpasswd -c /etc/nginx/.htpasswd admin
# 输入密码
# 添加更多用户
htpasswd /etc/nginx/.htpasswd user2location /admin/ {
auth_basic "Admin Area";
auth_basic_user_file /etc/nginx/.htpasswd;
proxy_pass http://admin-backend:3000;
}防盗链
location ~* \.(jpg|png|gif|webp)$ {
# 允许的来源
valid_referers none blocked server_names
~\.google\.com
~\.example\.com;
# 拒绝盗链
if ($invalid_referer) {
return 403;
}
root /var/www/images;
}请求体大小限制
# 全局限制
http {
client_max_body_size 10m;
}
# 特定 location 限制(上传接口)
location /upload/ {
client_max_body_size 100m;
proxy_pass http://upload-backend;
}
# 取消限制
location /stream/ {
client_max_body_size 0; # 不限制
proxy_request_buffering off;
}综合速率限制配置
http {
# IP 速率限制
limit_req_zone $binary_remote_addr zone=api:10m rate=10r/s;
limit_req_zone $binary_remote_addr zone=login:10m rate=2r/m;
# 并发连接限制
limit_conn_zone $binary_remote_addr zone=conn:10m;
server {
listen 80;
server_name app.example.com;
# 全局限流
location /api/ {
limit_req zone=api burst=20 nodelay;
limit_req_status 429;
proxy_pass http://backend:3000;
}
# 登录接口更严格(防暴力破解)
location /api/login {
limit_req zone=login burst=5;
limit_req_status 429;
proxy_pass http://backend:3000;
}
# 大文件下载限制并发
location /downloads/ {
limit_conn conn 3;
limit_conn_status 503;
alias /var/data/files;
}
# 后台管理 IP 白名单
location /admin/ {
allow 10.0.0.0/8;
deny all;
auth_basic "Admin";
auth_basic_user_file /etc/nginx/.htpasswd;
proxy_pass http://admin-backend;
}
}
}小结
limit_req_zone+limit_req按速率限流(r/s),burst允许突发,nodelay快速消费突发。limit_conn_zone+limit_conn限制并发连接数。allow/deny基于 IP 的访问控制,auth_basic用户名密码认证。valid_referers实现防盗链。client_max_body_size限制请求体大小,上传接口需要调大。
上一节:CORS 跨域 下一节:upstream 与负载均衡算法
