You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Helm为Google Cloud CDN同时配置后端与边缘安全策略

实现Google Cloud CDN同时配置边缘与后端Cloud Armor策略(Helm方式)

要同时配置边缘安全策略(edge-security-policy)和后端安全策略(backend-security-policy),核心是将边缘策略绑定到Ingress层面,后端策略绑定到BackendConfig层面,二者互不冲突,和GCP控制台的配置逻辑完全匹配。具体实现步骤如下:

1. 保留原后端安全策略配置

原BackendConfig中绑定后端安全策略的配置无需修改,它负责在请求转发到K8s服务前执行安全检查:

apiVersion: cloud.google.com/v1
kind: BackendConfig
metadata:
  name: backendconfig-cdn
spec:
  securityPolicy:
    name: backend-security-policy # 后端安全策略
  timeoutSec: 1800
  cdn:
    enabled: true
  healthCheck:
    checkIntervalSec: 5
    type: HTTP
    requestPath: /

2. 新增FrontendConfig配置边缘安全策略

创建FrontendConfig资源,用于绑定边缘安全策略,该策略会在请求进入GCP边缘网络(CDN节点)时生效:

apiVersion: networking.gke.io/v1
kind: FrontendConfig
metadata:
  name: frontendconfig-cdn
spec:
  securityPolicy:
    name: edge-security-policy # 边缘安全策略

3. 修改Ingress关联FrontendConfig

在Ingress的注解中添加networking.gke.io/frontend-config,关联上述创建的FrontendConfig,让边缘策略生效:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: ingress-cdn
  annotations:
    kubernetes.io/ingress.class: "gce"
    networking.gke.io/frontend-config: "frontendconfig-cdn" # 关联边缘策略配置
spec:
  rules:
  - host: www.mycdn.com
    http:
      paths:
      - path: /*
        pathType: ImplementationSpecific
        backend:
          service:
            name: service-cdn
            port:
              number: 80

4. Helm整合优化

在Helm Chart中,可以将策略名称抽象到values.yaml中,方便动态配置和复用:

values.yaml

cdn:
  backendSecurityPolicy: "backend-security-policy"
  edgeSecurityPolicy: "edge-security-policy"
  host: "www.mycdn.com"

模板文件调整

  • templates/backendconfig.yaml:
apiVersion: cloud.google.com/v1
kind: BackendConfig
metadata:
  name: {{ .Release.Name }}-backendconfig-cdn
spec:
  securityPolicy:
    name: {{ .Values.cdn.backendSecurityPolicy }}
  timeoutSec: 1800
  cdn:
    enabled: true
  healthCheck:
    checkIntervalSec: 5
    type: HTTP
    requestPath: /
  • templates/frontendconfig.yaml:
apiVersion: networking.gke.io/v1
kind: FrontendConfig
metadata:
  name: {{ .Release.Name }}-frontendconfig-cdn
spec:
  securityPolicy:
    name: {{ .Values.cdn.edgeSecurityPolicy }}
  • templates/ingress.yaml:
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: {{ .Release.Name }}-ingress-cdn
  annotations:
    kubernetes.io/ingress.class: "gce"
    networking.gke.io/frontend-config: "{{ .Release.Name }}-frontendconfig-cdn"
spec:
  rules:
  - host: {{ .Values.cdn.host }}
    http:
      paths:
      - path: /*
        pathType: ImplementationSpecific
        backend:
          service:
            name: {{ .Release.Name }}-service-cdn
            port:
              number: 80
  • templates/service.yaml(同步调整名称关联):
apiVersion: v1
kind: Service
metadata:
  labels:
    app: service-cdn
  name: {{ .Release.Name }}-service-cdn
  annotations:
    cloud.google.com/neg: '{"ingress": true}'
    cloud.google.com/backend-config: '{"default": "{{ .Release.Name }}-backendconfig-cdn"}'
spec:
  ports:
    - name: web
      port: 80
      targetPort: 8080
  clusterIP: None
  selector:
    app: lb-stateful

生效逻辑说明

  • 边缘安全策略:通过FrontendConfig绑定到Ingress,请求到达GCP边缘负载均衡节点(CDN层)时即执行检查,拦截恶意请求。
  • 后端安全策略:通过BackendConfig绑定到Service,请求转发到K8s后端服务前执行二次检查,进一步保障服务安全。

内容的提问来源于stack exchange,提问作者zeebuck

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 16:06:04