You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GKE集群部署GCE外部Ingress报错:缺失资源或配置无效

在GKE集群通过Helm部署GCE外部Ingress时持续遇资源缺失错误

部署过程中反复触发以下错误:

Missing one or more resources. If resource creation takes longer than expected, you might have an invalid configuration.

相关配置详情

Deployment.yaml

apiVersion: apps/v1
kind: Deployment
metadata:
  name: service-backend
spec:
  replicas: 1
  selector:
    matchLabels:
      app: service-backend
  template:
    metadata:
      labels:
        app: service-backend
        date: "{{ now | unixEpoch }}"
    spec:
      containers:
        - name: service-backend
          image: "{{ .Values.image.repository }}@sha256:{{ .Values.image.sha | default .Chart.AppVersion }}"
          imagePullPolicy: {{ .Values.image.pullPolicy }}
          ports:
            - name: http
              containerPort: 3000
              protocol: TCP
          resources:
            {{- toYaml .Values.resources | nindent 12 }}
          env:
            {{- toYaml .Values.env | nindent 12 }}

Service.yaml

apiVersion: v1
kind: Service
metadata:
  name: app-service
  annotations:
    cloud.google.com/neg: '{"ingress": true}'
spec:
  type: NodePort
  ports:
    - port: 80
      targetPort: 3000
      protocol: TCP
      name: http
  selector:
    app: service-backend

Ingress.yaml

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: http-ingress-staging
  annotations:
    kubernetes.io/ingress.allow-http: "true"
    kubernetes.io/ingress.global-static-ip-name: my-staging-ip
spec:
  ingressClassName: "gce"
  rules:
    - host: staging-api.myhost.com
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: app-service
                port:
                  number: 80

当前状态

  • Ingress无法正常路由流量
  • 频繁出现资源缺失或超时类错误
  • Ingress地址为空
  • Ingress未绑定指定静态IP
  • Service、Pod等其他组件运行状态正常

已尝试操作

  • 验证后端服务与Pod的健康状态均正常
  • 检查Ingress YAML文件的语法与配置项
  • 通过Helm卸载并重新部署整个版本
  • 重建整个GKE集群

排查与解决步骤

  1. 检查静态IP配置

    • 确认my-staging-ip全局静态IP已创建,且所属区域与GKE集群一致
    • 验证IP类型为全局(GCE外部Ingress不支持区域静态IP)
    • 执行gcloud compute addresses list查看IP状态,确保未被其他资源占用
  2. 修正Service与NEG配置

    • 使用cloud.google.com/neg: '{"ingress": true}'注解时,Service类型可改为ClusterIP(GCE Ingress会自动创建NEG,无需NodePort)
    • 确认Service的selector与Deployment的Pod标签完全匹配(当前配置app: service-backend匹配,但需检查Pod实际标签是否一致)
  3. 检查集群与控制器权限

    • 确认GKE集群已启用HTTP Load Balancing组件(默认启用,若手动关闭需重新开启)
    • 检查节点池服务账号是否拥有roles/compute.loadBalancerAdmin等权限,确保Ingress控制器能创建GCP负载均衡资源
  4. 查看Ingress控制器日志

    • 执行kubectl logs -n kube-system -l app=glbc查看GCE Ingress控制器(glbc)日志,定位具体缺失的资源(如后端服务、健康检查、转发规则等)
  5. 修复Helm模板问题

    • 移除Deployment中date: "{{ now | unixEpoch }}"动态标签(会导致Pod频繁重建,影响NEG健康检查同步),或改为固定值
    • 验证{{ .Values.image.sha | default .Chart.AppVersion }}渲染结果,确保镜像能正常拉取
  6. 验证域名解析

    • 确认staging-api.myhost.com已正确解析到指定静态IP,Ingress规则中的host需与解析记录完全一致

内容的提问来源于stack exchange,提问作者Suraj Auwal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 11:54:57