You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EKS中为Traefik配置NLB TLS终止遇问题求助

问题与解决方案:EKS中Traefik+NLB SSL终止异常

场景背景

在EKS集群通过Helm部署Traefik,期望NLB完成SSL终止,但访问Argo Workflows应用时,浏览器提示连接不安全,使用的是Traefik默认证书。查看NLB发现目标组指向TCP:443,且未配置证书,SSL终止未生效。

现有配置

Traefik Helm Values(已替换变量)

ingressClass:
    enabled: true
    isDefaultClass: true
    name: "traefik"
ingressRoute:
    dashboard:
        enabled: false
service:
    annotations:
        service.beta.kubernetes.io/aws-load-balancer-type: nlb
        service.beta.kubernetes.io/aws-load-balancer-ssl-cert: "arn:aws:acm:xxx:xxx:certificate/xxx" # 实际ACM证书ARN
        service.beta.kubernetes.io/aws-load-balancer-backend-protocol: http
        service.beta.kubernetes.io/aws-load-balancer-ssl-ports: websecure
providers:
    kubernetesIngress:
        enabled: true
        ingressClass: "traefik"
        publishedService: 
            enabled: true
externalTrafficPolicy: Local

Argo Workflows Helm Values(已替换变量)

server:
    ingress:
        enabled: true
        annotations:
            traefik.ingress.kubernetes.io/router.entrypoints: websecure
            external-dns.alpha.kubernetes.io/hostname: "example.host"
        hosts:
        - "example.host"

核心问题

  1. AWS NLB的aws-load-balancer-ssl-ports注解只识别数字端口号,原配置用websecure(Traefik的entrypoint名称)无法被AWS解析,导致NLB未在443端口启用SSL终止。
  2. Traefik的websecure端口默认监听HTTPS,但NLB终止SSL后后端应使用HTTP通信,端口映射不匹配。

修复步骤

1. 修正Traefik Service配置

更新Traefik的Helm Values,调整端口映射和AWS注解:

ingressClass:
    enabled: true
    isDefaultClass: true
    name: "traefik"
ingressRoute:
    dashboard:
        enabled: false
service:
    ports:
      web:
        port: 80
        targetPort: 80
        protocol: TCP
      websecure:
        port: 443
        targetPort: 8080 # 指向Traefik的HTTP入口,NLB已终止SSL,后端用HTTP
        protocol: TCP
    annotations:
        service.beta.kubernetes.io/aws-load-balancer-type: nlb
        service.beta.kubernetes.io/aws-load-balancer-ssl-cert: "arn:aws:acm:xxx:xxx:certificate/xxx"
        service.beta.kubernetes.io/aws-load-balancer-backend-protocol: http
        service.beta.kubernetes.io/aws-load-balancer-ssl-ports: "443" # 改用数字端口号
        # 可选:保留客户端源IP,需要Traefik启用ProxyProtocol
        service.beta.kubernetes.io/aws-load-balancer-target-group-attributes: "proxy_protocol_v2.enabled=true"
providers:
    kubernetesIngress:
        enabled: true
        ingressClass: "traefik"
        publishedService: 
            enabled: true
externalTrafficPolicy: Local
# 补充EntryPoints配置,确保websecure监听HTTP端口
entryPoints:
  web:
    address: ":80"
  websecure:
    address: ":8080"

2. (可选)启用Traefik ProxyProtocol(如果保留源IP)

如果添加了proxy_protocol_v2.enabled=true,需要在Traefik配置中启用ProxyProtocol:

additionalArguments:
  - "--entrypoints.web.proxyprotocol.trustedips=0.0.0.0/0"
  - "--entrypoints.websecure.proxyprotocol.trustedips=0.0.0.0/0"

3. 重新部署Traefik和Argo

执行Helm更新命令:

helm upgrade traefik traefik/traefik -f updated-traefik-values.yaml -n traefik
helm upgrade argo-workflows argo/argo-workflows -f argo-values.yaml -n argo

验证

  1. 登录AWS控制台,查看NLB的监听配置:确认443端口已关联ACM证书,SSL终止状态为启用。
  2. 查看NLB的目标组:确认协议为HTTP,目标端口为8080(对应Traefik的websecure entrypoint)。
  3. 访问example.host:浏览器应显示安全连接,证书为你配置的ACM证书。

内容的提问来源于stack exchange,提问作者Zu Jiry

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 07:45:15