You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Ingress同时对接GKE与Cloud Run?(Autopilot集群)

可以配置Ingress(Gateway API)同时对接GKE与Cloud Run

完全可以实现你描述的架构,核心是使用GKE Gateway API(替代传统Ingress资源)来统一路由请求到GKE内部服务和Cloud Run服务,和Cloud Deploy无关(Cloud Deploy是持续部署工具,不负责流量路由)。以下是具体实现方案和Autopilot集群的配置注意事项:

实现核心逻辑

通过Gateway API的HTTPRoute资源定义路由规则,分别将不同路径/域名的请求转发到GKE Service和Cloud Run服务:

  • 对于GKE内部服务:直接引用集群内的Service资源即可
  • 对于Cloud Run服务:通过创建ExternalName类型的Kubernetes Service,指向Cloud Run服务的公网域名,再在HTTPRoute中引用该Service

GKE Autopilot集群的特殊配置

Autopilot集群默认支持Gateway API,但需要完成以下两步配置:

  1. 启用Gateway API组件
    执行命令开启集群的Gateway API支持:
    gcloud container clusters update YOUR_CLUSTER_NAME --region YOUR_REGION --enable-gateway-api
    
  2. 配置Cloud Run访问权限
    给GKE节点的服务账号授予Cloud Run Invoker角色,允许集群网关调用Cloud Run服务:
    gcloud projects add-iam-policy-binding YOUR_PROJECT_ID \
      --member "serviceAccount:PROJECT_NUMBER-compute@developer.gserviceaccount.com" \
      --role "roles/run.invoker"
    

示例配置文件

1. 创建GatewayClass(使用Google托管的L7网关)

apiVersion: gateway.networking.k8s.io/v1
kind: GatewayClass
metadata:
  name: gke-managed-gateway
spec:
  controllerName: "gateway.networking.k8s.io/gke-l7-gateway"

2. 创建Gateway(暴露公网入口)

apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
  name: multi-service-gateway
  namespace: default
spec:
  gatewayClassName: gke-managed-gateway
  listeners:
  - name: http
    port: 80
    protocol: HTTP
    hostname: "your-domain.com"

3. 创建Cloud Run对应的ExternalName Service

apiVersion: v1
kind: Service
metadata:
  name: cloud-run-proxy
  namespace: default
spec:
  type: ExternalName
  externalName: your-cloud-run-service-abcdefghij-uc.a.run.app

4. 创建HTTPRoute路由规则

apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: multi-service-route
  namespace: default
spec:
  parentRefs:
  - name: multi-service-gateway
  hostnames:
  - "your-domain.com"
  rules:
  # 路由到GKE内部服务
  - matches:
    - path:
        type: PathPrefix
        value: /gke-app
    backendRefs:
    - name: your-gke-service
      port: 80
  # 路由到Cloud Run服务
  - matches:
    - path:
        type: PathPrefix
        value: /cloud-run-app
    backendRefs:
    - name: cloud-run-proxy
      port: 443

关键注意事项

  • 确保Cloud Run服务的访问策略允许来自GKE网关的流量,除了IAM权限配置,也可以在Cloud Run设置中允许公网访问(如果不需要严格限制来源)
  • Autopilot集群会自动管理负载均衡器的生命周期,不需要手动配置节点端口或负载均衡器权限
  • Gateway API是Kubernetes官方推荐的下一代路由方案,比传统Ingress更灵活,适合跨服务(GKE/Cloud Run)的路由场景

内容的提问来源于stack exchange,提问作者Lukáš Prudil

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 10:52:35