Release and Audit API Rate-Control Rules
Use this task to release an API rate-control rule version safely and validate node state and business impact.
Applicable Roles
- Platform Operators, API gateway administrators, and security or audit staff
Before You Start
- Record the target API, tenant or model scope, and current normal request baseline.
- Define statistics or blocking mode, threshold, observation window, and rollback conditions.
- Confirm release permission, approval requirements, and target-node scope.
Procedure
1. Record the Traffic Baseline
Open API Rate Control Overview, select a time range that covers normal and peak traffic, and record requests, blocked requests, over-limit statistics, and top rules. Do not judge a rule from total requests alone.

2. Create or Review the Rule
Open Rule Management and review API Pattern, counting scope, mode, quota, window, and priority. Validate a new rule in statistics mode or a limited scope first, then expand only after confirming that it does not match unrelated APIs.

3. Release and Check Node Versions
Release the target version according to approval requirements. Open Release Center and check version, state, node count, publisher, and message. Then open Node Cache and confirm that target nodes loaded the same version. Investigate failed nodes before repeating a full release.

4. Observe Hits and Audit Details
Return to Overview to review request and blocking trends. Then open Observability and Audit and compare minute statistics, block logs, and audit logs for the same API, nodes, and time range. Adjust or roll back according to the plan when false positives or abnormal growth appear.

Completion Checklist
Purpose: These checks confirm that the release action produced observable and explainable node behavior. Stop expanding the rule scope while any check fails.
| Check | Pass Criteria |
|---|---|
| Rule configuration | API matching, counting scope, threshold, mode, and priority are correct. |
| Release record | Target version, node count, state, and release message match expectations. |
| Node cache | All target nodes load the same valid version. |
| Hit audit | Overview metrics correspond to audit records and false positives are acceptable. |
| Rollback readiness | Rollback condition, owner, and validation method are clear. |
Troubleshooting
| Symptom | Check First |
|---|---|
| Rule does not work after a successful release | Enabled state, API Pattern, rule priority, and node-cache version |
| Only some nodes apply the rule | Release target, failure message, node availability, and cache update time |
| Blocking count rises unexpectedly | Business peak, caller retries, matching scope, and threshold |
| Overview shows blocks but audit has no records | Time range, tab, API Path, node, and reporting delay |