# Rate limiting behaviour

**URL:** <https://discuss.konghq.com/t/rate-limiting-behaviour/2081>\
**Category:** Questions\
**Created:** [October 11, 2018, 7:16am UTC](https://discuss.konghq.com/t/rate-limiting-behaviour/2081 "2018-10-11T07:16:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Siamak\_Rahimi\_Motem](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/siamak_rahimi_motem/32/300_2.png) [@Siamak\_Rahimi\_Motem](https://discuss.konghq.com/u/Siamak_Rahimi_Motem)\
**Post date:** [October 11, 2018, 7:16am UTC](https://discuss.konghq.com/t/rate-limiting-behaviour/2081/1 "2018-10-11T07:16:18Z")

</div>

I am a bit mixed up with rate-limiting plugin. Is there anyway so that we rate-limit a service for aggregated calls from any consumer not from each customer ?  
I mean imagine my API has a load tolerance of 100 request per second. I want to enforce this rate limit and I do not know how many consumers will have access. based on the docs it cares about consumer and it use authentication or ip of conusmer machine.  
This way if I put 100 req per second, and if I have 10 consumers they can make 10\*100 request.  
This will be worse if there are 100 consumers and so on.

---

<div class="post-metadata">

**Author:** ![julienlau](https://avatars.discourse-cdn.com/v4/letter/j/2bfe46/32.png) [@julienlau](https://discuss.konghq.com/u/julienlau)\
**Post date:** [November 27, 2018, 2:38pm UTC](https://discuss.konghq.com/t/rate-limiting-behaviour/2081/2 "2018-11-27T14:38:55Z")

</div>

Hi,  
I have also the same issue : I want to protect my backend overall:  
I want to enforce rate limit on each end point linked to hardware/stack capacities (in addition to rate limit per consumer). However, the current rate-limiting plugin needs to be aggregate counts either to an ip, a consumer or a credential.

Is it something only possible with the “pro” edition and rate-limiting-advanced plugin ?  
Has anyone hacked the lua code to implement this in the community edition ?  
Regards  
Julien

---

<div class="post-metadata">

**Author:** ![julienlau](https://avatars.discourse-cdn.com/v4/letter/j/2bfe46/32.png) [@julienlau](https://discuss.konghq.com/u/julienlau)\
**Post date:** [November 27, 2018, 4:20pm UTC](https://discuss.konghq.com/t/rate-limiting-behaviour/2081/3 "2018-11-27T16:20:43Z")

</div>

I just submitted a pull request on github implementing this.

> <https://github.com/Kong/kong/pull/4023>

You do not need to recompile anything to use it.  
Overwrite the lua scripts from your existing rate-limiting plugin and restart kong.

Example:  
git clone blabla  
scp kong/plugins/rate-limiting/handler.lua scp kong/plugins/rate-limiting/schema.lua root@server-kong:/usr/local/share/lua/5.1/kong/plugins/rate-limiting/

---

<div class="post-metadata">

**Author:** ![Cooper](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/cooper/32/9_2.png) [@Cooper](https://discuss.konghq.com/u/Cooper)\
**Post date:** [November 27, 2018, 6:28pm UTC](https://discuss.konghq.com/t/rate-limiting-behaviour/2081/4 "2018-11-27T18:28:01Z")

</div>

Note related discussion in [Common rate limiting for all consumers](https://discuss.konghq.com/t/common-rate-limiting-for-all-consumers/2218/2?u=cooper)

You are indeed correct that if you have fast-growing usage of your backend service, and you don’t have plans to scale your backend in response, you will have problems - but I suggest that the correct way to solve those problems is by scaling your backend service and/or implementing per-consumer (or per-IP) rate limits.

Global rate limiting has the potential to cause increased usage of your service, by a single consumer, to effectively deny **all** users access to your service - I doubt that is what you want.

---

<div class="post-metadata">

**Author:** ![julienlau](https://avatars.discourse-cdn.com/v4/letter/j/2bfe46/32.png) [@julienlau](https://discuss.konghq.com/u/julienlau)\
**Post date:** [November 29, 2018, 8:16am UTC](https://discuss.konghq.com/t/rate-limiting-behaviour/2081/5 "2018-11-29T08:16:44Z")

</div>

Thanks Cooper for the link, I will now switch to this thread.
