Load testing a gRPC service
You can use Load Testing for service load testing via gRPC
To run a load test:
- Get your cloud ready.
- Prepare a test target.
- Set up your infrastructure.
- Create an agent.
- Test gRPC Server Reflection.
- Prepare a file with test data.
- Run the test.
If you no longer need the resources you created, delete them.
Get your cloud ready
Sign up for Yandex Cloud and create a billing account:
- Navigate to the management console- On the Yandex Cloud BillingACTIVEorTRIAL_ACTIVEstatus. If you do not have a billing account, create one and link a cloud to it.
If you have an active billing account, you can navigate to the cloud page
Learn more about clouds and folders here.
Required paid resources
If the agent is hosted on Yandex Cloud, you pay for computing resources (see Yandex Compute Cloud pricing).
At the Preview stage, Load Testing is free of charge.
Prepare a test target
In this example, we will be using a gRPC service with the 172.17.0.10 internal IP address in the same subnet as where the agent will reside.
To learn how to integrate the gRPC framework for different programming languages, see this documentation
- 
Configure support for gRPC Server Reflection. To learn how to configure gRPC Server Reflection for different programming languages, see this documentation With gRPC Server Reflection, the load generator polls the server at the start of a test to collect information about services and their methods and uses this data to generate correct gRPC requests during the test. 
- 
Install a port to access the gRPC service: 8080.
You can also use Load Testing for a service that is public or located in a subnet and security group other than those of the agent.
For a public service, allow incoming HTTPS traffic on port 8080.
For a service whose subnet and security group is different from the agent's ones, create a rule for incoming HTTPS traffic on port 8080 in the security group where the test target is located.
Set up your infrastructure
Create a service account
- Create a service account named sa-loadtestin the folder that will host the agent to generate the load.
- Assign the loadtesting.generatorClientrole to the service account.
Configure your network
Create and configure a NAT gateway in the subnet hosting your test target and where the agent will reside. This will enable the agent to access Load Testing.
Configure security groups
- 
Configure the test agent security group: - Create an agent security group named agent-sg.
- Add rules:
- 
Rule for outbound HTTPS traffic to the Load Testing public API: - Port range: 443.
- Protocol: TCP.
- Destination name: CIDR.
- CIDR blocks: 0.0.0.0/0.
 This will allow you to connect the agent to Load Testing to manage tests from the interface and get test results. 
- Port range: 
- 
Inbound SSH traffic rule: - Port range: 22.
- Protocol: TCP.
- Destination name: CIDR.
- CIDR blocks: 0.0.0.0/0.
 This will allow you to connect to the agent over SSH and manage tests from the console or collect debugging information. 
- Port range: 
- 
Rule for outbound traffic when generating load to the test target: - Port range: 0-65535.
- Protocol: Any.
- Destination name: Security group.
 SelectFrom list. Specify the security group comprising the test target.
 Create this rule for each test target with a unique security group. 
- Port range: 
 
- 
 
- Create an agent security group named 
- 
Configure the test target security group: - 
Create a test target security group named load-target-sg.
- 
Add a rule for inbound traffic when generating load to the test target: - Port range: 0-65535.
- Protocol: Any.
- Destination name: Security group.
 SelectFrom list. Specify the security group comprising the test target.
 This rule allows agents to generate load to the test target or use additional monitoring tools. 
- Port range: 
 
- 
Create a test agent
- 
If you do not have an SSH key pair yet, create one. 
- 
Create an agent: Management consoleCLI- 
In the management console - 
In the list of services, select Load Testing. 
- 
In the Agents tab, click Create agent. 
- 
Enter a name for the agent, e.g., agent-008.
- 
Specify the same availability zone as the one hosting your test target. 
- 
Under Agent: - Select the appropriate agent type. For more information, see Agent performance.
- Specify the subnet hosting your test target. Make sure you created and set up a NAT gateway in that subnet.
- If you have access to security groups, select a preset agent security group.
 
- 
Under Access, specify the agent access credentials: - 
Select the sa-loadtestservice account.
- 
Under Login, enter the username. Alert Do not use rootor other reserved usernames. To perform operations requiring root privileges, use thesudocommand.
- 
In the SSH key field, paste the contents of the public key file. 
 
- 
- 
Click Create. 
- 
Wait for the VM to create. Make sure the agent status has changed to Ready for test.Note If the agent creation process has stopped at Initializing connection, make sure the following conditions are met:- The agent has a public IP address and access to loadtesting.api.cloud.yandex.net:443.
- The target subnet has a configured NAT gateway.
- The service account assigned to the agent has the required roles.
 
- The agent has a public IP address and access to 
 If you do not have the Yandex Cloud CLI installed yet, install and initialize it. By default, the CLI uses the folder specified when creating the profile. To change the default folder, use the yc config set folder-id <folder_ID>command. You can also set a different folder for any specific command using the--folder-nameor--folder-idparameter.- 
See the description of the CLI command for creating an agent: yc loadtesting agent create --help
- 
Select the same availability zone as the one hosting your test target. 
- 
Select the subnet hosting your test target. Make sure you created and set up a NAT gateway in that subnet. To get a list of available subnets using the CLI, run this command: yc vpc subnet listResult: +----------------------+---------------------------+----------------------+----------------+-------------------+-----------------+ | ID | NAME | NETWORK ID | ROUTE TABLE ID | ZONE | RANGE | +----------------------+---------------------------+----------------------+----------------+-------------------+-----------------+ | e2lfkhps7bol******** | default-ru-central1-b | enpnf7hajqmd******** | | ru-central1-b | [10.129.0.0/24] | | e9bgnq1bggfa******** | default-ru-central1-a | enpnf7hajqmd******** | | ru-central1-a | [10.128.0.0/24] | | fl841n5ilklr******** | default-ru-central1-d | enpnf7hajqmd******** | | ru-central1-d | [10.130.0.0/24] | +----------------------+---------------------------+----------------------+----------------+-------------------+-----------------+
- 
Select the security group. Make sure to configure the security group in advance. To get a list of available security groups using the CLI, run this command: yc vpc security-group listResult: +----------------------+---------------------------------+--------------------------------+----------------------+ | ID | NAME | DESCRIPTION | NETWORK-ID | +----------------------+---------------------------------+--------------------------------+----------------------+ | enp414a2tnnp******** | default-sg-enpnf7hajqmd******** | Default security group for | enpnf7hajqmd******** | | | | network | | | enpctpve7951******** | sg-load-testing-agents | | enpnf7hajqmd******** | | enpufo9ms0gi******** | sg-load-testing-targets | | enpnf7hajqmd******** | +----------------------+---------------------------------+--------------------------------+----------------------+
- 
Get the ID of sa-loadtestservice account, specifying its name:yc iam service-account get sa-loadtestResult: id: ajespasg04oc******** folder_id: b1g85uk96h3f******** created_at: "2024-12-04T17:38:57Z" name: sa-loadtest last_authenticated_at: "2024-12-12T19:10:00Z"
- 
Create an agent in the default folder: yc loadtesting agent create \ --name agent-008 \ --labels origin=default,label-key=label-value \ --zone default-ru-central1-a \ --network-interface subnet-id=e9bgnq1bggfa********,security-group-ids=enpctpve7951******** \ --cores 2 \ --memory 2G \ --service-account-id ajespasg04oc******** --metadata-from-file user-data=metadata.yamlWhere: - --name: Agent name.
- --labels: Agent labels.
- --zone: Availability zone to host the agent.
- --network-interface: Agent network interface settings:- subnet-name: ID of the selected subnet.
- security-group-ids: Security group IDs.
 
- --cores: Number of CPU cores the agent can use.
- --memory: Amount of RAM allocated to the agent.
- --service-account-id: Service account ID.
- --metadata-from-file:- <key>=<value>pair with the name of the file containing the public SSH key path. For an example of the- metadata.yamlconfiguration file, see VM metadata.
 For more information on how to create an agent with the CLI, see the Yandex Cloud Examples repository 
 
- 
- 
Assign a public IP address to your agent to enable access over SSH: Management consoleCLI- In the management console- Select Compute Cloud.
- Select the agent-008VM.
- Under Network interface, in the top-right corner, click - In the window that opens:
- In the Public address field, select Auto.
- Click Add.
 
 To assign a public IP address to an agent, run the following CLI command: yc compute instance add-one-to-one-nat \ --id=<VM_ID> \ --network-interface-index=<VM_network_interface_number> \ --nat-address=<IP_address>Where: - 
--id: VM ID. You can get a list of available VM IDs in the folder using theyc compute instance listCLI command.
- 
--network-interface-index: VM network interface number. The default value is0. To get a list of VM network interfaces and their numbers, runyc compute instance get <VM_ID>.
- 
--nat-address: Public IP address to assign to the VM. This is an optional setting. If you skip it, the VM will get a public IP address automatically.You can get a list of reserved public IP addresses available in the folder using the yc vpc address listCLI command. The IP address and the VM must be in the same availability zone.
 Here is a possible use case: yc compute instance add-one-to-one-nat \ --id=fhmsbag62taf******** \ --network-interface-index=0 \ --nat-address=51.250.*.***Result: id: fhmsbag62taf******** folder_id: b1gv87ssvu49******** created_at: "2022-05-06T10:41:56Z" ... network_settings: type: STANDARD placement_policy: {}For more information about the yc compute instance add-one-to-one-natcommand, see the CLI reference.
- In the management console
Test gRPC Server Reflection
- 
Connect to the agent via SSH. 
- 
Run the following command to test gRPC Server Reflection on the gRPC service: Connecting via TLSConnecting without TLSgrpcurl 172.17.0.10:8080 listgrpcurl --plaintext 172.17.0.10:8080 listResult: api.Adder grpc.reflection.v1alpha.ServerReflection
Prepare a file with test data
- 
Generate test data in GRPC_JSON format: {"tag": "/Add", "call": "api.Adder.Add", "payload": {"x": 21, "y": 12}} {"tag": "/Add", "call": "api.Adder.Add", "payload": {"x": 21, "y": 12}} {"tag": "/Add2", "call": "api.Adder.Add", "payload": {"x": 210, "y": 120}}Where: - tag: Request tag to display in reports.
- call: Method being called.
- payload: Dictionary with the call parameters to provide to the test target.
 In our example, two thirds of requests will be tagged as /Addand one third, as/Add2.
- 
Save the test data to a file named data.json.
Run the test
- In the management console- In the left-hand panel, select - Click Create test.
- On the test creation page:
- 
In the Agents field, select agent-008you previously created.
- 
Under Attached files, click Select files and select the data.jsonfile you saved earlier.
- 
Under Test settings: - 
In the Configuration method field, select Config. 
- 
In the configuration input field, specify the testing thread settings in yamlformat:pandora: enabled: true pandora_cmd: /usr/local/bin/pandora package: yandextank.plugins.Pandora config_content: pools: - id: GRPC gun: type: grpc # Protocol. target: 172.17.0.10:8080 # Address of the test target. tls: false ammo: type: grpc/json file: data.json # The file name must match the name of the attached file. result: type: phout destination: ./phout.log rps: - duration: 180s # Test duration. type: line # Load type. from: 1 to: 1500 startup: type: once times: 1500 # Number of threads. log: level: debug monitoring: expvar: enabled: true port: 1234 autostop: enabled: true package: yandextank.plugins.Autostop autostop: - limit (5m) uploader: api_address: loadtesting.api.cloud.yandex.net:443 enabled: true job_dsc: grpc test job_name: '[pandora][config][grpc]' package: yandextank.plugins.DataUploader ver: '1.1' core: {}Tip Check this sample configuration file. You can also find sample configuration files in existing tests. 
 
- 
- 
Click Create. 
 
- 
Next, the configuration will be checked, and the agent will start loading the gRPC service.
To see the testing progress, select the new test and go to the Test results tab.
Delete the resources you created
Some resources are not free of charge. To avoid paying for them, delete the resources you no longer need: