You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从同VPC内的VM访问GKE内部Knative服务

问题分析与修复步骤

1. 用正确的Host头访问内部服务

调用helloworld-internal时,必须使用集群内部的Host名,不能用外部服务的URL。先获取内部服务的Host:

kubectl get ksvc helloworld-internal -o jsonpath='{.status.url}'

返回值类似 http://helloworld-internal.default.svc.cluster.local,对应的Host头就是 helloworld-internal.default.svc.cluster.local。访问命令要改成:

curl -H "Host: helloworld-internal.default.svc.cluster.local" http://<ilb-ip>

2. 给内部服务配置Gateway路由规则

默认Gateway只会路由允许外部入口的服务,得给内部服务加专属路由:
创建internal-route.yaml:

apiVersion: serving.knative.dev/v1
kind: Route
metadata:
  name: helloworld-internal-route
  namespace: default
spec:
  traffic:
  - revisionName: helloworld-internal-<你的修订ID> # 用kubectl get revisions查实际ID
    percent: 100
  gateway: <你的Gateway名称> # 替换成你创建的Gateway名字

应用配置:

kubectl apply -f internal-route.yaml

3. 检查ILB后端是否包含内部服务的Pod

确认ILB对应的服务(比如istio-ingressgateway)的后端端点里有helloworld-internal的Pod IP:

kubectl describe svc <ILB服务名> -n <网关命名空间> # 一般是istio-system

如果没找到内部服务的Pod IP,检查Knative Ingress是否为内部服务生成了Endpoint,或者确认cluster-local注解没有阻止ILB的内部流量(ILB属于集群内部访问,理论上应该允许)。

4. 补全内部服务的防火墙规则

除了15017端口,还得开放Knative服务默认用的80/443端口,允许VM子网和集群IP范围之间的流量:

gcloud compute firewall-rules create allow-internal-knative \
  --network=<你的VPC名> \
  --allow=tcp:80,tcp:443 \
  --source-ranges=<VM子网CIDR>,<集群Pod CIDR>,<集群服务CIDR> \
  --target-tags=<集群节点标签> # 用gcloud container clusters describe查节点标签

5. 完成托管Cloud Run的VPC访问配置(最终目标)

要让托管Cloud Run调用内部GKE Knative服务,还需要:

  • 给Cloud Run服务开启直接VPC访问,选择和GKE集群同VPC的子网,或者配置VPC连接器。
  • 确保Cloud Run的服务账号有访问GKE内部资源的权限,比如roles/container.developer。
  • 调用时用集群内部的Host名(比如helloworld-internal.default.svc.cluster.local),确保VPC路由能通到集群的Pod/服务IP范围。

内容的提问来源于stack exchange,提问作者Zaphod

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 16:13:09