1. Images & Charts
  2. envoy-ratelimit
envoy-ratelimit

envoy-ratelimit

Infra
Updated on July 26

Envoy-Ratelimit Overview

Secure your stack with a hardened Envoy-Ratelimit image freshly-built by Minimus. Minimus images always include the most up-to-date package version for all packages and dependencies.


Envoy-Ratelimit is a Go/gRPC service that provides centralized rate limiting for Envoy proxies. It evaluates incoming requests against configurable rules and enforces limits using a Redis backend, enabling fine-grained traffic control across services.


Try It Out

Take the Minimus Envoy-Ratelimit image for a test run using Docker Compose. This guide sets up the rate limit service alongside Redis and Envoy.

To begin, log into the Minimus registry:

echo "{token}" | docker login reg.mini.dev -u minimus --password-stdin

Create a Rate Limit Configuration

Save the following to a ratelimit-config.yaml file in your working directory:

domain: test
descriptors:
  - key: generic_key
    value: default
    rate_limit:
      unit: minute
      requests_per_unit: 10

Create a Docker Compose File

Save the following to a docker-compose-ratelimit.yaml file in your working directory:

services:
  redis:
    image: reg.mini.dev/redis:latest
    ports:
      - "6379:6379"
    healthcheck:
      test: ["CMD", "redis-cli", "ping"]
      interval: 5s
      timeout: 3s
      retries: 5

  ratelimit:
    image: reg.mini.dev/envoy-ratelimit:latest
    depends_on:
      redis:
        condition: service_healthy
    environment:
      USE_STATSD: "false"
      LOG_LEVEL: debug
      REDIS_SOCKET_TYPE: tcp
      REDIS_URL: redis:6379
      RUNTIME_ROOT: /data
      RUNTIME_SUBDIRECTORY: ratelimit
      RUNTIME_WATCH_ROOT: "false"
    volumes:
      - ./ratelimit-config.yaml:/data/ratelimit/config/test.yaml
    ports:
      - "8080:8080"
      - "8081:8081"
      - "6070:6070"

Start the Services

docker compose -f docker-compose-ratelimit.yaml up -d

Wait for all services to become healthy:

docker compose -f docker-compose-ratelimit.yaml ps

Verify the Rate Limit Service

Send a test request to the HTTP debug endpoint:

curl -s http://localhost:8080/healthcheck

A successful response returns OK, confirming the rate limit service is running.

Clean Up

Stop and remove all containers and volumes:

docker compose -f docker-compose-ratelimit.yaml down -v

Technical Considerations

The Envoy-Ratelimit image provided by Minimus is a slim, security-hardened alternative to the public image from Docker Hub. The images are largely interchangeable, with a few differences as noted below.

Envoy-Ratelimit built by Minimus:

  1. Runs as non-root by default for a security-first approach that protects against privilege escalation attacks.
  2. Drill down on the version specification tab to see the default user, listening ports, entrypoint, volumes, environment variables, etc.

The Payoff

A hardened, minimal image that will remain more secure for the long run and accrue vulnerabilities at a slower rate.


Terms & Info

Trademark

This catalog is published by Minimus. All product names, logos, and marks, other than those belonging to Minimus, shown are owned by their respective rights holders and appear here only to identify the open source software each image contains. Minimus claims no ownership of those marks and implies no affiliation with, endorsement by, certification by, or sponsorship by any rights holder.

Disclaimer

Images are provided "as-is" without warranty of any kind. "Hardened" refers to the security configuration applied at the time of build and does not constitute a guarantee of ongoing security or absence of vulnerabilities. The free tier is provided without support, SLA, or guaranteed patching timelines. Security updates may be applied to paid subscriptions before or instead of free tier images. By pulling or using any image you agree to our Terms of Use.