BLASTA

SOAP web services load testing template

SOAP 1.1 and 1.2 calls, WSDL, faults, WS-Security, large messages and hardening checks.

Category SOAPStack Any SOAP service (JAX-WS, WCF, Axis, Spring-WS, Zeep, PHP SoapServer)Jobs 27

About this SOAP web services load test

Load tests any SOAP service (JAX-WS, WCF, Axis, Spring-WS, PHP SoapServer): the WSDL, SOAP 1.1 and 1.2 calls, WS-Security, and hardening checks such as malformed XML, unknown operations, a wrong SOAPAction or content type and a DTD in the request, plus large messages, a capacity ramp and a ten-minute soak.

It holds 27 ready-made jobs: 14 single scenarios and an enterprise test plan of 13 stages to run in order, 11 of them with pass/fail targets (SLOs). Each job is a plain request pattern you can change before running.

Scenarios include fetch the WSDL, fetch the WSDL (cache bypass), SOAP 1.1 call, SOAP 1.2 call and WS-Security UsernameToken.

How to load test SOAP web services

  1. Open the template in BLASTA.
  2. Set url, soapAction, namespace, operation and param to point at your own SOAP web services system, ideally a staging copy.
  3. Pick a job and choose the rate and duration.
  4. Start the run and watch requests per second, latency percentiles and errors live; the result is saved to your history.

What you set before running

url
Service endpoint URL
soapAction
SOAPAction of the operation
namespace
Target namespace of the service
operation
Operation (request element) name
param
Name of one request parameter
value
Its value

Test scenarios (14)

fetch the WSDL

Read-only

Clients fetch the WSDL at start-up, and some on every call (a common performance bug). It is often generated on the fly.

SOAP 1.1 call

Read-only

A SOAP Fault is returned with HTTP 500, so a Fault counts as an error here. The baseline request: XML parse, dispatch, business logic and response serialisation.

SOAP 1.2 call

Read-only

A SOAP Fault is returned with HTTP 500, so a Fault counts as an error here. Same operation with the SOAP 1.2 envelope and content type; some stacks route the versions differently.

WS-Security UsernameToken

Read-only

A SOAP Fault is returned with HTTP 500, so a Fault counts as an error here. Adds authentication in the header. Needs SOAP_USER and SOAP_PASSWORD (CLI only; the web UI does not expand environment variables). Token validation is often the slow part.

malformed XML

Read-only

Not XML at all. The service must answer with a 400 or a SOAP Fault (HTTP 500) quickly, with no stack trace. Both count as handled.

unknown operation

Read-only

A valid envelope calling an operation that does not exist: a Fault is expected.

wrong SOAPAction

Read-only

Header does not match the body. Strict services reject it; lenient ones ignore it. Either is fine, but it should not crash.

DTD in the request (XXE hardening)

Read-only

A harmless inline entity declaration. A hardened parser REFUSES documents with a DOCTYPE (400 or a Fault); a 200 here means DTDs are processed, which is an XML external entity risk.

large message (~100 KB)

Read-only

Big requests stress the XML parser (DOM parsers hold the whole tree in memory) and body limits. A 413 or a Fault for too-large input is acceptable.

capacity ramp

Read-only

A SOAP Fault is returned with HTTP 500, so a Fault counts as an error here. Ramps the SOAP call to find where latency climbs. XML processing is CPU heavy, so expect a lower ceiling than for JSON.

soak (10 min)

Read-only

A SOAP Fault is returned with HTTP 500, so a Fault counts as an error here. Steady load that finds leaks in session state, JAXB/DOM caches and connection pools.

Enterprise test plan (13)

Run in order: smoke, baseline, load, stress, spike, soak, breakpoint and failover window, each with pass/fail targets.

SOAP web services: 01 smoke

Read-only

Enterprise plan, step 1 of 10. One request a second for 30 seconds. Run this first, every time: it proves the address, credentials and headers are right and that the environment is up before any real load is applied. Gate: zero errors. Reference request: SOAP 1.1 call.

SOAP web services: 02 baseline (20% load)

Read-only

Step 2 of 10. About a fifth of normal traffic for 5 minutes: the uncontended latency of this request. Every later result is judged against it, so record p50 and p95. Gate: at most 0.5% errors and the default latency targets. Reference request: SOAP 1.1 call.

SOAP web services: 03 average load (SLO check)

Read-only

Step 3 of 10. Normal busy-hour traffic for 10 minutes. The rate is the reference job's rate: raise it to your measured production peak-hour rate. This is the run that proves (or breaks) your SLO. Gate: at most 1% errors, p95 and p99 inside the targets. Reference request: SOAP 1.1 call.

SOAP web services: 04 peak load (2x average)

Read-only

Step 4 of 10. Twice the average for 10 minutes: the busiest hour of the year plus headroom. Latency may rise, but must stay in SLO; if it does not, you have no headroom. Gate: at most 2% errors, latency targets doubled. Reference request: SOAP 1.1 call.

SOAP web services: 05 stress (ramp to 4x)

Read-only

Step 5 of 10. Ramps to four times average over 10 minutes, then holds for 2. Finds where it degrades and HOW: gracefully (latency rises, errors stay low) or badly (errors, timeouts, crashes, restarts). Observation only, no gate. Reference request: SOAP 1.1 call.

SOAP web services: 06 spike (10x in 10 s)

Read-only

Step 6 of 10. Reaches ten times average within 10 seconds and holds for 2 minutes: a campaign email, a news link, a failover. Checks autoscaling, queue limits and load shedding. Gate: at most 5% errors, because shedding load is acceptable and crashing is not. Reference request: SOAP 1.1 call.

SOAP web services: 07 recovery after the spike

Read-only

Step 7 of 10. Run IMMEDIATELY after the spike, at average load for 5 minutes. Latency and errors must return to the baseline from step 2. If they do not, something is stuck: queues, connection pools, GC, an autoscaler cool-down. Gate: same as average load. Reference request: SOAP 1.1 call.

SOAP web services: 08 soak (1 hour at 60%)

Read-only

Step 8 of 10. One hour of steady load. Finds leaks and slow decay in memory, connections, file descriptors, disk, log volume and cache churn. Watch the resource graphs: any line that climbs and never flattens is a finding. Gate: at most 0.5% errors. Reference request: SOAP 1.1 call.

SOAP web services: 09 breakpoint (find the ceiling)

Read-only

Step 9 of 10. Ramps to twenty times average over 20 minutes. Stop it when errors pass about 5%: the rate at that moment is your ceiling, and ceiling divided by peak is your capacity margin. Use a production-like environment, never production. Reference request: SOAP 1.1 call.

SOAP web services: 10 resilience window (failover / deploy)

Read-only

Step 10 of 10. Average load for 15 minutes. About 5 minutes in, cause the event you are testing: kill a pod or node, fail over the database, roll out a new version, drain a zone. Errors in the window are your real availability loss. Gate: at most 1% errors overall; read the time series for how long the dip lasted. Reference request: SOAP 1.1 call.

SOAP web services: peak (2x)

Read-only

Twice normal for 10 minutes. XML parsing is CPU bound, so SOAP services often saturate a core long before the network. Reference request: SOAP 1.1 call.

SOAP web services: WSDL refetch herd

Read-only

Clients refetch the WSDL when they restart, so a rolling restart of 50 client instances is a burst of WSDL requests. Ten times normal for 90 seconds. Reference request: fetch the WSDL.

SOAP web services: authenticated peak

Read-only

Three times normal authenticated calls for 10 minutes. Token validation is often the slow part. Reference request: WS-Security UsernameToken.

Frequently asked questions

What does the SOAP web services load test cover?

The SOAP web services template has 27 jobs: 14 single scenarios and an enterprise test plan of 13 stages (smoke, baseline, load, stress, spike, soak, breakpoint and failover window). Scenarios include fetch the WSDL, fetch the WSDL (cache bypass), SOAP 1.1 call and SOAP 1.2 call. 11 of them have pass/fail targets (SLOs), so a run can be judged against limits you set.

How do I load test SOAP web services with BLASTA?

Open the template in BLASTA and set url, soapAction, namespace, operation and param, then pick a job and start it. Results stream live: requests per second, latency percentiles and errors, and the run is kept in your history. To run from the command line, use blasta preset new soap-services with your address.

Is it safe to run the SOAP web services load test against production?

All 27 jobs in this template are read-only: they request pages or data and do not change anything. Even so, a load test can slow a live system down, so start with a low rate and prefer a staging copy. Only test systems you own or have permission to test.

Run a load test

Point BLASTA at something you own, choose how hard to hit it, and press Start test. Results stream in live.

1 What do you want to test? Use a template

Request headers

2 How hard should it hit?

Advanced limits
Pass / fail targets (SLO) optional
The result is marked SLO met or SLO missed. The same targets live in a job file, where blasta run exits 2 on a miss so CI or Kubernetes can gate a release.

Set up this job

Quick check

Please confirm you are not a robot to start your free test.

Clear history

Delete every finished test in your history. Tests still running are kept. This cannot be undone.

Add identity provider

Add user

The account is active at once. Share the password with them securely; they can change it from their menu.

Sign in to use templates

Templates and test history are part of the full app. Sign in, or create a free account, to use them.

Sign inCreate account

Change password