You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes 1.29.6升级后NGINX Ingress CORS配置失效求助

问题描述

通过Helm部署NGINX Ingress Controller的Kubernetes集群中,两个应用各有独立Ingress。升级Kubernetes到1.29.6后,App1向App2发起请求出现CORS错误,此前相同配置可正常运行。

已做的配置尝试:

  • 在Helm升级Ingress Controller时修改values.yaml配置全局CORS
  • 在App2的Ingress资源中添加CORS相关注释
  • 修改App1 Ingress注释时,添加引号或合并跨两行的cors-allow-header注释均提示“未做任何更改”

排查情况:

  • 检查Ingress NGINX Pod内配置文件,未发现CORS相关配置
  • Ingress NGINX Pod、App1及App2 Pod中均无CORS相关日志

App2 Ingress配置

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  annotations:
    cert-manager.io/cluster-issuer: dev-test-issuer
    kubectl.kubernetes.io/last-applied-configuration: |
      {"apiVersion":"networking.k8s.io/v1","kind":"Ingress","metadata":{"annotations":{"cert-manager.io/cluster-issuer":"dev-test-issuer","nginx.ingress.kubernetes.io/cors-allow-headers":"access-control-allow-origin, Origin, Authorization, Content-Type","nginx.ingress.kubernetes.io/cors-allow-methods":"POST, OPTIONS, DELETE, GET, PUT","nginx.ingress.kubernetes.io/cors-allow-origin":"*","nginx.ingress.kubernetes.io/enable-cors":"true"},"creationTimestamp":"2024-07-30T10:58:46Z","generation":1,"name":"myapplication-ingress","namespace":"dev-testing","resourceVersion":"341461422","uid":"4c498cf4-5aaa-4299-bc89-ca3e5c84b410"},"spec":{"ingressClassName":"nginx","rules":[{"host":"myapplication.dev-testing.k8s-apps.dev-test.int","http":{"paths":[{"backend":{"service":{"name":"myapplication-service","port":{"number":8096}}},"path":"/","pathType":"Prefix"}]}}],"tls":[{"hosts":["myapplication.dev-testing.k8s-apps.dev-test.int"],"secretName":"myapplication-ingress-tls"}],"status":{"loadBalancer":{}}}
    nginx.ingress.kubernetes.io/cors-allow-headers: access-control-allow-origin, Origin,
  Authorization, Content-Type
    nginx.ingress.kubernetes.io/cors-allow-methods: POST, OPTIONS, DELETE, GET, PUT
    nginx.ingress.kubernetes.io/cors-allow-origin: '*'
    nginx.ingress.kubernetes.io/enable-cors: "true"
  creationTimestamp: "2024-08-02T21:33:46Z"
  generation: 1
  name: myapplication-ingress
  namespace: dev-testing
  resourceVersion: "341465375"
  uid: 33a1fdc2-b3b0-50d6-baec-46b03ce8ed2f
spec:
  ingressClassName: nginx
  rules:
  - host: myapplication.dev-testing.k8s-apps.dev-test.int
    http:
      paths:
      - backend:
          service:
            name: myapplication-service
            port:
              number: 8016
        path: /
        pathType: Prefix
  tls:
  - hosts:
- myapplication.dev-testing.k8s-apps.dev-test.int
    secretName: myapplication-ingress-tls
status:
  loadBalancer: {}

NGINX Controller Helm values.yaml配置片段

...
entries:
  proxy-body-size: "2g"  # Maximum size of the client request body
  client-max-body-size: "2g"  # Maximum size of the client request body
  proxy-buffer-size: "2m"  # Buffer size for reading the first part of the response
  proxy-buffers: "16 2m"    # Number and size of buffers for reading the response
  proxy_busy_buffers_size: "2m"
  proxy_buffering: "off"
  enable-cors: "true"
  cors-allow-origin: "*"
  cors-allow-methods: "GET, PUT, POST, DELETE, PATCH, OPTIONS"
  cors-allow-headers: "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Authorization"
  large-client-header-buffers: "16 2m"  # Number and size of buffers for large client headers
...

解决步骤

1. 修复App2 Ingress的格式错误

从配置中可以看到两处关键YAML格式问题,这是导致Ingress Controller无法解析CORS配置的核心原因:

  • cors-allow-headers注释跨行时缩进错误,破坏了注释结构
  • tls.hosts列表项缩进错误,导致YAML解析失败

修正后的核心配置片段:

metadata:
  annotations:
    # 保留其他注释
    nginx.ingress.kubernetes.io/cors-allow-headers: "access-control-allow-origin, Origin, Authorization, Content-Type"
    nginx.ingress.kubernetes.io/cors-allow-methods: "POST, OPTIONS, DELETE, GET, PUT"
    nginx.ingress.kubernetes.io/cors-allow-origin: "*"
    nginx.ingress.kubernetes.io/enable-cors: "true"
spec:
  # 保留其他配置
  tls:
  - hosts:
    - myapplication.dev-testing.k8s-apps.dev-test.int
    secretName: myapplication-ingress-tls

注意:所有CORS注释值用双引号包裹,避免YAML解析歧义;禁止跨行配置时出现缩进混乱,优先使用单行配置。

2. 验证全局CORS配置是否生效

Helm values.yaml中的全局配置需要确认是否被正确注入Ingress Controller的ConfigMap:

  • 执行命令查看ConfigMap:kubectl get configmap <nginx-ingress-controller-configmap> -n <controller-namespace> -o yaml
  • 检查输出中是否包含enable-cors、cors-allow-origin等配置项
  • 若配置未生效,重新执行Helm升级:helm upgrade nginx-ingress ingress-nginx/ingress-nginx -n <namespace> -f values.yaml

3. 确认版本兼容性

Kubernetes 1.29.6升级后,需确保NGINX Ingress Controller版本与之兼容:

  • 查看当前Controller版本:kubectl get pods -n <namespace> -l app.kubernetes.io/name=ingress-nginx -o jsonpath='{.items[0].metadata.labels.app\.kubernetes\.io/version}'
  • 确保使用v1.10+版本(官方兼容Kubernetes 1.29的最低版本),若版本过低,升级Controller到兼容版本

4. 强制刷新Ingress Controller配置

Ingress资源更新后,Controller可能未自动重载配置,手动触发重启:

  • 删除Controller Pod强制重启:kubectl delete pods -n <namespace> -l app.kubernetes.io/name=ingress-nginx
  • 重启后进入Pod检查NGINX配置文件(路径通常为/etc/nginx/nginx.conf或/etc/nginx/conf.d/),确认是否生成CORS相关配置段

5. 检查请求路径匹配规则

确认App1发起的请求路径是否匹配App2 Ingress的path规则(当前为/前缀匹配):

  • 若请求有特殊前缀,需调整Ingress的path配置或添加额外路径规则

内容的提问来源于stack exchange,提问作者Rog Boy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 05:13:12