如何在Host或Path级别配置Kubernetes的HAProxy Ingress控制器?
HAProxy Ingress在Host/Path级别调整配置的方法
当然可以,HAProxy Ingress完全支持在Host或Path级别做精细化配置调整,不用局限于全局统一设置。下面分两种场景说明具体实现方式:
一、Host级别配置调整
方式1:为单个Host创建独立Ingress
如果不同Host的配置差异较大,最清晰的方式是为每个Host单独创建Ingress资源,各自配置专属的注解:
# 针对myhost1.org的Ingress,使用长超时配置 apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: gn-ingress-myhost1 namespace: gn annotations: kubernetes.io/ingress.class: haproxy haproxy.org/backend-config-snippet: | timeout server 600s timeout client 600s timeout http-request 60s spec: rules: - host: "myhost1.org" http: paths: - path: / pathType: Prefix backend: service: name: myhost port: number: 80 # 针对myhost2.org的Ingress,使用短超时配置 apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: gn-ingress-myhost2 namespace: gn annotations: kubernetes.io/ingress.class: haproxy haproxy.org/backend-config-snippet: | timeout server 300s timeout client 300s timeout http-request 30s spec: rules: - host: "myhost2.org" http: paths: - path: / pathType: Prefix backend: service: name: myhost2 port: number: 80
方式2:同一Ingress中区分Host配置
如果想在同一个Ingress里管理多个Host,可以通过haproxy.org/route-config-snippet注解,结合ACL匹配特定Host来插入差异化配置:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: gn-ingress-multi namespace: gn annotations: kubernetes.io/ingress.class: haproxy haproxy.org/route-config-snippet: | # 匹配myhost1.org并设置长超时 acl host_myhost1 hdr(host) -i myhost1.org timeout server 600s if host_myhost1 timeout client 600s if host_myhost1 # 匹配myhost2.org并设置短超时 acl host_myhost2 hdr(host) -i myhost2.org timeout server 300s if host_myhost2 timeout client 300s if host_myhost2 spec: rules: - host: "myhost1.org" http: paths: - path: / pathType: Prefix backend: service: name: myhost port: number: 80 - host: "myhost2.org" http: paths: - path: / pathType: Prefix backend: service: name: myhost2 port: number: 80
二、Path级别配置调整
方式1:通过ACL匹配Path设置差异化配置
如果同一个Host下不同Path需要不同配置,可以用ACL匹配Path,结合haproxy.org/route-config-snippet注解实现:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: gn-ingress-path namespace: gn annotations: kubernetes.io/ingress.class: haproxy # 默认全局backend配置 haproxy.org/backend-config-snippet: | timeout server 600s timeout client 600s # 针对/api路径设置特殊超时 haproxy.org/route-config-snippet: | acl path_api path_beg /api timeout server 1200s if path_api timeout client 1200s if path_api spec: rules: - host: "myhost1.org" http: paths: - path: / pathType: Prefix backend: service: name: myhost port: number: 80 - path: /api pathType: Prefix backend: service: name: myhost-api port: number: 80
方式2:为Path绑定的Service添加专属注解
如果不同Path对应不同的Service,直接给目标Service添加HAProxy注解,就能实现该Path对应的配置隔离:
# 为myhost-api Service配置专属超时 apiVersion: v1 kind: Service metadata: name: myhost-api namespace: gn annotations: haproxy.org/backend-config-snippet: | timeout server 1200s timeout client 1200s spec: selector: app: myhost-api ports: - port: 80 targetPort: 8080
对应的Ingress正常配置Path即可:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: gn-ingress-path-service namespace: gn annotations: kubernetes.io/ingress.class: haproxy spec: rules: - host: "myhost1.org" http: paths: - path: / pathType: Prefix backend: service: name: myhost port: number: 80 - path: /api pathType: Prefix backend: service: name: myhost-api port: number: 80
内容的提问来源于stack exchange,提问作者dimus
相关产品推荐
相关产品推荐

