Rate-limit the addresses in a list
Create a network list and a firewall rule that holds each client in it to a request rate, in Azion Console, the Azion CLI, or the API.
You can hold the clients in a network list to a request rate from Azion Console, the Azion CLI, or the API. The rule sets no limit on any client outside the list. One firewall rule pairs the Network criterion, which reads the list, with the Set Rate Limit behavior. Use it when a set of addresses may keep using your application, but only at a pace the application can serve. To refuse those addresses instead of slowing them, refer to Block requests by IP, ASN, or country.
Select the interface for this guide. Its prerequisites and every task on this page switch to that interface.
Prerequisites
- A workload bound to a firewall. The rate-limit rule goes on that firewall.
- Network Shield on for that firewall, because the Network criterion comes from it. It starts on in every firewall and stays on until someone turns it off.
- An account that can sign in to Azion Console.
Create the list of addresses to limit
The addresses to limit go in a list of the ip_cidr type, shown as IP/CIDR in Azion Console. Its items are addresses and ranges, such as 203.0.113.0/24 and 198.51.100.7. The rule stores the ID of the list rather than its items. An address you add to the list or remove from it therefore changes which clients are limited, and the rule needs no edit. For every field and type a list accepts, refer to Network list fields and List types.
To create the list with the Azion CLI, write it to a file named network-list.json:
Create the list from that file:
The output carries the ID of the list:
Keep that ID, because the rule refers to Rate-limited addresses by it.
Create the rule that rate-limits the list
The rule joins the Network criterion, with its matches operator, to the Set Rate Limit behavior. Only a client in the list makes that criterion true, so only those clients are limited. A request from any other client leaves the criterion false: the rule runs nothing, and the firewall goes on to its next rule. The behavior in this guide allows each client IP address an average of 10 requests per second, with a burst of 10. Set Rate Limit is a behavior of Firewall itself, and Network Shield adds only the criterion. For what each field of the behavior counts, refer to Set Rate Limit.
azion create firewall-rule takes the rule only as a JSON file, through --file, next to --firewall-id. To create it with the Azion CLI, write it to a file named rule.json. Put the ID of your list in place of <network-list-id>, as a number with no quotes:
Create the rule from that file on the firewall bound to your workload. Put the ID of that firewall in place of <firewall-id>:
The output carries the ID of the rule:
The rule is active on the firewall, and it limits the clients in Rate-limited addresses once it reaches traffic.
Confirm that the rate limit applies to listed clients
A rule you add can take from 6 minutes 29 seconds to 9 minutes 18 seconds to reach traffic across Azion’s distributed infrastructure. Until it does, the rule limits no client. Send the requests again until they answer as expected.
Set Rate Limit does not refuse a request over the rate at once. For example, take a rule with a rate of one request per second and a burst of 1. Requests that match it one after another are each held about one second, then served. Only concurrent requests beyond the burst receive 429. A check that sends one request at a time can therefore get no 429 at all. For how the burst queues requests, refer to Rate limits.
A refused request from a listed client receives HTTP 429 and Azion’s default error page, headed Too Many Requests. No rate-limit header comes back, so the client gets no signal of when to retry. The response looks like this:
The rule limits whichever clients the list holds when a request arrives. A change to the items of the list reaches traffic in 46 seconds to about 100 seconds, sooner than a rule you add. Until it settles, answers can switch between the old items and the updated ones. Repeat a request until the answers agree.