部署AGIC+AKS集群时遇502错误,求排查与解决方法
核心问题排查点
1. AGIC未部署或配置异常
你的操作流程中缺失AGIC安装步骤——AGIC是AKS Ingress与Azure Application Gateway的同步核心,未部署的话Application Gateway无法获取AKS服务配置,直接返回502。
执行以下命令确认AGIC状态:
kubectl get pods -n kube-system -l app=azure-application-gateway-ingress-controller
若无任何Pod输出,说明AGIC未安装。
2. 后端服务健康检查失败
即使AGIC已部署,若aspnetapp服务不可用或健康检查不通过,Application Gateway会标记后端为不可用,返回502:
- 检查服务与Pod状态:
kubectl get pods,svc -n <你的应用命名空间> - 通过Azure门户查看对应Application Gateway的后端池健康状态,确认是否有正常的后端节点。
3. Ingress资源配置错误
AGIC仅处理带有指定注解的Ingress资源,若配置缺失或错误,会导致规则无法同步:
- 检查Ingress配置:
kubectl get ingress -n <你的应用命名空间> kubectl describe ingress <ingress名称> -n <你的应用命名空间>
需确认Ingress包含kubernetes.io/ingress.class: azure/application-gateway注解,且正确关联后端服务端口。
4. Cert-manager/ClusterIssuer配置异常
若Ingress配置了TLS但证书未签发,AGIC无法配置Application Gateway的HTTPS规则,可能引发502:
- 检查cert-manager组件状态:
kubectl get pods -n cert-manager - 检查ClusterIssuer与证书状态:
kubectl get clusterissuer kubectl describe clusterissuer <你的ClusterIssuer名称> kubectl get certificates -n <你的应用命名空间>
修复方案与完整配置流程
1. 安装并配置AGIC
通过Helm安装AGIC(需预先创建有权限管理Application Gateway的服务主体或使用AKS托管身份):
helm repo add application-gateway-kubernetes-ingress https://appgwingress.blob.core.windows.net/ingress-azure-helm-package/ helm repo update helm install ingress-azure application-gateway-kubernetes-ingress/ingress-azure \ --namespace kube-system \ --set appgw.name=<你的Application Gateway名称> \ --set appgw.resourceGroup=<你的资源组名称> \ --set appgw.subscriptionId=<你的订阅ID> \ --set armAuth.type=servicePrincipal \ --set armAuth.secretJSON='{"clientId": "<SPN客户端ID>", "clientSecret": "<SPN密钥>", "tenantId": "<租户ID>"}' \ --set rbac.enabled=true
2. 修正Ingress资源配置
确保Ingress包含AGIC注解与cert-manager关联配置,示例如下:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: aspnetapp-ingress namespace: default annotations: kubernetes.io/ingress.class: azure/application-gateway cert-manager.io/cluster-issuer: <你的ClusterIssuer名称> # 若应用有自定义健康检查路径,添加以下注解 # appgw.ingress.kubernetes.io/health-probe-path: /healthz spec: tls: - hosts: - aspnetapp.xxx.com secretName: aspnetapp-tls rules: - host: aspnetapp.xxx.com http: paths: - path: / pathType: Prefix backend: service: name: aspnetapp-service port: number: 80
3. 验证后端服务可用性
- 端口转发验证服务:
kubectl port-forward svc/aspnetapp-service 8080:80 -n <你的应用命名空间>
访问http://localhost:8080确认服务正常响应。
- 调整Application Gateway健康探针:若应用有自定义健康检查端点,在Ingress中添加对应注解同步配置。
4. 确认证书签发状态
等待cert-manager完成证书签发,当状态变为Ready时,AGIC会自动将证书同步到Application Gateway:
kubectl get certificates -n <你的应用命名空间>
公网访问验证
将域名aspnetapp.xxx.com解析到Application Gateway的公网IP,访问https://aspnetapp.xxx.com确认服务正常响应。
内容的提问来源于stack exchange,提问作者Senior Pomidor

