如何在F5 NGINX Ingress Controller中添加X-Original-Forwarded-For请求头
配置F5 NGINX Ingress Controller添加X-Original-Forwarded-For请求头
我使用的是F5 NGINX Ingress Controller(非Kubernetes社区版Ingress-nginx),已通过Virtual Server实现流量拆分,但生产环境中部分客户端依赖IP白名单机制,需要通过X-Original-Forwarded-For请求头才能正常转发请求,因此需在控制器中配置该请求头。
根据官方文档,Ingress层面的配置会对Virtual Server生效,我通过Helm结合env.yaml安装控制器,但尝试后未成功,以下是已尝试的配置及后续补充操作:
已尝试的Helm配置(env.yaml)
# Traffic split Nginx Ingress controller: replicaCount: 2 config: log-format-upstream: '$http_x_forwarded_for - $remote_addr - $remote_user [$time_local] "$request" $status $body_bytes_sent "$http_referer" "$http_user_agent" $request_length $request_time [$proxy_upstream_name] [$proxy_alternative_upstream_name] $upstream_addr $upstream_response_length $upstream_response_time $upstream_status $req_id' service: loadBalancerIP: "xxx.xxxx.xxxx" externalTrafficPolicy: "Local" annotations: service.beta.kubernetes.io/azure-load-balancer-resource-group: "xxxxxxx" nginx.org/location-snippets: | more_set_input_headers "X-Original-Forwarded-For: jatin";
安装使用的Helm命令
helm upgrade --install nginx-ingress nginx-stable/nginx-ingress \ --version 1.0.2 -n nginx-ingress --create-namespace \ --set controller.ingressClass.create=true \ --set controller.ingressClass.name=nginx-ingress \ --set controller.ingressClass.setAsDefaultIngress=false \ -f ./nginx-ingress/env/env.yaml
已尝试的Virtual Server配置
apiVersion: k8s.nginx.org/v1 kind: VirtualServer metadata: namespace: xxxxxx name: nginx-vs-traffic-split annotations: nginx.ingress.kubernetes.io/ingress.class: nginx-ingress spec: host: xxxxx.com upstreams: - name: xxxxx-a service: xxxx-a port: 80 - name: xxxx-b service: xxxx-b port: 80 - name: xxxx-c service: xxxx-c port: 80 routes: - path: / location-snippets: | add_header my-test-header test-value; splits: # The sum of the weights of all splits must be equal to 100 - weight: 33 action: pass: xxxxx-a - weight: 33 action: pass: xxxx-b - weight: 34 action: pass: xxxxx-c
补充尝试
我还参考了官方关于snippets的相关文档,尝试使用configuration-snippet和location-snippets进行配置,但均未成功。
正确配置方案
方案1:全局ConfigMap配置
将location-snippets从Service注解移至Controller的Config配置中,并使用正确指令传递真实客户端IP:
controller: replicaCount: 2 config: log-format-upstream: '$http_x_forwarded_for - $remote_addr - $remote_user [$time_local] "$request" $status $body_bytes_sent "$http_referer" "$http_user_agent" $request_length $request_time [$proxy_upstream_name] [$proxy_alternative_upstream_name] $upstream_addr $upstream_response_length $upstream_response_time $upstream_status $req_id' # 全局配置location片段 location-snippets: | # 若使用NGINX Plus或已安装headers-more模块 more_set_input_headers "X-Original-Forwarded-For: $http_x_forwarded_for"; # 若为开源版NGINX Ingress Controller,使用以下指令 # proxy_set_header X-Original-Forwarded-For $http_x_forwarded_for; service: loadBalancerIP: "xxx.xxxx.xxxx" externalTrafficPolicy: "Local" annotations: service.beta.kubernetes.io/azure-load-balancer-resource-group: "xxxxxxx"
方案2:Virtual Server局部配置
修正注解并在location片段中添加正确的请求头配置:
apiVersion: k8s.nginx.org/v1 kind: VirtualServer metadata: namespace: xxxxxx name: nginx-vs-traffic-split annotations: nginx.org/ingress.class: nginx-ingress # 注意:F5 NGINX使用此注解而非社区版注解 spec: host: xxxxx.com upstreams: - name: xxxxx-a service: xxxx-a port: 80 - name: xxxx-b service: xxxx-b port: 80 - name: xxxx-c service: xxxx-c port: 80 routes: - path: / location-snippets: | # 若使用NGINX Plus或已安装headers-more模块 more_set_input_headers "X-Original-Forwarded-For: $http_x_forwarded_for"; # 若为开源版,替换为以下指令 # proxy_set_header X-Original-Forwarded-For $http_x_forwarded_for; add_header my-test-header test-value; splits: - weight: 33 action: pass: xxxxx-a - weight: 33 action: pass: xxxx-b - weight: 34 action: pass: xxxxx-c
关键注意事项
- 注解错误:F5 NGINX Ingress Controller的Ingress类注解为
nginx.org/ingress.class,而非社区版的nginx.ingress.kubernetes.io/ingress.class,之前的注解错误会导致配置不生效。 - 指令选择:根据版本选择对应指令:
more_set_input_headers需NGINX Plus或headers-more-nginx-module支持;开源版默认使用proxy_set_header。 - 变量传递:需使用
$http_x_forwarded_for变量传递真实客户端的X-Forwarded-For值,而非固定字符串。
内容的提问来源于stack exchange,提问作者Jatin Mehrotra
相关产品推荐
相关产品推荐

