You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

部署AGIC+AKS集群时遇502错误,求排查与解决方法

AKS集成AGIC后502 Bad Gateway问题排查与修复(结合Let's Encrypt证书配置)

核心问题排查点

1. AGIC未部署或配置异常

你的操作流程中缺失AGIC安装步骤——AGIC是AKS Ingress与Azure Application Gateway的同步核心,未部署的话Application Gateway无法获取AKS服务配置,直接返回502。
执行以下命令确认AGIC状态:

kubectl get pods -n kube-system -l app=azure-application-gateway-ingress-controller

若无任何Pod输出,说明AGIC未安装。

2. 后端服务健康检查失败

即使AGIC已部署,若aspnetapp服务不可用或健康检查不通过,Application Gateway会标记后端为不可用,返回502:

  • 检查服务与Pod状态:
    kubectl get pods,svc -n <你的应用命名空间>
    
  • 通过Azure门户查看对应Application Gateway的后端池健康状态,确认是否有正常的后端节点。

3. Ingress资源配置错误

AGIC仅处理带有指定注解的Ingress资源,若配置缺失或错误,会导致规则无法同步:

  • 检查Ingress配置:
    kubectl get ingress -n <你的应用命名空间>
    kubectl describe ingress <ingress名称> -n <你的应用命名空间>
    

需确认Ingress包含kubernetes.io/ingress.class: azure/application-gateway注解,且正确关联后端服务端口。

4. Cert-manager/ClusterIssuer配置异常

若Ingress配置了TLS但证书未签发,AGIC无法配置Application Gateway的HTTPS规则,可能引发502:

  • 检查cert-manager组件状态:
    kubectl get pods -n cert-manager
    
  • 检查ClusterIssuer与证书状态:
    kubectl get clusterissuer
    kubectl describe clusterissuer <你的ClusterIssuer名称>
    kubectl get certificates -n <你的应用命名空间>
    

修复方案与完整配置流程

1. 安装并配置AGIC

通过Helm安装AGIC(需预先创建有权限管理Application Gateway的服务主体或使用AKS托管身份):

helm repo add application-gateway-kubernetes-ingress https://appgwingress.blob.core.windows.net/ingress-azure-helm-package/
helm repo update

helm install ingress-azure application-gateway-kubernetes-ingress/ingress-azure \
  --namespace kube-system \
  --set appgw.name=<你的Application Gateway名称> \
  --set appgw.resourceGroup=<你的资源组名称> \
  --set appgw.subscriptionId=<你的订阅ID> \
  --set armAuth.type=servicePrincipal \
  --set armAuth.secretJSON='{"clientId": "<SPN客户端ID>", "clientSecret": "<SPN密钥>", "tenantId": "<租户ID>"}' \
  --set rbac.enabled=true

2. 修正Ingress资源配置

确保Ingress包含AGIC注解与cert-manager关联配置,示例如下:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: aspnetapp-ingress
  namespace: default
  annotations:
    kubernetes.io/ingress.class: azure/application-gateway
    cert-manager.io/cluster-issuer: <你的ClusterIssuer名称>
    # 若应用有自定义健康检查路径,添加以下注解
    # appgw.ingress.kubernetes.io/health-probe-path: /healthz
spec:
  tls:
  - hosts:
    - aspnetapp.xxx.com
    secretName: aspnetapp-tls
  rules:
  - host: aspnetapp.xxx.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: aspnetapp-service
            port:
              number: 80

3. 验证后端服务可用性

  • 端口转发验证服务:
    kubectl port-forward svc/aspnetapp-service 8080:80 -n <你的应用命名空间>
    

访问http://localhost:8080确认服务正常响应。

  • 调整Application Gateway健康探针:若应用有自定义健康检查端点,在Ingress中添加对应注解同步配置。

4. 确认证书签发状态

等待cert-manager完成证书签发,当状态变为Ready时,AGIC会自动将证书同步到Application Gateway:

kubectl get certificates -n <你的应用命名空间>

公网访问验证

将域名aspnetapp.xxx.com解析到Application Gateway的公网IP,访问https://aspnetapp.xxx.com确认服务正常响应。

内容的提问来源于stack exchange,提问作者Senior Pomidor

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 22:20:58