You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Cloudflare DNS,将HTTP/HTTPS流量导向GCP负载均衡器?

问题

我在GCP上托管一个单页Web应用,使用Cloudflare管理的子域名。之前已将应用部署到存储桶,通过Cloudflare的CNAME记录指向c.storage.googleapis.com提供访问。

现在需要为应用添加TLS支持,因此在存储桶前部署了负载均衡器。原本计划的流程是:

  • 配置负载均衡器将流量导向Web应用
  • 在Cloudflare添加A记录指向负载均衡器的IP

但发现GCP负载均衡器的HTTP和HTTPS转发规则分配了独立的IP地址,不知道该如何配置DNS才能让HTTP和HTTPS流量都正确路由到负载均衡器。

附上已完成的Terraform配置代码:

provider "google" {
  project = var.project_id
  region  = var.region
}

# Create the Cloud Storage bucket
resource "google_storage_bucket" "react_app" {
  name          = var.domain # Must be globally unique
  location      = var.region
  force_destroy = true # Automatically delete bucket and contents if needed

  website {
    main_page_suffix = "index.html"
    not_found_page   = "index.html"
  }
}

# Set public read permissions for the bucket
resource "google_storage_bucket_iam_member" "all_users" {
  bucket = google_storage_bucket.react_app.name
  role   = "roles/storage.objectViewer"
  member = "allUsers"
}


# Upload files to the bucket
resource "google_storage_bucket_object" "react_app_files" {
  for_each = fileset("${path.module}/../dist", "**") # Iterates over files in the 'dist' folder
  name     = each.value
  bucket   = google_storage_bucket.react_app.name
  source   = "${path.module}/../dist/${each.value}"
  content_type = lookup(
    {
      "html" = "text/html",
      "css"  = "text/css",
      "js"   = "application/javascript",
      "json" = "application/json",
      "png"  = "image/png",
      "jpg"  = "image/jpeg",
    },
    split(".", each.value)[length(split(".", each.value)) - 1],
    "application/octet-stream"
  )
}

# 2. Backend bucket for the load balancer
resource "google_compute_backend_bucket" "dashboard_backend" {
  name        = "dashboard-backend-bucket"
  bucket_name = google_storage_bucket.react_app.name
  enable_cdn  = true # Enable Cloud CDN for faster delivery
}

# 3. URL map to route traffic to the backend bucket
resource "google_compute_url_map" "dashboard_url_map" {
  name            = "dashboard-url-map"
  default_service = google_compute_backend_bucket.dashboard_backend.id
}

# 4. HTTP-to-HTTPS redirect
resource "google_compute_target_http_proxy" "dashboard_http_proxy" {
  name    = "dashboard-http-proxy"
  url_map = google_compute_url_map.dashboard_url_map.id
}

resource "google_compute_global_forwarding_rule" "http_forwarding_rule" {
  name       = "http-forwarding-rule"
  target     = google_compute_target_http_proxy.dashboard_http_proxy.id
  port_range = "80"
}

# 5. HTTPS proxy
resource "google_compute_managed_ssl_certificate" "dashboard_ssl" {
  name = "react-ssl-cert"
  managed {
    domains = [var.domain]
  }
}

resource "google_compute_target_https_proxy" "dashboard_https_proxy" {
  name             = "dashboard-https-proxy"
  url_map          = google_compute_url_map.dashboard_url_map.id
  ssl_certificates = [google_compute_managed_ssl_certificate.dashboard_ssl.id]
}

# 6. HTTPS forwarding rule
resource "google_compute_global_forwarding_rule" "https_forwarding_rule" {
  name       = "https-forwarding-rule"
  target     = google_compute_target_https_proxy.dashboard_https_proxy.id
  port_range = "443"
}
解决方案

1. 统一负载均衡器的IP地址

当前Terraform配置中,HTTP和HTTPS转发规则未指定固定IP,GCP自动分配了两个独立的临时IP。最佳做法是创建一个全局静态IP地址,让两个转发规则共享该IP:

在Terraform代码中添加全局静态IP资源:

# 全局静态IP地址,供HTTP和HTTPS转发规则共享
resource "google_compute_global_address" "lb_static_ip" {
  name = "lb-static-ip"
}

然后修改两个转发规则,指定address字段为该静态IP:

# 修改HTTP转发规则
resource "google_compute_global_forwarding_rule" "http_forwarding_rule" {
  name       = "http-forwarding-rule"
  target     = google_compute_target_http_proxy.dashboard_http_proxy.id
  port_range = "80"
  address    = google_compute_global_address.lb_static_ip.address # 添加此行
}

# 修改HTTPS转发规则
resource "google_compute_global_forwarding_rule" "https_forwarding_rule" {
  name       = "https-forwarding-rule"
  target     = google_compute_target_https_proxy.dashboard_https_proxy.id
  port_range = "443"
  address    = google_compute_global_address.lb_static_ip.address # 添加此行
}

执行terraform apply后,HTTP和HTTPS流量都会指向同一个静态IP。

2. 配置Cloudflare DNS

在Cloudflare的域名管理面板中:

  • 添加一条A记录:
    • 名称:你的子域名(如app.yourdomain.com)
    • 内容:上述全局静态IP的地址
    • TTL:选择「自动」
    • 代理状态:开启(橙色云图标,利用Cloudflare的CDN和安全功能)
  • 调整SSL/TLS模式为严格:因为GCP负载均衡器已经配置了受信任的托管SSL证书,严格模式会强制客户端与Cloudflare、Cloudflare与GCP之间都使用HTTPS加密。

备选方案(无需修改Terraform)

如果暂时不想调整Terraform配置,也可以在Cloudflare添加两条A记录,分别指向HTTP和HTTPS转发规则的IP地址。但这种方式会增加维护成本,IP变更时需要同步更新两条记录,因此推荐使用统一静态IP的方案。

内容的提问来源于stack exchange,提问作者sak

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 20:47:07