From 727bece101b095e4cdf4d7088f3d2aa3956e7cbb Mon Sep 17 00:00:00 2001 From: buildmaster Date: Wed, 24 Jul 2019 21:27:02 +0000 Subject: [PATCH] Sync docs from 2.1.x to gh-pages --- .../multi/multi__gatewayfilter_factories.html | 51 ++++++++++-------- 2.1.x/multi/multi_spring-cloud-gateway.html | 2 +- 2.1.x/single/spring-cloud-gateway.html | 53 +++++++++++-------- 2.1.x/spring-cloud-gateway.xml | 18 +++++++ 4 files changed, 80 insertions(+), 44 deletions(-) diff --git a/2.1.x/multi/multi__gatewayfilter_factories.html b/2.1.x/multi/multi__gatewayfilter_factories.html index 3e7870d3..97b822ba 100644 --- a/2.1.x/multi/multi__gatewayfilter_factories.html +++ b/2.1.x/multi/multi__gatewayfilter_factories.html @@ -146,7 +146,16 @@ a fallbackUri in an external application, like in t

In this example, after an execution exception occurs while running the HystrixCommand, the request will be forwarde to the fallback endpoint or handler in an app running on localhost:9994. The headers with the exception type, message and -if available- root cause exception type and message will be added to that request by the FallbackHeaders filter.

The names of the headers can be overwritten in the config by setting the values of the arguments listed below, along with -their default values:

You can find more information on how Hystrix works with Gateway in the Hystrix GatewayFilter Factory section.

5.7 PrefixPath GatewayFilter Factory

The PrefixPath GatewayFilter Factory takes a single prefix parameter.

application.yml.  +their default values:

  • executionExceptionTypeHeaderName ("Execution-Exception-Type")
  • executionExceptionMessageHeaderName ("Execution-Exception-Message")
  • rootCauseExceptionTypeHeaderName ("Root-Cause-Exception-Type")
  • rootCauseExceptionMessageHeaderName ("Root-Cause-Exception-Message")

You can find more information on how Hystrix works with Gateway in the Hystrix GatewayFilter Factory section.

5.7 MapRequestHeader GatewayFilter Factory

The MapRequestHeader GatewayFilter Factory takes 'fromHeader' and 'toHeader' parameters. It creates a new named header (toHeader) and the value is extracted out of an existing named header (fromHeader) from the incoming http request. If the input header does not exist then the filter has no impact. If the new named header already exists then it’s values will be augmented with the new values.

application.yml.  +

spring:
+  cloud:
+    gateway:
+      routes:
+      - id: map_request_header_route
+        uri: https://example.org
+        filters:
+        - MapRequestHeader=Bar, X-Request-Foo

+

This will add X-Request-Foo:<values> header to the downstream request’s with updated values from the incoming http request Bar header.

5.8 PrefixPath GatewayFilter Factory

The PrefixPath GatewayFilter Factory takes a single prefix parameter.

application.yml. 

spring:
   cloud:
     gateway:
@@ -155,7 +164,7 @@ their default values:

    uri: https://example.org filters: - PrefixPath=/mypath

-

This will prefix /mypath to the path of all matching requests. So a request to /hello, would be sent to /mypath/hello.

5.8 PreserveHostHeader GatewayFilter Factory

The PreserveHostHeader GatewayFilter Factory has not parameters. This filter, sets a request attribute that the routing filter will inspect to determine if the original host header should be sent, rather than the host header determined by the http client.

application.yml.  +

This will prefix /mypath to the path of all matching requests. So a request to /hello, would be sent to /mypath/hello.

5.9 PreserveHostHeader GatewayFilter Factory

The PreserveHostHeader GatewayFilter Factory has not parameters. This filter, sets a request attribute that the routing filter will inspect to determine if the original host header should be sent, rather than the host header determined by the http client.

application.yml. 

spring:
   cloud:
     gateway:
@@ -164,14 +173,14 @@ their default values:

    uri: https://example.org filters: - PreserveHostHeader

-

5.9 RequestRateLimiter GatewayFilter Factory

The RequestRateLimiter GatewayFilter Factory is uses a RateLimiter implementation to determine if the current request is allowed to proceed. If it is not, a status of HTTP 429 - Too Many Requests (by default) is returned.

This filter takes an optional keyResolver parameter and parameters specific to the rate limiter (see below).

keyResolver is a bean that implements the KeyResolver interface. In configuration, reference the bean by name using SpEL. #{@myKeyResolver} is a SpEL expression referencing a bean with the name myKeyResolver.

KeyResolver.java.  +

5.10 RequestRateLimiter GatewayFilter Factory

The RequestRateLimiter GatewayFilter Factory is uses a RateLimiter implementation to determine if the current request is allowed to proceed. If it is not, a status of HTTP 429 - Too Many Requests (by default) is returned.

This filter takes an optional keyResolver parameter and parameters specific to the rate limiter (see below).

keyResolver is a bean that implements the KeyResolver interface. In configuration, reference the bean by name using SpEL. #{@myKeyResolver} is a SpEL expression referencing a bean with the name myKeyResolver.

KeyResolver.java. 

public interface KeyResolver {
 	Mono<String> resolve(ServerWebExchange exchange);
 }

The KeyResolver interface allows pluggable strategies to derive the key for limiting requests. In future milestones, there will be some KeyResolver implementations.

The default implementation of KeyResolver is the PrincipalNameKeyResolver which retrieves the Principal from the ServerWebExchange and calls Principal.getName().

By default, if the KeyResolver does not find a key, requests will be denied. This behavior can be adjust with the spring.cloud.gateway.filter.request-rate-limiter.deny-empty-key (true or false) and spring.cloud.gateway.filter.request-rate-limiter.empty-key-status-code properties.

[Note]Note

The RequestRateLimiter is not configurable via the "shortcut" notation. The example below is invalid

application.properties. 

# INVALID SHORTCUT CONFIGURATION
 spring.cloud.gateway.routes[0].filters[0]=RequestRateLimiter=2, 2, #{@userkeyresolver}

-

5.9.1 Redis RateLimiter

The redis implementation is based off of work done at Stripe. It requires the use of the spring-boot-starter-data-redis-reactive Spring Boot starter.

The algorithm used is the Token Bucket Algorithm.

The redis-rate-limiter.replenishRate is how many requests per second do you want a user to be allowed to do, without any dropped requests. This is the rate that the token bucket is filled.

The redis-rate-limiter.burstCapacity is the maximum number of requests a user is allowed to do in a single second. This is the number of tokens the token bucket can hold. Setting this value to zero will block all requests.

A steady rate is accomplished by setting the same value in replenishRate and burstCapacity. Temporary bursts can be allowed by setting burstCapacity higher than replenishRate. In this case, the rate limiter needs to be allowed some time between bursts (according to replenishRate), as 2 consecutive bursts will result in dropped requests (HTTP 429 - Too Many Requests).

application.yml.  +

5.10.1 Redis RateLimiter

The redis implementation is based off of work done at Stripe. It requires the use of the spring-boot-starter-data-redis-reactive Spring Boot starter.

The algorithm used is the Token Bucket Algorithm.

The redis-rate-limiter.replenishRate is how many requests per second do you want a user to be allowed to do, without any dropped requests. This is the rate that the token bucket is filled.

The redis-rate-limiter.burstCapacity is the maximum number of requests a user is allowed to do in a single second. This is the number of tokens the token bucket can hold. Setting this value to zero will block all requests.

A steady rate is accomplished by setting the same value in replenishRate and burstCapacity. Temporary bursts can be allowed by setting burstCapacity higher than replenishRate. In this case, the rate limiter needs to be allowed some time between bursts (according to replenishRate), as 2 consecutive bursts will result in dropped requests (HTTP 429 - Too Many Requests).

application.yml. 

spring:
   cloud:
     gateway:
@@ -200,7 +209,7 @@ KeyResolver userKeyResolver() {
           args:
             rate-limiter: "#{@myRateLimiter}"
             key-resolver: "#{@userKeyResolver}"

-

5.10 RedirectTo GatewayFilter Factory

The RedirectTo GatewayFilter Factory takes a status and a url parameter. The status should be a 300 series redirect http code, such as 301. The url should be a valid url. This will be the value of the Location header.

application.yml.  +

5.11 RedirectTo GatewayFilter Factory

The RedirectTo GatewayFilter Factory takes a status and a url parameter. The status should be a 300 series redirect http code, such as 301. The url should be a valid url. This will be the value of the Location header.

application.yml. 

spring:
   cloud:
     gateway:
@@ -209,7 +218,7 @@ KeyResolver userKeyResolver() {
         uri: https://example.org
         filters:
         - RedirectTo=302, https://acme.org

-

This will send a status 302 with a Location:https://acme.org header to perform a redirect.

5.11 RemoveHopByHopHeadersFilter GatewayFilter Factory

The RemoveHopByHopHeadersFilter GatewayFilter Factory removes headers from forwarded requests. The default list of headers that is removed comes from the IETF.

The default removed headers are:

  • Connection
  • Keep-Alive
  • Proxy-Authenticate
  • Proxy-Authorization
  • TE
  • Trailer
  • Transfer-Encoding
  • Upgrade

To change this, set the spring.cloud.gateway.filter.remove-non-proxy-headers.headers property to the list of header names to remove.

5.12 RemoveRequestHeader GatewayFilter Factory

The RemoveRequestHeader GatewayFilter Factory takes a name parameter. It is the name of the header to be removed.

application.yml.  +

This will send a status 302 with a Location:https://acme.org header to perform a redirect.

5.12 RemoveHopByHopHeadersFilter GatewayFilter Factory

The RemoveHopByHopHeadersFilter GatewayFilter Factory removes headers from forwarded requests. The default list of headers that is removed comes from the IETF.

The default removed headers are:

  • Connection
  • Keep-Alive
  • Proxy-Authenticate
  • Proxy-Authorization
  • TE
  • Trailer
  • Transfer-Encoding
  • Upgrade

To change this, set the spring.cloud.gateway.filter.remove-non-proxy-headers.headers property to the list of header names to remove.

5.13 RemoveRequestHeader GatewayFilter Factory

The RemoveRequestHeader GatewayFilter Factory takes a name parameter. It is the name of the header to be removed.

application.yml. 

spring:
   cloud:
     gateway:
@@ -218,7 +227,7 @@ KeyResolver userKeyResolver() {
         uri: https://example.org
         filters:
         - RemoveRequestHeader=X-Request-Foo

-

This will remove the X-Request-Foo header before it is sent downstream.

5.13 RemoveResponseHeader GatewayFilter Factory

The RemoveResponseHeader GatewayFilter Factory takes a name parameter. It is the name of the header to be removed.

application.yml.  +

This will remove the X-Request-Foo header before it is sent downstream.

5.14 RemoveResponseHeader GatewayFilter Factory

The RemoveResponseHeader GatewayFilter Factory takes a name parameter. It is the name of the header to be removed.

application.yml. 

spring:
   cloud:
     gateway:
@@ -229,7 +238,7 @@ KeyResolver userKeyResolver() {
         - RemoveResponseHeader=X-Response-Foo

This will remove the X-Response-Foo header from the response before it is returned to the gateway client.

To remove any kind of sensitive header you should configure this filter for any routes that you may want to do so. In addition you can configure this filter once using spring.cloud.gateway.default-filters -and have it applied to all routes.

5.14 RewritePath GatewayFilter Factory

The RewritePath GatewayFilter Factory takes a path regexp parameter and a replacement parameter. This uses Java regular expressions for a flexible way to rewrite the request path.

application.yml.  +and have it applied to all routes.

5.15 RewritePath GatewayFilter Factory

The RewritePath GatewayFilter Factory takes a path regexp parameter and a replacement parameter. This uses Java regular expressions for a flexible way to rewrite the request path.

application.yml. 

spring:
   cloud:
     gateway:
@@ -240,7 +249,7 @@ and have it applied to all routes.

- Path=/foo/** filters: - RewritePath=/foo/(?<segment>.*), /$\{segment}

-

For a request path of /foo/bar, this will set the path to /bar before making the downstream request. Notice the $\ which is replaced with $ because of the YAML spec.

5.15 RewriteLocationResponseHeader GatewayFilter Factory

The RewriteLocationResponseHeader GatewayFilter Factory modifies the value of Location response header, usually to get rid of backend specific details. It takes stripVersionMode, locationHeaderName, hostValue, and protocolsRegex parameters.

application.yml.  +

For a request path of /foo/bar, this will set the path to /bar before making the downstream request. Notice the $\ which is replaced with $ because of the YAML spec.

5.16 RewriteLocationResponseHeader GatewayFilter Factory

The RewriteLocationResponseHeader GatewayFilter Factory modifies the value of Location response header, usually to get rid of backend specific details. It takes stripVersionMode, locationHeaderName, hostValue, and protocolsRegex parameters.

application.yml. 

spring:
   cloud:
     gateway:
@@ -249,7 +258,7 @@ and have it applied to all routes.

uri: http://example.org filters: - RewriteLocationResponseHeader=AS_IN_REQUEST, Location, ,

-

For example, for a request POST https://api.example.com/some/object/name, Location response header value https://object-service.prod.example.net/v2/some/object/id will be rewritten as https://api.example.com/some/object/id.

Parameter stripVersionMode has the following possible values: NEVER_STRIP, AS_IN_REQUEST (default), ALWAYS_STRIP.

  • NEVER_STRIP - Version will not be stripped, even if the original request path contains no version
  • AS_IN_REQUEST - Version will be stripped only if the original request path contains no version
  • ALWAYS_STRIP - Version will be stripped, even if the original request path contains version

Parameter hostValue, if provided, will be used to replace the host:port portion of the response Location header. If not provided, the value of the Host request header will be used.

Parameter protocolsRegex must be a valid regex String, against which the protocol name will be matched. If not matched, the filter will do nothing. Default is http|https|ftp|ftps.

5.16 RewriteResponseHeader GatewayFilter Factory

The RewriteResponseHeader GatewayFilter Factory takes name, regexp, and replacement parameters. It uses Java regular expressions for a flexible way to rewrite the response header value.

application.yml.  +

For example, for a request POST https://api.example.com/some/object/name, Location response header value https://object-service.prod.example.net/v2/some/object/id will be rewritten as https://api.example.com/some/object/id.

Parameter stripVersionMode has the following possible values: NEVER_STRIP, AS_IN_REQUEST (default), ALWAYS_STRIP.

  • NEVER_STRIP - Version will not be stripped, even if the original request path contains no version
  • AS_IN_REQUEST - Version will be stripped only if the original request path contains no version
  • ALWAYS_STRIP - Version will be stripped, even if the original request path contains version

Parameter hostValue, if provided, will be used to replace the host:port portion of the response Location header. If not provided, the value of the Host request header will be used.

Parameter protocolsRegex must be a valid regex String, against which the protocol name will be matched. If not matched, the filter will do nothing. Default is http|https|ftp|ftps.

5.17 RewriteResponseHeader GatewayFilter Factory

The RewriteResponseHeader GatewayFilter Factory takes name, regexp, and replacement parameters. It uses Java regular expressions for a flexible way to rewrite the response header value.

application.yml. 

spring:
   cloud:
     gateway:
@@ -258,7 +267,7 @@ and have it applied to all routes.

uri: https://example.org filters: - RewriteResponseHeader=X-Response-Foo, , password=[^&]+, password=***

-

For a header value of /42?user=ford&password=omg!what&flag=true, it will be set to /42?user=ford&password=***&flag=true after making the downstream request. Please use $\ to mean $ because of the YAML spec.

5.17 SaveSession GatewayFilter Factory

The SaveSession GatewayFilter Factory forces a WebSession::save operation before forwarding the call downstream. This is of particular use when +

For a header value of /42?user=ford&password=omg!what&flag=true, it will be set to /42?user=ford&password=***&flag=true after making the downstream request. Please use $\ to mean $ because of the YAML spec.

5.18 SaveSession GatewayFilter Factory

The SaveSession GatewayFilter Factory forces a WebSession::save operation before forwarding the call downstream. This is of particular use when using something like Spring Session with a lazy data store and need to ensure the session state has been saved before making the forwarded call.

application.yml. 

spring:
   cloud:
@@ -270,7 +279,7 @@ using something like         - Path=/foo/**
         filters:
         - SaveSession

-

If you are integrating Spring Security with Spring Session, and want to ensure security details have been forwarded to the remote process, this is critical.

5.18 SecureHeaders GatewayFilter Factory

The SecureHeaders GatewayFilter Factory adds a number of headers to the response at the recommendation from this blog post.

The following headers are added (allong with default values):

  • X-Xss-Protection:1; mode=block
  • Strict-Transport-Security:max-age=631138519
  • X-Frame-Options:DENY
  • X-Content-Type-Options:nosniff
  • Referrer-Policy:no-referrer
  • Content-Security-Policy:default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data:; object-src 'none'; script-src https:; style-src 'self' https: 'unsafe-inline'
  • X-Download-Options:noopen
  • X-Permitted-Cross-Domain-Policies:none

To change the default values set the appropriate property in the spring.cloud.gateway.filter.secure-headers namespace:

Property to change:

  • xss-protection-header
  • strict-transport-security
  • frame-options
  • content-type-options
  • referrer-policy
  • content-security-policy
  • download-options
  • permitted-cross-domain-policies

To disable the default values set the property spring.cloud.gateway.filter.secure-headers.disable with comma separated values.

Example: spring.cloud.gateway.filter.secure-headers.disable=frame-options,download-options

5.19 SetPath GatewayFilter Factory

The SetPath GatewayFilter Factory takes a path template parameter. It offers a simple way to manipulate the request path by allowing templated segments of the path. This uses the uri templates from Spring Framework. Multiple matching segments are allowed.

application.yml.  +

If you are integrating Spring Security with Spring Session, and want to ensure security details have been forwarded to the remote process, this is critical.

5.19 SecureHeaders GatewayFilter Factory

The SecureHeaders GatewayFilter Factory adds a number of headers to the response at the recommendation from this blog post.

The following headers are added (allong with default values):

  • X-Xss-Protection:1; mode=block
  • Strict-Transport-Security:max-age=631138519
  • X-Frame-Options:DENY
  • X-Content-Type-Options:nosniff
  • Referrer-Policy:no-referrer
  • Content-Security-Policy:default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data:; object-src 'none'; script-src https:; style-src 'self' https: 'unsafe-inline'
  • X-Download-Options:noopen
  • X-Permitted-Cross-Domain-Policies:none

To change the default values set the appropriate property in the spring.cloud.gateway.filter.secure-headers namespace:

Property to change:

  • xss-protection-header
  • strict-transport-security
  • frame-options
  • content-type-options
  • referrer-policy
  • content-security-policy
  • download-options
  • permitted-cross-domain-policies

To disable the default values set the property spring.cloud.gateway.filter.secure-headers.disable with comma separated values.

Example: spring.cloud.gateway.filter.secure-headers.disable=frame-options,download-options

5.20 SetPath GatewayFilter Factory

The SetPath GatewayFilter Factory takes a path template parameter. It offers a simple way to manipulate the request path by allowing templated segments of the path. This uses the uri templates from Spring Framework. Multiple matching segments are allowed.

application.yml. 

spring:
   cloud:
     gateway:
@@ -281,7 +290,7 @@ using something like         - Path=/foo/{segment}
         filters:
         - SetPath=/{segment}

-

For a request path of /foo/bar, this will set the path to /bar before making the downstream request.

5.20 SetRequestHeader GatewayFilter Factory

The SetRequestHeader GatewayFilter Factory takes name and value parameters.

application.yml.  +

For a request path of /foo/bar, this will set the path to /bar before making the downstream request.

5.21 SetRequestHeader GatewayFilter Factory

The SetRequestHeader GatewayFilter Factory takes name and value parameters.

application.yml. 

spring:
   cloud:
     gateway:
@@ -301,7 +310,7 @@ using something like         - Host: {segment}.myhost.org
         filters:
         - SetRequestHeader=foo, bar-{segment}

-

5.21 SetResponseHeader GatewayFilter Factory

The SetResponseHeader GatewayFilter Factory takes name and value parameters.

application.yml.  +

5.22 SetResponseHeader GatewayFilter Factory

The SetResponseHeader GatewayFilter Factory takes name and value parameters.

application.yml. 

spring:
   cloud:
     gateway:
@@ -321,7 +330,7 @@ using something like         - Host: {segment}.myhost.org
         filters:
         - SetResponseHeader=foo, bar-{segment}

-

5.22 SetStatus GatewayFilter Factory

The SetStatus GatewayFilter Factory takes a single status parameter. It must be a valid Spring HttpStatus. It may be the integer value 404 or the string representation of the enumeration NOT_FOUND.

application.yml.  +

5.23 SetStatus GatewayFilter Factory

The SetStatus GatewayFilter Factory takes a single status parameter. It must be a valid Spring HttpStatus. It may be the integer value 404 or the string representation of the enumeration NOT_FOUND.

application.yml. 

spring:
   cloud:
     gateway:
@@ -334,7 +343,7 @@ using something like         uri: https://example.org
         filters:
         - SetStatus=401

-

In either case, the HTTP status of the response will be set to 401.

5.23 StripPrefix GatewayFilter Factory

The StripPrefix GatewayFilter Factory takes one paramter, parts. The parts parameter indicated the number of parts in the path to strip from the request before sending it downstream.

application.yml.  +

In either case, the HTTP status of the response will be set to 401.

5.24 StripPrefix GatewayFilter Factory

The StripPrefix GatewayFilter Factory takes one paramter, parts. The parts parameter indicated the number of parts in the path to strip from the request before sending it downstream.

application.yml. 

spring:
   cloud:
     gateway:
@@ -345,7 +354,7 @@ using something like         - Path=/name/**
         filters:
         - StripPrefix=2

-

When a request is made through the gateway to /name/bar/foo the request made to nameservice will look like http://nameservice/foo.

5.24 Retry GatewayFilter Factory

The Retry GatewayFilter Factory takes retries, statuses, methods, and series as parameters.

  • retries: the number of retries that should be attempted
  • statuses: the HTTP status codes that should be retried, represented using org.springframework.http.HttpStatus
  • methods: the HTTP methods that should be retried, represented using org.springframework.http.HttpMethod
  • series: the series of status codes to be retried, represented using org.springframework.http.HttpStatus.Series

application.yml.  +

When a request is made through the gateway to /name/bar/foo the request made to nameservice will look like http://nameservice/foo.

5.25 Retry GatewayFilter Factory

The Retry GatewayFilter Factory takes retries, statuses, methods, and series as parameters.

  • retries: the number of retries that should be attempted
  • statuses: the HTTP status codes that should be retried, represented using org.springframework.http.HttpStatus
  • methods: the HTTP methods that should be retried, represented using org.springframework.http.HttpMethod
  • series: the series of status codes to be retried, represented using org.springframework.http.HttpStatus.Series

application.yml. 

spring:
   cloud:
     gateway:
@@ -359,7 +368,7 @@ using something like           args:
             retries: 3
             statuses: BAD_GATEWAY

-

[Note]Note

The retry filter does not currently support retrying with a body (e.g. for POST or PUT requests with a body).

[Note]Note

When using the retry filter with a forward: prefixed URL, the target endpoint should be written carefully so that in case of an error it does not do anything that could result in a response being sent to the client and committed. For example, if the target endpoint is an annotated controller, the target controller method should not return ResponseEntity with an error status code. Instead it should throw an Exception, or signal an error, e.g. via a Mono.error(ex) return value, which the retry filter can be configured to handle by retrying.

5.25 RequestSize GatewayFilter Factory

The RequestSize GatewayFilter Factory can restrict a request from reaching the downstream service , when the request size is greater than the permissible limit. The filter takes RequestSize as parameter which is the permissible size limit of the request defined in bytes.

application.yml.  +

[Note]Note

The retry filter does not currently support retrying with a body (e.g. for POST or PUT requests with a body).

[Note]Note

When using the retry filter with a forward: prefixed URL, the target endpoint should be written carefully so that in case of an error it does not do anything that could result in a response being sent to the client and committed. For example, if the target endpoint is an annotated controller, the target controller method should not return ResponseEntity with an error status code. Instead it should throw an Exception, or signal an error, e.g. via a Mono.error(ex) return value, which the retry filter can be configured to handle by retrying.

5.26 RequestSize GatewayFilter Factory

The RequestSize GatewayFilter Factory can restrict a request from reaching the downstream service , when the request size is greater than the permissible limit. The filter takes RequestSize as parameter which is the permissible size limit of the request defined in bytes.

application.yml. 

spring:
   cloud:
     gateway:
@@ -372,7 +381,7 @@ using something like       - name: RequestSize
         args:
           maxSize: 5000000

-

The RequestSize GatewayFilter Factory set the response status as 413 Payload Too Large with a additional header errorMessage when the Request is rejected due to size. Following is an example of such an errorMessage .

errorMessage : Request size is larger than permissible limit. Request size is 6.0 MB where permissible limit is 5.0 MB

[Note]Note

The default Request size will be set to 5 MB if not provided as filter argument in route definition.

5.26 Modify Request Body GatewayFilter Factory

This filter is considered BETA and the API may change in the future

This filter can be used to modify the request body before it is sent downstream by the Gateway.

[Note]Note

This filter can only be configured using the Java DSL

@Bean
+

The RequestSize GatewayFilter Factory set the response status as 413 Payload Too Large with a additional header errorMessage when the Request is rejected due to size. Following is an example of such an errorMessage .

errorMessage : Request size is larger than permissible limit. Request size is 6.0 MB where permissible limit is 5.0 MB

[Note]Note

The default Request size will be set to 5 MB if not provided as filter argument in route definition.

5.27 Modify Request Body GatewayFilter Factory

This filter is considered BETA and the API may change in the future

This filter can be used to modify the request body before it is sent downstream by the Gateway.

[Note]Note

This filter can only be configured using the Java DSL

@Bean
 public RouteLocator routes(RouteLocatorBuilder builder) {
     return builder.routes()
         .route("rewrite_request_obj", r -> r.host("*.rewriterequestobj.org")
@@ -398,7 +407,7 @@ using something like public void setMessage(String message) {
         this.message = message;
     }
-}

5.27 Modify Response Body GatewayFilter Factory

This filter is considered BETA and the API may change in the future

This filter can be used to modify the response body before it is sent back to the Client.

[Note]Note

This filter can only be configured using the Java DSL

@Bean
+}

5.28 Modify Response Body GatewayFilter Factory

This filter is considered BETA and the API may change in the future

This filter can be used to modify the response body before it is sent back to the Client.

[Note]Note

This filter can only be configured using the Java DSL

@Bean
 public RouteLocator routes(RouteLocatorBuilder builder) {
     return builder.routes()
         .route("rewrite_response_upper", r -> r.host("*.rewriteresponseupper.org")
@@ -406,7 +415,7 @@ using something like class, String.class,
         		    (exchange, s) -> Mono.just(s.toUpperCase()))).uri(uri)
         .build();
-}

5.28 Default Filters

If you would like to add a filter and apply it to all routes you can use spring.cloud.gateway.default-filters. +}

5.29 Default Filters

If you would like to add a filter and apply it to all routes you can use spring.cloud.gateway.default-filters. This property takes a list of filters

application.yml. 

spring:
   cloud:
diff --git a/2.1.x/multi/multi_spring-cloud-gateway.html b/2.1.x/multi/multi_spring-cloud-gateway.html
index c4fbaab7..2272acbf 100644
--- a/2.1.x/multi/multi_spring-cloud-gateway.html
+++ b/2.1.x/multi/multi_spring-cloud-gateway.html
@@ -1,3 +1,3 @@
 
       
-   Spring Cloud Gateway

Spring Cloud Gateway


Table of Contents

1. How to Include Spring Cloud Gateway
2. Glossary
3. How It Works
4. Route Predicate Factories
4.1. After Route Predicate Factory
4.2. Before Route Predicate Factory
4.3. Between Route Predicate Factory
4.4. Cookie Route Predicate Factory
4.5. Header Route Predicate Factory
4.6. Host Route Predicate Factory
4.7. Method Route Predicate Factory
4.8. Path Route Predicate Factory
4.9. Query Route Predicate Factory
4.10. RemoteAddr Route Predicate Factory
4.10.1. Modifying the way remote addresses are resolved
5. GatewayFilter Factories
5.1. AddRequestHeader GatewayFilter Factory
5.2. AddRequestParameter GatewayFilter Factory
5.3. AddResponseHeader GatewayFilter Factory
5.4. DedupeResponseHeader GatewayFilter Factory
5.5. Hystrix GatewayFilter Factory
5.6. FallbackHeaders GatewayFilter Factory
5.7. PrefixPath GatewayFilter Factory
5.8. PreserveHostHeader GatewayFilter Factory
5.9. RequestRateLimiter GatewayFilter Factory
5.9.1. Redis RateLimiter
5.10. RedirectTo GatewayFilter Factory
5.11. RemoveHopByHopHeadersFilter GatewayFilter Factory
5.12. RemoveRequestHeader GatewayFilter Factory
5.13. RemoveResponseHeader GatewayFilter Factory
5.14. RewritePath GatewayFilter Factory
5.15. RewriteLocationResponseHeader GatewayFilter Factory
5.16. RewriteResponseHeader GatewayFilter Factory
5.17. SaveSession GatewayFilter Factory
5.18. SecureHeaders GatewayFilter Factory
5.19. SetPath GatewayFilter Factory
5.20. SetRequestHeader GatewayFilter Factory
5.21. SetResponseHeader GatewayFilter Factory
5.22. SetStatus GatewayFilter Factory
5.23. StripPrefix GatewayFilter Factory
5.24. Retry GatewayFilter Factory
5.25. RequestSize GatewayFilter Factory
5.26. Modify Request Body GatewayFilter Factory
5.27. Modify Response Body GatewayFilter Factory
5.28. Default Filters
6. Global Filters
6.1. Combined Global Filter and GatewayFilter Ordering
6.2. Forward Routing Filter
6.3. LoadBalancerClient Filter
6.4. Netty Routing Filter
6.5. Netty Write Response Filter
6.6. RouteToRequestUrl Filter
6.7. Websocket Routing Filter
6.8. Gateway Metrics Filter
6.9. Marking An Exchange As Routed
7. TLS / SSL
7.1. TLS Handshake
8. Configuration
8.1. Fluent Java Routes API
8.2. DiscoveryClient Route Definition Locator
8.2.1. Configuring Predicates and Filters For DiscoveryClient Routes
9. Reactor Netty Access Logs
10. CORS Configuration
11. Actuator API
11.1. Verbose Actuator Format
11.2. Retrieving route filters
11.2.1. Global Filters
11.2.2. Route Filters
11.3. Refreshing the route cache
11.4. Retrieving the routes defined in the gateway
11.5. Retrieving information about a particular route
11.6. Creating and deleting a particular route
11.7. Recap: list of all endpoints
12. Troubleshooting
12.1. Log Levels
12.2. Wiretap
13. Developer Guide
13.1. Writing Custom Route Predicate Factories
13.2. Writing Custom GatewayFilter Factories
13.3. Writing Custom Global Filters
13.4. Writing Custom Route Locators and Writers
14. Building a Simple Gateway Using Spring MVC or Webflux
\ No newline at end of file + Spring Cloud Gateway

Spring Cloud Gateway


Table of Contents

1. How to Include Spring Cloud Gateway
2. Glossary
3. How It Works
4. Route Predicate Factories
4.1. After Route Predicate Factory
4.2. Before Route Predicate Factory
4.3. Between Route Predicate Factory
4.4. Cookie Route Predicate Factory
4.5. Header Route Predicate Factory
4.6. Host Route Predicate Factory
4.7. Method Route Predicate Factory
4.8. Path Route Predicate Factory
4.9. Query Route Predicate Factory
4.10. RemoteAddr Route Predicate Factory
4.10.1. Modifying the way remote addresses are resolved
5. GatewayFilter Factories
5.1. AddRequestHeader GatewayFilter Factory
5.2. AddRequestParameter GatewayFilter Factory
5.3. AddResponseHeader GatewayFilter Factory
5.4. DedupeResponseHeader GatewayFilter Factory
5.5. Hystrix GatewayFilter Factory
5.6. FallbackHeaders GatewayFilter Factory
5.7. MapRequestHeader GatewayFilter Factory
5.8. PrefixPath GatewayFilter Factory
5.9. PreserveHostHeader GatewayFilter Factory
5.10. RequestRateLimiter GatewayFilter Factory
5.10.1. Redis RateLimiter
5.11. RedirectTo GatewayFilter Factory
5.12. RemoveHopByHopHeadersFilter GatewayFilter Factory
5.13. RemoveRequestHeader GatewayFilter Factory
5.14. RemoveResponseHeader GatewayFilter Factory
5.15. RewritePath GatewayFilter Factory
5.16. RewriteLocationResponseHeader GatewayFilter Factory
5.17. RewriteResponseHeader GatewayFilter Factory
5.18. SaveSession GatewayFilter Factory
5.19. SecureHeaders GatewayFilter Factory
5.20. SetPath GatewayFilter Factory
5.21. SetRequestHeader GatewayFilter Factory
5.22. SetResponseHeader GatewayFilter Factory
5.23. SetStatus GatewayFilter Factory
5.24. StripPrefix GatewayFilter Factory
5.25. Retry GatewayFilter Factory
5.26. RequestSize GatewayFilter Factory
5.27. Modify Request Body GatewayFilter Factory
5.28. Modify Response Body GatewayFilter Factory
5.29. Default Filters
6. Global Filters
6.1. Combined Global Filter and GatewayFilter Ordering
6.2. Forward Routing Filter
6.3. LoadBalancerClient Filter
6.4. Netty Routing Filter
6.5. Netty Write Response Filter
6.6. RouteToRequestUrl Filter
6.7. Websocket Routing Filter
6.8. Gateway Metrics Filter
6.9. Marking An Exchange As Routed
7. TLS / SSL
7.1. TLS Handshake
8. Configuration
8.1. Fluent Java Routes API
8.2. DiscoveryClient Route Definition Locator
8.2.1. Configuring Predicates and Filters For DiscoveryClient Routes
9. Reactor Netty Access Logs
10. CORS Configuration
11. Actuator API
11.1. Verbose Actuator Format
11.2. Retrieving route filters
11.2.1. Global Filters
11.2.2. Route Filters
11.3. Refreshing the route cache
11.4. Retrieving the routes defined in the gateway
11.5. Retrieving information about a particular route
11.6. Creating and deleting a particular route
11.7. Recap: list of all endpoints
12. Troubleshooting
12.1. Log Levels
12.2. Wiretap
13. Developer Guide
13.1. Writing Custom Route Predicate Factories
13.2. Writing Custom GatewayFilter Factories
13.3. Writing Custom Global Filters
13.4. Writing Custom Route Locators and Writers
14. Building a Simple Gateway Using Spring MVC or Webflux
\ No newline at end of file diff --git a/2.1.x/single/spring-cloud-gateway.html b/2.1.x/single/spring-cloud-gateway.html index 39ca6ee8..94d95c74 100644 --- a/2.1.x/single/spring-cloud-gateway.html +++ b/2.1.x/single/spring-cloud-gateway.html @@ -1,6 +1,6 @@ - Spring Cloud Gateway

Spring Cloud Gateway


Table of Contents

1. How to Include Spring Cloud Gateway
2. Glossary
3. How It Works
4. Route Predicate Factories
4.1. After Route Predicate Factory
4.2. Before Route Predicate Factory
4.3. Between Route Predicate Factory
4.4. Cookie Route Predicate Factory
4.5. Header Route Predicate Factory
4.6. Host Route Predicate Factory
4.7. Method Route Predicate Factory
4.8. Path Route Predicate Factory
4.9. Query Route Predicate Factory
4.10. RemoteAddr Route Predicate Factory
4.10.1. Modifying the way remote addresses are resolved
5. GatewayFilter Factories
5.1. AddRequestHeader GatewayFilter Factory
5.2. AddRequestParameter GatewayFilter Factory
5.3. AddResponseHeader GatewayFilter Factory
5.4. DedupeResponseHeader GatewayFilter Factory
5.5. Hystrix GatewayFilter Factory
5.6. FallbackHeaders GatewayFilter Factory
5.7. PrefixPath GatewayFilter Factory
5.8. PreserveHostHeader GatewayFilter Factory
5.9. RequestRateLimiter GatewayFilter Factory
5.9.1. Redis RateLimiter
5.10. RedirectTo GatewayFilter Factory
5.11. RemoveHopByHopHeadersFilter GatewayFilter Factory
5.12. RemoveRequestHeader GatewayFilter Factory
5.13. RemoveResponseHeader GatewayFilter Factory
5.14. RewritePath GatewayFilter Factory
5.15. RewriteLocationResponseHeader GatewayFilter Factory
5.16. RewriteResponseHeader GatewayFilter Factory
5.17. SaveSession GatewayFilter Factory
5.18. SecureHeaders GatewayFilter Factory
5.19. SetPath GatewayFilter Factory
5.20. SetRequestHeader GatewayFilter Factory
5.21. SetResponseHeader GatewayFilter Factory
5.22. SetStatus GatewayFilter Factory
5.23. StripPrefix GatewayFilter Factory
5.24. Retry GatewayFilter Factory
5.25. RequestSize GatewayFilter Factory
5.26. Modify Request Body GatewayFilter Factory
5.27. Modify Response Body GatewayFilter Factory
5.28. Default Filters
6. Global Filters
6.1. Combined Global Filter and GatewayFilter Ordering
6.2. Forward Routing Filter
6.3. LoadBalancerClient Filter
6.4. Netty Routing Filter
6.5. Netty Write Response Filter
6.6. RouteToRequestUrl Filter
6.7. Websocket Routing Filter
6.8. Gateway Metrics Filter
6.9. Marking An Exchange As Routed
7. TLS / SSL
7.1. TLS Handshake
8. Configuration
8.1. Fluent Java Routes API
8.2. DiscoveryClient Route Definition Locator
8.2.1. Configuring Predicates and Filters For DiscoveryClient Routes
9. Reactor Netty Access Logs
10. CORS Configuration
11. Actuator API
11.1. Verbose Actuator Format
11.2. Retrieving route filters
11.2.1. Global Filters
11.2.2. Route Filters
11.3. Refreshing the route cache
11.4. Retrieving the routes defined in the gateway
11.5. Retrieving information about a particular route
11.6. Creating and deleting a particular route
11.7. Recap: list of all endpoints
12. Troubleshooting
12.1. Log Levels
12.2. Wiretap
13. Developer Guide
13.1. Writing Custom Route Predicate Factories
13.2. Writing Custom GatewayFilter Factories
13.3. Writing Custom Global Filters
13.4. Writing Custom Route Locators and Writers
14. Building a Simple Gateway Using Spring MVC or Webflux

2.1.3.BUILD-SNAPSHOT

This project provides an API Gateway built on top of the Spring Ecosystem, including: Spring 5, Spring Boot 2 and Project Reactor. Spring Cloud Gateway aims to provide a simple, yet effective way to route to APIs and provide cross cutting concerns to them such as: security, monitoring/metrics, and resiliency.

1. How to Include Spring Cloud Gateway

To include Spring Cloud Gateway in your project use the starter with group org.springframework.cloud + Spring Cloud Gateway

Spring Cloud Gateway


Table of Contents

1. How to Include Spring Cloud Gateway
2. Glossary
3. How It Works
4. Route Predicate Factories
4.1. After Route Predicate Factory
4.2. Before Route Predicate Factory
4.3. Between Route Predicate Factory
4.4. Cookie Route Predicate Factory
4.5. Header Route Predicate Factory
4.6. Host Route Predicate Factory
4.7. Method Route Predicate Factory
4.8. Path Route Predicate Factory
4.9. Query Route Predicate Factory
4.10. RemoteAddr Route Predicate Factory
4.10.1. Modifying the way remote addresses are resolved
5. GatewayFilter Factories
5.1. AddRequestHeader GatewayFilter Factory
5.2. AddRequestParameter GatewayFilter Factory
5.3. AddResponseHeader GatewayFilter Factory
5.4. DedupeResponseHeader GatewayFilter Factory
5.5. Hystrix GatewayFilter Factory
5.6. FallbackHeaders GatewayFilter Factory
5.7. MapRequestHeader GatewayFilter Factory
5.8. PrefixPath GatewayFilter Factory
5.9. PreserveHostHeader GatewayFilter Factory
5.10. RequestRateLimiter GatewayFilter Factory
5.10.1. Redis RateLimiter
5.11. RedirectTo GatewayFilter Factory
5.12. RemoveHopByHopHeadersFilter GatewayFilter Factory
5.13. RemoveRequestHeader GatewayFilter Factory
5.14. RemoveResponseHeader GatewayFilter Factory
5.15. RewritePath GatewayFilter Factory
5.16. RewriteLocationResponseHeader GatewayFilter Factory
5.17. RewriteResponseHeader GatewayFilter Factory
5.18. SaveSession GatewayFilter Factory
5.19. SecureHeaders GatewayFilter Factory
5.20. SetPath GatewayFilter Factory
5.21. SetRequestHeader GatewayFilter Factory
5.22. SetResponseHeader GatewayFilter Factory
5.23. SetStatus GatewayFilter Factory
5.24. StripPrefix GatewayFilter Factory
5.25. Retry GatewayFilter Factory
5.26. RequestSize GatewayFilter Factory
5.27. Modify Request Body GatewayFilter Factory
5.28. Modify Response Body GatewayFilter Factory
5.29. Default Filters
6. Global Filters
6.1. Combined Global Filter and GatewayFilter Ordering
6.2. Forward Routing Filter
6.3. LoadBalancerClient Filter
6.4. Netty Routing Filter
6.5. Netty Write Response Filter
6.6. RouteToRequestUrl Filter
6.7. Websocket Routing Filter
6.8. Gateway Metrics Filter
6.9. Marking An Exchange As Routed
7. TLS / SSL
7.1. TLS Handshake
8. Configuration
8.1. Fluent Java Routes API
8.2. DiscoveryClient Route Definition Locator
8.2.1. Configuring Predicates and Filters For DiscoveryClient Routes
9. Reactor Netty Access Logs
10. CORS Configuration
11. Actuator API
11.1. Verbose Actuator Format
11.2. Retrieving route filters
11.2.1. Global Filters
11.2.2. Route Filters
11.3. Refreshing the route cache
11.4. Retrieving the routes defined in the gateway
11.5. Retrieving information about a particular route
11.6. Creating and deleting a particular route
11.7. Recap: list of all endpoints
12. Troubleshooting
12.1. Log Levels
12.2. Wiretap
13. Developer Guide
13.1. Writing Custom Route Predicate Factories
13.2. Writing Custom GatewayFilter Factories
13.3. Writing Custom Global Filters
13.4. Writing Custom Route Locators and Writers
14. Building a Simple Gateway Using Spring MVC or Webflux

2.1.3.BUILD-SNAPSHOT

This project provides an API Gateway built on top of the Spring Ecosystem, including: Spring 5, Spring Boot 2 and Project Reactor. Spring Cloud Gateway aims to provide a simple, yet effective way to route to APIs and provide cross cutting concerns to them such as: security, monitoring/metrics, and resiliency.

1. How to Include Spring Cloud Gateway

To include Spring Cloud Gateway in your project use the starter with group org.springframework.cloud and artifact id spring-cloud-starter-gateway. See the Spring Cloud Project page for details on setting up your build system with the current Spring Cloud Release Train.

If you include the starter, but, for some reason, you do not want the gateway to be enabled, set spring.cloud.gateway.enabled=false.

[Important]Important

Spring Cloud Gateway is built upon Spring Boot 2.x, Spring WebFlux, @@ -271,7 +271,16 @@ a fallbackUri in an external application, like in t

In this example, after an execution exception occurs while running the HystrixCommand, the request will be forwarde to the fallback endpoint or handler in an app running on localhost:9994. The headers with the exception type, message and -if available- root cause exception type and message will be added to that request by the FallbackHeaders filter.

The names of the headers can be overwritten in the config by setting the values of the arguments listed below, along with -their default values:

  • executionExceptionTypeHeaderName ("Execution-Exception-Type")
  • executionExceptionMessageHeaderName ("Execution-Exception-Message")
  • rootCauseExceptionTypeHeaderName ("Root-Cause-Exception-Type")
  • rootCauseExceptionMessageHeaderName ("Root-Cause-Exception-Message")

You can find more information on how Hystrix works with Gateway in the Hystrix GatewayFilter Factory section.

5.7 PrefixPath GatewayFilter Factory

The PrefixPath GatewayFilter Factory takes a single prefix parameter.

application.yml.  +their default values:

  • executionExceptionTypeHeaderName ("Execution-Exception-Type")
  • executionExceptionMessageHeaderName ("Execution-Exception-Message")
  • rootCauseExceptionTypeHeaderName ("Root-Cause-Exception-Type")
  • rootCauseExceptionMessageHeaderName ("Root-Cause-Exception-Message")

You can find more information on how Hystrix works with Gateway in the Hystrix GatewayFilter Factory section.

5.7 MapRequestHeader GatewayFilter Factory

The MapRequestHeader GatewayFilter Factory takes 'fromHeader' and 'toHeader' parameters. It creates a new named header (toHeader) and the value is extracted out of an existing named header (fromHeader) from the incoming http request. If the input header does not exist then the filter has no impact. If the new named header already exists then it’s values will be augmented with the new values.

application.yml.  +

spring:
+  cloud:
+    gateway:
+      routes:
+      - id: map_request_header_route
+        uri: https://example.org
+        filters:
+        - MapRequestHeader=Bar, X-Request-Foo

+

This will add X-Request-Foo:<values> header to the downstream request’s with updated values from the incoming http request Bar header.

5.8 PrefixPath GatewayFilter Factory

The PrefixPath GatewayFilter Factory takes a single prefix parameter.

application.yml. 

spring:
   cloud:
     gateway:
@@ -280,7 +289,7 @@ their default values:

    uri: https://example.org filters: - PrefixPath=/mypath

-

This will prefix /mypath to the path of all matching requests. So a request to /hello, would be sent to /mypath/hello.

5.8 PreserveHostHeader GatewayFilter Factory

The PreserveHostHeader GatewayFilter Factory has not parameters. This filter, sets a request attribute that the routing filter will inspect to determine if the original host header should be sent, rather than the host header determined by the http client.

application.yml.  +

This will prefix /mypath to the path of all matching requests. So a request to /hello, would be sent to /mypath/hello.

5.9 PreserveHostHeader GatewayFilter Factory

The PreserveHostHeader GatewayFilter Factory has not parameters. This filter, sets a request attribute that the routing filter will inspect to determine if the original host header should be sent, rather than the host header determined by the http client.

application.yml. 

spring:
   cloud:
     gateway:
@@ -289,14 +298,14 @@ their default values:

    uri: https://example.org filters: - PreserveHostHeader

-

5.9 RequestRateLimiter GatewayFilter Factory

The RequestRateLimiter GatewayFilter Factory is uses a RateLimiter implementation to determine if the current request is allowed to proceed. If it is not, a status of HTTP 429 - Too Many Requests (by default) is returned.

This filter takes an optional keyResolver parameter and parameters specific to the rate limiter (see below).

keyResolver is a bean that implements the KeyResolver interface. In configuration, reference the bean by name using SpEL. #{@myKeyResolver} is a SpEL expression referencing a bean with the name myKeyResolver.

KeyResolver.java.  +

5.10 RequestRateLimiter GatewayFilter Factory

The RequestRateLimiter GatewayFilter Factory is uses a RateLimiter implementation to determine if the current request is allowed to proceed. If it is not, a status of HTTP 429 - Too Many Requests (by default) is returned.

This filter takes an optional keyResolver parameter and parameters specific to the rate limiter (see below).

keyResolver is a bean that implements the KeyResolver interface. In configuration, reference the bean by name using SpEL. #{@myKeyResolver} is a SpEL expression referencing a bean with the name myKeyResolver.

KeyResolver.java. 

public interface KeyResolver {
 	Mono<String> resolve(ServerWebExchange exchange);
 }

The KeyResolver interface allows pluggable strategies to derive the key for limiting requests. In future milestones, there will be some KeyResolver implementations.

The default implementation of KeyResolver is the PrincipalNameKeyResolver which retrieves the Principal from the ServerWebExchange and calls Principal.getName().

By default, if the KeyResolver does not find a key, requests will be denied. This behavior can be adjust with the spring.cloud.gateway.filter.request-rate-limiter.deny-empty-key (true or false) and spring.cloud.gateway.filter.request-rate-limiter.empty-key-status-code properties.

[Note]Note

The RequestRateLimiter is not configurable via the "shortcut" notation. The example below is invalid

application.properties. 

# INVALID SHORTCUT CONFIGURATION
 spring.cloud.gateway.routes[0].filters[0]=RequestRateLimiter=2, 2, #{@userkeyresolver}

-

5.9.1 Redis RateLimiter

The redis implementation is based off of work done at Stripe. It requires the use of the spring-boot-starter-data-redis-reactive Spring Boot starter.

The algorithm used is the Token Bucket Algorithm.

The redis-rate-limiter.replenishRate is how many requests per second do you want a user to be allowed to do, without any dropped requests. This is the rate that the token bucket is filled.

The redis-rate-limiter.burstCapacity is the maximum number of requests a user is allowed to do in a single second. This is the number of tokens the token bucket can hold. Setting this value to zero will block all requests.

A steady rate is accomplished by setting the same value in replenishRate and burstCapacity. Temporary bursts can be allowed by setting burstCapacity higher than replenishRate. In this case, the rate limiter needs to be allowed some time between bursts (according to replenishRate), as 2 consecutive bursts will result in dropped requests (HTTP 429 - Too Many Requests).

application.yml.  +

5.10.1 Redis RateLimiter

The redis implementation is based off of work done at Stripe. It requires the use of the spring-boot-starter-data-redis-reactive Spring Boot starter.

The algorithm used is the Token Bucket Algorithm.

The redis-rate-limiter.replenishRate is how many requests per second do you want a user to be allowed to do, without any dropped requests. This is the rate that the token bucket is filled.

The redis-rate-limiter.burstCapacity is the maximum number of requests a user is allowed to do in a single second. This is the number of tokens the token bucket can hold. Setting this value to zero will block all requests.

A steady rate is accomplished by setting the same value in replenishRate and burstCapacity. Temporary bursts can be allowed by setting burstCapacity higher than replenishRate. In this case, the rate limiter needs to be allowed some time between bursts (according to replenishRate), as 2 consecutive bursts will result in dropped requests (HTTP 429 - Too Many Requests).

application.yml. 

spring:
   cloud:
     gateway:
@@ -325,7 +334,7 @@ KeyResolver userKeyResolver() {
           args:
             rate-limiter: "#{@myRateLimiter}"
             key-resolver: "#{@userKeyResolver}"

-

5.10 RedirectTo GatewayFilter Factory

The RedirectTo GatewayFilter Factory takes a status and a url parameter. The status should be a 300 series redirect http code, such as 301. The url should be a valid url. This will be the value of the Location header.

application.yml.  +

5.11 RedirectTo GatewayFilter Factory

The RedirectTo GatewayFilter Factory takes a status and a url parameter. The status should be a 300 series redirect http code, such as 301. The url should be a valid url. This will be the value of the Location header.

application.yml. 

spring:
   cloud:
     gateway:
@@ -334,7 +343,7 @@ KeyResolver userKeyResolver() {
         uri: https://example.org
         filters:
         - RedirectTo=302, https://acme.org

-

This will send a status 302 with a Location:https://acme.org header to perform a redirect.

5.11 RemoveHopByHopHeadersFilter GatewayFilter Factory

The RemoveHopByHopHeadersFilter GatewayFilter Factory removes headers from forwarded requests. The default list of headers that is removed comes from the IETF.

The default removed headers are:

  • Connection
  • Keep-Alive
  • Proxy-Authenticate
  • Proxy-Authorization
  • TE
  • Trailer
  • Transfer-Encoding
  • Upgrade

To change this, set the spring.cloud.gateway.filter.remove-non-proxy-headers.headers property to the list of header names to remove.

5.12 RemoveRequestHeader GatewayFilter Factory

The RemoveRequestHeader GatewayFilter Factory takes a name parameter. It is the name of the header to be removed.

application.yml.  +

This will send a status 302 with a Location:https://acme.org header to perform a redirect.

5.12 RemoveHopByHopHeadersFilter GatewayFilter Factory

The RemoveHopByHopHeadersFilter GatewayFilter Factory removes headers from forwarded requests. The default list of headers that is removed comes from the IETF.

The default removed headers are:

  • Connection
  • Keep-Alive
  • Proxy-Authenticate
  • Proxy-Authorization
  • TE
  • Trailer
  • Transfer-Encoding
  • Upgrade

To change this, set the spring.cloud.gateway.filter.remove-non-proxy-headers.headers property to the list of header names to remove.

5.13 RemoveRequestHeader GatewayFilter Factory

The RemoveRequestHeader GatewayFilter Factory takes a name parameter. It is the name of the header to be removed.

application.yml. 

spring:
   cloud:
     gateway:
@@ -343,7 +352,7 @@ KeyResolver userKeyResolver() {
         uri: https://example.org
         filters:
         - RemoveRequestHeader=X-Request-Foo

-

This will remove the X-Request-Foo header before it is sent downstream.

5.13 RemoveResponseHeader GatewayFilter Factory

The RemoveResponseHeader GatewayFilter Factory takes a name parameter. It is the name of the header to be removed.

application.yml.  +

This will remove the X-Request-Foo header before it is sent downstream.

5.14 RemoveResponseHeader GatewayFilter Factory

The RemoveResponseHeader GatewayFilter Factory takes a name parameter. It is the name of the header to be removed.

application.yml. 

spring:
   cloud:
     gateway:
@@ -354,7 +363,7 @@ KeyResolver userKeyResolver() {
         - RemoveResponseHeader=X-Response-Foo

This will remove the X-Response-Foo header from the response before it is returned to the gateway client.

To remove any kind of sensitive header you should configure this filter for any routes that you may want to do so. In addition you can configure this filter once using spring.cloud.gateway.default-filters -and have it applied to all routes.

5.14 RewritePath GatewayFilter Factory

The RewritePath GatewayFilter Factory takes a path regexp parameter and a replacement parameter. This uses Java regular expressions for a flexible way to rewrite the request path.

application.yml.  +and have it applied to all routes.

5.15 RewritePath GatewayFilter Factory

The RewritePath GatewayFilter Factory takes a path regexp parameter and a replacement parameter. This uses Java regular expressions for a flexible way to rewrite the request path.

application.yml. 

spring:
   cloud:
     gateway:
@@ -365,7 +374,7 @@ and have it applied to all routes.

- Path=/foo/** filters: - RewritePath=/foo/(?<segment>.*), /$\{segment}

-

For a request path of /foo/bar, this will set the path to /bar before making the downstream request. Notice the $\ which is replaced with $ because of the YAML spec.

5.15 RewriteLocationResponseHeader GatewayFilter Factory

The RewriteLocationResponseHeader GatewayFilter Factory modifies the value of Location response header, usually to get rid of backend specific details. It takes stripVersionMode, locationHeaderName, hostValue, and protocolsRegex parameters.

application.yml.  +

For a request path of /foo/bar, this will set the path to /bar before making the downstream request. Notice the $\ which is replaced with $ because of the YAML spec.

5.16 RewriteLocationResponseHeader GatewayFilter Factory

The RewriteLocationResponseHeader GatewayFilter Factory modifies the value of Location response header, usually to get rid of backend specific details. It takes stripVersionMode, locationHeaderName, hostValue, and protocolsRegex parameters.

application.yml. 

spring:
   cloud:
     gateway:
@@ -374,7 +383,7 @@ and have it applied to all routes.

uri: http://example.org filters: - RewriteLocationResponseHeader=AS_IN_REQUEST, Location, ,

-

For example, for a request POST https://api.example.com/some/object/name, Location response header value https://object-service.prod.example.net/v2/some/object/id will be rewritten as https://api.example.com/some/object/id.

Parameter stripVersionMode has the following possible values: NEVER_STRIP, AS_IN_REQUEST (default), ALWAYS_STRIP.

  • NEVER_STRIP - Version will not be stripped, even if the original request path contains no version
  • AS_IN_REQUEST - Version will be stripped only if the original request path contains no version
  • ALWAYS_STRIP - Version will be stripped, even if the original request path contains version

Parameter hostValue, if provided, will be used to replace the host:port portion of the response Location header. If not provided, the value of the Host request header will be used.

Parameter protocolsRegex must be a valid regex String, against which the protocol name will be matched. If not matched, the filter will do nothing. Default is http|https|ftp|ftps.

5.16 RewriteResponseHeader GatewayFilter Factory

The RewriteResponseHeader GatewayFilter Factory takes name, regexp, and replacement parameters. It uses Java regular expressions for a flexible way to rewrite the response header value.

application.yml.  +

For example, for a request POST https://api.example.com/some/object/name, Location response header value https://object-service.prod.example.net/v2/some/object/id will be rewritten as https://api.example.com/some/object/id.

Parameter stripVersionMode has the following possible values: NEVER_STRIP, AS_IN_REQUEST (default), ALWAYS_STRIP.

  • NEVER_STRIP - Version will not be stripped, even if the original request path contains no version
  • AS_IN_REQUEST - Version will be stripped only if the original request path contains no version
  • ALWAYS_STRIP - Version will be stripped, even if the original request path contains version

Parameter hostValue, if provided, will be used to replace the host:port portion of the response Location header. If not provided, the value of the Host request header will be used.

Parameter protocolsRegex must be a valid regex String, against which the protocol name will be matched. If not matched, the filter will do nothing. Default is http|https|ftp|ftps.

5.17 RewriteResponseHeader GatewayFilter Factory

The RewriteResponseHeader GatewayFilter Factory takes name, regexp, and replacement parameters. It uses Java regular expressions for a flexible way to rewrite the response header value.

application.yml. 

spring:
   cloud:
     gateway:
@@ -383,7 +392,7 @@ and have it applied to all routes.

uri: https://example.org filters: - RewriteResponseHeader=X-Response-Foo, , password=[^&]+, password=***

-

For a header value of /42?user=ford&password=omg!what&flag=true, it will be set to /42?user=ford&password=***&flag=true after making the downstream request. Please use $\ to mean $ because of the YAML spec.

5.17 SaveSession GatewayFilter Factory

The SaveSession GatewayFilter Factory forces a WebSession::save operation before forwarding the call downstream. This is of particular use when +

For a header value of /42?user=ford&password=omg!what&flag=true, it will be set to /42?user=ford&password=***&flag=true after making the downstream request. Please use $\ to mean $ because of the YAML spec.

5.18 SaveSession GatewayFilter Factory

The SaveSession GatewayFilter Factory forces a WebSession::save operation before forwarding the call downstream. This is of particular use when using something like Spring Session with a lazy data store and need to ensure the session state has been saved before making the forwarded call.

application.yml. 

spring:
   cloud:
@@ -395,7 +404,7 @@ using something like         - Path=/foo/**
         filters:
         - SaveSession

-

If you are integrating Spring Security with Spring Session, and want to ensure security details have been forwarded to the remote process, this is critical.

5.18 SecureHeaders GatewayFilter Factory

The SecureHeaders GatewayFilter Factory adds a number of headers to the response at the recommendation from this blog post.

The following headers are added (allong with default values):

  • X-Xss-Protection:1; mode=block
  • Strict-Transport-Security:max-age=631138519
  • X-Frame-Options:DENY
  • X-Content-Type-Options:nosniff
  • Referrer-Policy:no-referrer
  • Content-Security-Policy:default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data:; object-src 'none'; script-src https:; style-src 'self' https: 'unsafe-inline'
  • X-Download-Options:noopen
  • X-Permitted-Cross-Domain-Policies:none

To change the default values set the appropriate property in the spring.cloud.gateway.filter.secure-headers namespace:

Property to change:

  • xss-protection-header
  • strict-transport-security
  • frame-options
  • content-type-options
  • referrer-policy
  • content-security-policy
  • download-options
  • permitted-cross-domain-policies

To disable the default values set the property spring.cloud.gateway.filter.secure-headers.disable with comma separated values.

Example: spring.cloud.gateway.filter.secure-headers.disable=frame-options,download-options

5.19 SetPath GatewayFilter Factory

The SetPath GatewayFilter Factory takes a path template parameter. It offers a simple way to manipulate the request path by allowing templated segments of the path. This uses the uri templates from Spring Framework. Multiple matching segments are allowed.

application.yml.  +

If you are integrating Spring Security with Spring Session, and want to ensure security details have been forwarded to the remote process, this is critical.

5.19 SecureHeaders GatewayFilter Factory

The SecureHeaders GatewayFilter Factory adds a number of headers to the response at the recommendation from this blog post.

The following headers are added (allong with default values):

  • X-Xss-Protection:1; mode=block
  • Strict-Transport-Security:max-age=631138519
  • X-Frame-Options:DENY
  • X-Content-Type-Options:nosniff
  • Referrer-Policy:no-referrer
  • Content-Security-Policy:default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data:; object-src 'none'; script-src https:; style-src 'self' https: 'unsafe-inline'
  • X-Download-Options:noopen
  • X-Permitted-Cross-Domain-Policies:none

To change the default values set the appropriate property in the spring.cloud.gateway.filter.secure-headers namespace:

Property to change:

  • xss-protection-header
  • strict-transport-security
  • frame-options
  • content-type-options
  • referrer-policy
  • content-security-policy
  • download-options
  • permitted-cross-domain-policies

To disable the default values set the property spring.cloud.gateway.filter.secure-headers.disable with comma separated values.

Example: spring.cloud.gateway.filter.secure-headers.disable=frame-options,download-options

5.20 SetPath GatewayFilter Factory

The SetPath GatewayFilter Factory takes a path template parameter. It offers a simple way to manipulate the request path by allowing templated segments of the path. This uses the uri templates from Spring Framework. Multiple matching segments are allowed.

application.yml. 

spring:
   cloud:
     gateway:
@@ -406,7 +415,7 @@ using something like         - Path=/foo/{segment}
         filters:
         - SetPath=/{segment}

-

For a request path of /foo/bar, this will set the path to /bar before making the downstream request.

5.20 SetRequestHeader GatewayFilter Factory

The SetRequestHeader GatewayFilter Factory takes name and value parameters.

application.yml.  +

For a request path of /foo/bar, this will set the path to /bar before making the downstream request.

5.21 SetRequestHeader GatewayFilter Factory

The SetRequestHeader GatewayFilter Factory takes name and value parameters.

application.yml. 

spring:
   cloud:
     gateway:
@@ -426,7 +435,7 @@ using something like         - Host: {segment}.myhost.org
         filters:
         - SetRequestHeader=foo, bar-{segment}

-

5.21 SetResponseHeader GatewayFilter Factory

The SetResponseHeader GatewayFilter Factory takes name and value parameters.

application.yml.  +

5.22 SetResponseHeader GatewayFilter Factory

The SetResponseHeader GatewayFilter Factory takes name and value parameters.

application.yml. 

spring:
   cloud:
     gateway:
@@ -446,7 +455,7 @@ using something like         - Host: {segment}.myhost.org
         filters:
         - SetResponseHeader=foo, bar-{segment}

-

5.22 SetStatus GatewayFilter Factory

The SetStatus GatewayFilter Factory takes a single status parameter. It must be a valid Spring HttpStatus. It may be the integer value 404 or the string representation of the enumeration NOT_FOUND.

application.yml.  +

5.23 SetStatus GatewayFilter Factory

The SetStatus GatewayFilter Factory takes a single status parameter. It must be a valid Spring HttpStatus. It may be the integer value 404 or the string representation of the enumeration NOT_FOUND.

application.yml. 

spring:
   cloud:
     gateway:
@@ -459,7 +468,7 @@ using something like         uri: https://example.org
         filters:
         - SetStatus=401

-

In either case, the HTTP status of the response will be set to 401.

5.23 StripPrefix GatewayFilter Factory

The StripPrefix GatewayFilter Factory takes one paramter, parts. The parts parameter indicated the number of parts in the path to strip from the request before sending it downstream.

application.yml.  +

In either case, the HTTP status of the response will be set to 401.

5.24 StripPrefix GatewayFilter Factory

The StripPrefix GatewayFilter Factory takes one paramter, parts. The parts parameter indicated the number of parts in the path to strip from the request before sending it downstream.

application.yml. 

spring:
   cloud:
     gateway:
@@ -470,7 +479,7 @@ using something like         - Path=/name/**
         filters:
         - StripPrefix=2

-

When a request is made through the gateway to /name/bar/foo the request made to nameservice will look like http://nameservice/foo.

5.24 Retry GatewayFilter Factory

The Retry GatewayFilter Factory takes retries, statuses, methods, and series as parameters.

  • retries: the number of retries that should be attempted
  • statuses: the HTTP status codes that should be retried, represented using org.springframework.http.HttpStatus
  • methods: the HTTP methods that should be retried, represented using org.springframework.http.HttpMethod
  • series: the series of status codes to be retried, represented using org.springframework.http.HttpStatus.Series

application.yml.  +

When a request is made through the gateway to /name/bar/foo the request made to nameservice will look like http://nameservice/foo.

5.25 Retry GatewayFilter Factory

The Retry GatewayFilter Factory takes retries, statuses, methods, and series as parameters.

  • retries: the number of retries that should be attempted
  • statuses: the HTTP status codes that should be retried, represented using org.springframework.http.HttpStatus
  • methods: the HTTP methods that should be retried, represented using org.springframework.http.HttpMethod
  • series: the series of status codes to be retried, represented using org.springframework.http.HttpStatus.Series

application.yml. 

spring:
   cloud:
     gateway:
@@ -484,7 +493,7 @@ using something like           args:
             retries: 3
             statuses: BAD_GATEWAY

-

[Note]Note

The retry filter does not currently support retrying with a body (e.g. for POST or PUT requests with a body).

[Note]Note

When using the retry filter with a forward: prefixed URL, the target endpoint should be written carefully so that in case of an error it does not do anything that could result in a response being sent to the client and committed. For example, if the target endpoint is an annotated controller, the target controller method should not return ResponseEntity with an error status code. Instead it should throw an Exception, or signal an error, e.g. via a Mono.error(ex) return value, which the retry filter can be configured to handle by retrying.

5.25 RequestSize GatewayFilter Factory

The RequestSize GatewayFilter Factory can restrict a request from reaching the downstream service , when the request size is greater than the permissible limit. The filter takes RequestSize as parameter which is the permissible size limit of the request defined in bytes.

application.yml.  +

[Note]Note

The retry filter does not currently support retrying with a body (e.g. for POST or PUT requests with a body).

[Note]Note

When using the retry filter with a forward: prefixed URL, the target endpoint should be written carefully so that in case of an error it does not do anything that could result in a response being sent to the client and committed. For example, if the target endpoint is an annotated controller, the target controller method should not return ResponseEntity with an error status code. Instead it should throw an Exception, or signal an error, e.g. via a Mono.error(ex) return value, which the retry filter can be configured to handle by retrying.

5.26 RequestSize GatewayFilter Factory

The RequestSize GatewayFilter Factory can restrict a request from reaching the downstream service , when the request size is greater than the permissible limit. The filter takes RequestSize as parameter which is the permissible size limit of the request defined in bytes.

application.yml. 

spring:
   cloud:
     gateway:
@@ -497,7 +506,7 @@ using something like       - name: RequestSize
         args:
           maxSize: 5000000

-

The RequestSize GatewayFilter Factory set the response status as 413 Payload Too Large with a additional header errorMessage when the Request is rejected due to size. Following is an example of such an errorMessage .

errorMessage : Request size is larger than permissible limit. Request size is 6.0 MB where permissible limit is 5.0 MB

[Note]Note

The default Request size will be set to 5 MB if not provided as filter argument in route definition.

5.26 Modify Request Body GatewayFilter Factory

This filter is considered BETA and the API may change in the future

This filter can be used to modify the request body before it is sent downstream by the Gateway.

[Note]Note

This filter can only be configured using the Java DSL

@Bean
+

The RequestSize GatewayFilter Factory set the response status as 413 Payload Too Large with a additional header errorMessage when the Request is rejected due to size. Following is an example of such an errorMessage .

errorMessage : Request size is larger than permissible limit. Request size is 6.0 MB where permissible limit is 5.0 MB

[Note]Note

The default Request size will be set to 5 MB if not provided as filter argument in route definition.

5.27 Modify Request Body GatewayFilter Factory

This filter is considered BETA and the API may change in the future

This filter can be used to modify the request body before it is sent downstream by the Gateway.

[Note]Note

This filter can only be configured using the Java DSL

@Bean
 public RouteLocator routes(RouteLocatorBuilder builder) {
     return builder.routes()
         .route("rewrite_request_obj", r -> r.host("*.rewriterequestobj.org")
@@ -523,7 +532,7 @@ using something like public void setMessage(String message) {
         this.message = message;
     }
-}

5.27 Modify Response Body GatewayFilter Factory

This filter is considered BETA and the API may change in the future

This filter can be used to modify the response body before it is sent back to the Client.

[Note]Note

This filter can only be configured using the Java DSL

@Bean
+}

5.28 Modify Response Body GatewayFilter Factory

This filter is considered BETA and the API may change in the future

This filter can be used to modify the response body before it is sent back to the Client.

[Note]Note

This filter can only be configured using the Java DSL

@Bean
 public RouteLocator routes(RouteLocatorBuilder builder) {
     return builder.routes()
         .route("rewrite_response_upper", r -> r.host("*.rewriteresponseupper.org")
@@ -531,7 +540,7 @@ using something like class, String.class,
         		    (exchange, s) -> Mono.just(s.toUpperCase()))).uri(uri)
         .build();
-}

5.28 Default Filters

If you would like to add a filter and apply it to all routes you can use spring.cloud.gateway.default-filters. +}

5.29 Default Filters

If you would like to add a filter and apply it to all routes you can use spring.cloud.gateway.default-filters. This property takes a list of filters

application.yml. 

spring:
   cloud:
diff --git a/2.1.x/spring-cloud-gateway.xml b/2.1.x/spring-cloud-gateway.xml
index 7425685e..e7eacfce 100644
--- a/2.1.x/spring-cloud-gateway.xml
+++ b/2.1.x/spring-cloud-gateway.xml
@@ -586,6 +586,24 @@ their default values:
 
 You can find more information on how Hystrix works with Gateway in the Hystrix GatewayFilter Factory section.
 
+
+MapRequestHeader GatewayFilter Factory +The MapRequestHeader GatewayFilter Factory takes 'fromHeader' and 'toHeader' parameters. It creates a new named header (toHeader) and the value is extracted out of an existing named header (fromHeader) from the incoming http request. If the input header does not exist then the filter has no impact. If the new named header already exists then it’s values will be augmented with the new values. + +application.yml + +spring: + cloud: + gateway: + routes: + - id: map_request_header_route + uri: https://example.org + filters: + - MapRequestHeader=Bar, X-Request-Foo + + +This will add X-Request-Foo:<values> header to the downstream request’s with updated values from the incoming http request Bar header. +
PrefixPath GatewayFilter Factory The PrefixPath GatewayFilter Factory takes a single prefix parameter.