常用的网关方案
- Nginx+Lua
- Kong
- Tyk Go语言开发的
- Spring Cloud Zuul
Zuul的特点
- 路由+过滤器=Zuul
- 核心是一系列的过滤器
Zuul的四种过滤器API
- 前置(Pre)
- 后置(Post)
- 路由(Route)
- 错误(Error)
使用Zuul实现网关
1.添加依赖
<dependency>
<groupId>org.springframework.cloud</groupId>
<artifactId>spring-cloud-starter-netflix-zuul</artifactId>
</dependency>
2.添加启动@EnableZuulProxy
@SpringBootApplication
@EnableZuulProxy
public class ApiGatewayApplication {
public static void main(String[] args) {
SpringApplication.run(ApiGatewayApplication.class, args);
}
}
3.测试
- 原来
http://127.0.0.1:8082/product/list
- 代理后,第一个product是服务的名字
http://127.0.0.1:9000/product/product/list
4.自定义路由
- 配置文件
zuul:
routes:
myProduct:
path: /myProduct/**
serviceId: product
- 简洁写法
zuul:
routes:
product: /myProduct/**
排除某些路由
zuul:
routes:
myProduct:
product: /myProduct/**
# 排除某些路由
ignored-patterns:
- /**/product/listForOrder
Zuul默认不传Cookie信息,需要传是需要配sensitiveHeaders未空才会传
zuul:
routes:
myProduct:
path: /myProduct/**
serviceId: product
sensitiveHeaders:
动态刷新配置
@Component
public class ZuulConfig {
@ConfigurationProperties("zuul")
@RefreshScope
public ZuulProperties zuulProperties(){
return new ZuulProperties();
}
}
二、Zuul自定义过滤器
- 进入时过滤,如权限token读取
package com.matea.filter;
import com.netflix.zuul.ZuulFilter;
import com.netflix.zuul.context.RequestContext;
import com.netflix.zuul.exception.ZuulException;
import org.apache.commons.lang.StringUtils;
import org.apache.http.HttpStatus;
import org.springframework.stereotype.Component;
import javax.servlet.http.HttpServletRequest;
import static org.springframework.cloud.netflix.zuul.filters.support.FilterConstants.*;
@Component
public class TokenFilter extends ZuulFilter{
@Override
public String filterType() {
return PRE_TYPE;
}
@Override
public int filterOrder() {
return PRE_DECORATION_FILTER_ORDER -1;
}
@Override
public boolean shouldFilter() {
return true;
}
@Override
public Object run() throws ZuulException {
RequestContext requestContext = RequestContext.getCurrentContext();
HttpServletRequest request = requestContext.getRequest();
//这里从url参数里获取,也可以从cookie,header里获取
String token = request.getParameter("token");
if(StringUtils.isEmpty(token)){
requestContext.setSendZuulResponse(false);
requestContext.setResponseStatusCode(HttpStatus.SC_UNAUTHORIZED);
}
return null;
}
}
- 返回时调用,如返回添加头信息
package com.matea.filter;
import com.netflix.zuul.ZuulFilter;
import com.netflix.zuul.context.RequestContext;
import com.netflix.zuul.exception.ZuulException;
import org.springframework.stereotype.Component;
import javax.servlet.http.HttpServletResponse;
import java.util.UUID;
import static org.springframework.cloud.netflix.zuul.filters.support.FilterConstants.PRE_TYPE;
import static org.springframework.cloud.netflix.zuul.filters.support.FilterConstants.SEND_RESPONSE_FILTER_ORDER;
@Component
public class addResponseHeaderFilter extends ZuulFilter {
@Override
public String filterType() {
return PRE_TYPE;
}
@Override
public int filterOrder() {
return SEND_RESPONSE_FILTER_ORDER-1;
}
@Override
public boolean shouldFilter() {
return true;
}
@Override
public Object run() throws ZuulException {
RequestContext requestContext = RequestContext.getCurrentContext();
HttpServletResponse response = requestContext.getResponse();
response.setHeader("X-Foo", UUID.randomUUID().toString());
return null;
}
}
三、Zuul限流
- 缓存,限流和降级是系统的三把利剑,用谷歌RateLimiter 实现令牌桶限流
- 令牌桶算法的原理是:系统以恒定的速率往桶里丢一定数量的令牌,请求只有拿到了令牌才能处理。当桶里没有令牌时便可拒绝服务。
package com.matea.filter;
import com.google.common.util.concurrent.RateLimiter;
import com.matea.exception.RateLimitException;
import com.netflix.zuul.ZuulFilter;
import com.netflix.zuul.exception.ZuulException;
import static org.springframework.cloud.netflix.zuul.filters.support.FilterConstants.PRE_TYPE;
import static org.springframework.cloud.netflix.zuul.filters.support.FilterConstants.SERVLET_DETECTION_FILTER_ORDER;
public class RateLimitFilter extends ZuulFilter {
private static final RateLimiter RATE_LIMITER =RateLimiter.create(100);
@Override
public String filterType() {
return PRE_TYPE;
}
@Override
public int filterOrder() {
return SERVLET_DETECTION_FILTER_ORDER-1;
}
@Override
public boolean shouldFilter() {
return true;
}
@Override
public Object run() throws ZuulException {
if(!RATE_LIMITER.tryAcquire()){
throw new RateLimitException();
}
return null;
}
}
四、Zuul权限校验
- 网关全部服务忽略敏感头
zuul:
# 全部服务忽略敏感头(全部服务都可以传递 Cookie)
sensitive-headers:
五、Zuul跨域
跨域问题处理方案
- 1.在被调用的类方法上增加@CrossOrigin注解
单个接口上添加
@GetMapping("/list")
@CrossOrigin(allowCredentials = "true")
public ResultVO<ProductVO> list() {}
@CrossOrigin(allowCredentials = "true")
allowCredentials = "true" 表示允许cookie跨域
- 2.在Zuul里面增加CrosFilter过滤器
package com.matea.config;
import org.apache.catalina.filters.CorsFilter;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.web.cors.CorsConfiguration;
import org.springframework.web.cors.UrlBasedCorsConfigurationSource;
import java.util.Arrays;
/**
* 跨域配置
*/
@Configuration
public class CorsConfig {
@Bean
public CorsFilter corsFilter(){
final UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
final CorsConfiguration config = new CorsConfiguration();
config.setAllowCredentials(true);
config.setAllowedOrigins(Arrays.asList("*"));//默认 http:www.a.com
config.setAllowedHeaders(Arrays.asList("*"));
config.setAllowedMethods(Arrays.asList("*"));
config.setMaxAge(300l);//换成时间
source.registerCorsConfiguration("/**",config);
return new CorsFilter()
}
}