You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

MicroK8s Ingress插件修改allow-snippet-annotations配置失败问题

在MicroK8s中启用Nginx Ingress Snippets的正确方法

为什么会出现“无效TCP端口号”的错误?

你修改的nginx-ingress-tcp-microk8s-conf是TCP端口转发专用的ConfigMap,它的作用是定义Ingress Controller需要代理的TCP端口映射,键值对必须遵循端口号: 命名空间/服务名:端口号的格式。你把allow-snippet-annotations添加到这个ConfigMap中,会被Controller当成TCP端口号解析,因此触发错误提示。

正确启用Snippets的步骤

MicroK8s的Nginx Ingress Controller主配置存放在nginx-load-balancer-microk8s-conf这个ConfigMap中,按以下步骤操作:

  1. 编辑正确的ConfigMap:

    kubectl edit configmap nginx-load-balancer-microk8s-conf -n ingress
    

    在data字段下添加配置:

    data:
      allow-snippet-annotations: "true"
    

    保存并退出编辑器。

  2. 重启Ingress Controller Pod:
    让新配置生效,需要重启Ingress Controller的Deployment:

    kubectl rollout restart deployment nginx-ingress-microk8s-controller -n ingress
    
  3. 验证配置生效:
    重新应用你的测试Ingress配置(补充完整spec部分示例如下):

    ---
    apiVersion: networking.k8s.io/v1
    kind: Ingress
    metadata:
      name: foo-ingress-bar
      namespace: foo
      annotations:
        cert-manager.io/cluster-issuer: letsencrypt
        nginx.ingress.kubernetes.io/server-snippet: deny all;
    spec:
      rules:
      - host: your-subdomain.example.com
        http:
          paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: your-service-name
                port:
                  number: 80
      tls:
      - hosts:
        - your-subdomain.example.com
        secretName: your-tls-secret
    

    访问对应的域名,应该会被拒绝,说明snippet注解已生效。

内容的提问来源于stack exchange,提问作者porkbrain

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 23:30:11