在 Debian 上运行的 Tomcat 可以通过多种层面做限流(节流/并发控制),下面按常用程度和实践可行性给你一个清晰清单。
编辑:
/etc/tomcat9/server.xml # 或 tomcat8 / tomcat10
<Connector
port="8080"
protocol="org.apache.coyote.http11.Http11NioProtocol"
maxThreads="200"
acceptCount="100"
maxConnections="10000"
connectionTimeout="20000"
/>
参数说明:
| 参数 | 作用 |
|---|---|
| maxThreads | 最大并发处理线程(≈并发请求数) |
| acceptCount | 队列长度(超过 maxThreads 后排队) |
| maxConnections | 最大连接数 |
| connectionTimeout | 连接超时(防慢连接拖死) |
✅ 这是最重要的限流点
Tomcat 8.5+ 支持 RemoteAddrValve:
<Valve className="org.apache.catalina.valves.RemoteAddrValve"
allow=".*"
deny=""
maxConnectionsPerIP="20"/>
或配合:
<Valve className="org.apache.catalina.valves.RemoteIpValve"/>
⚠️ 更推荐用 前端 Nginx 做 IP 限流(见下)
如果你前面有 Nginx:
http {
limit_req_zone $binary_remote_addr zone=req_limit:10m rate=10r/s;
server {
location / {
limit_req zone=req_limit burst=20 nodelay;
proxy_pass http://127.0.0.1:8080;
}
}
}
limit_conn_zone $binary_remote_addr zone=conn_limit:10m;
location / {
limit_conn conn_limit 10;
}
✅ Nginx 限流比 Tomcat 高效得多
适合:
@RateLimiter(permits = 5, timeUnit = TimeUnit.SECONDS)
或:
iptables -A INPUT -p tcp --dport 8080 -m limit --limit 20/s -j ACCEPT
ulimit -n 65535
| 场景 | 推荐方案 |
|---|---|
| 普通 Web | Tomcat maxThreads + Nginx limit_req |
| API 服务 | Nginx + 应用层限流 |
| 防御 CC | Nginx + iptables |
| 高并发 | Nginx → Tomcat 集群 |
你可以告诉我:
我可以直接给你 可复制的配置文件。