You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在F5 NGINX Ingress Controller中添加X-Original-Forwarded-For请求头

配置F5 NGINX Ingress Controller添加X-Original-Forwarded-For请求头

我使用的是F5 NGINX Ingress Controller(非Kubernetes社区版Ingress-nginx),已通过Virtual Server实现流量拆分,但生产环境中部分客户端依赖IP白名单机制,需要通过X-Original-Forwarded-For请求头才能正常转发请求,因此需在控制器中配置该请求头。

根据官方文档,Ingress层面的配置会对Virtual Server生效,我通过Helm结合env.yaml安装控制器,但尝试后未成功,以下是已尝试的配置及后续补充操作:

已尝试的Helm配置(env.yaml)

# Traffic split Nginx Ingress 
controller:
  replicaCount: 2
  config:
    log-format-upstream: '$http_x_forwarded_for - $remote_addr - $remote_user [$time_local] "$request" $status $body_bytes_sent "$http_referer" "$http_user_agent" $request_length $request_time [$proxy_upstream_name] [$proxy_alternative_upstream_name] $upstream_addr $upstream_response_length $upstream_response_time $upstream_status $req_id'
  service:
    loadBalancerIP: "xxx.xxxx.xxxx"
    externalTrafficPolicy: "Local"
    annotations:
      service.beta.kubernetes.io/azure-load-balancer-resource-group: "xxxxxxx"
      nginx.org/location-snippets: |
         more_set_input_headers "X-Original-Forwarded-For: jatin";

安装使用的Helm命令

helm upgrade --install nginx-ingress nginx-stable/nginx-ingress \
  --version 1.0.2 -n nginx-ingress --create-namespace \
  --set controller.ingressClass.create=true \
  --set controller.ingressClass.name=nginx-ingress \
  --set controller.ingressClass.setAsDefaultIngress=false \
  -f ./nginx-ingress/env/env.yaml

已尝试的Virtual Server配置

apiVersion: k8s.nginx.org/v1
kind: VirtualServer
metadata:
  namespace: xxxxxx
  name: nginx-vs-traffic-split
  annotations:
    nginx.ingress.kubernetes.io/ingress.class: nginx-ingress

spec:
  host: xxxxx.com
  upstreams:
  - name: xxxxx-a
    service: xxxx-a
    port: 80
  - name: xxxx-b
    service: xxxx-b
    port: 80
  - name: xxxx-c
    service: xxxx-c
    port: 80
  routes:
  - path: /
    location-snippets: |
      add_header my-test-header test-value;   
    splits:
    # The sum of the weights of all splits must be equal to 100
    - weight: 33
      action:
        pass: xxxxx-a
    - weight: 33
      action:
        pass: xxxx-b
    - weight: 34
      action:
        pass: xxxxx-c 

补充尝试

我还参考了官方关于snippets的相关文档,尝试使用configuration-snippet和location-snippets进行配置,但均未成功。


正确配置方案

方案1:全局ConfigMap配置

将location-snippets从Service注解移至Controller的Config配置中,并使用正确指令传递真实客户端IP:

controller:
  replicaCount: 2
  config:
    log-format-upstream: '$http_x_forwarded_for - $remote_addr - $remote_user [$time_local] "$request" $status $body_bytes_sent "$http_referer" "$http_user_agent" $request_length $request_time [$proxy_upstream_name] [$proxy_alternative_upstream_name] $upstream_addr $upstream_response_length $upstream_response_time $upstream_status $req_id'
    # 全局配置location片段
    location-snippets: |
      # 若使用NGINX Plus或已安装headers-more模块
      more_set_input_headers "X-Original-Forwarded-For: $http_x_forwarded_for";
      # 若为开源版NGINX Ingress Controller,使用以下指令
      # proxy_set_header X-Original-Forwarded-For $http_x_forwarded_for;
  service:
    loadBalancerIP: "xxx.xxxx.xxxx"
    externalTrafficPolicy: "Local"
    annotations:
      service.beta.kubernetes.io/azure-load-balancer-resource-group: "xxxxxxx"

方案2:Virtual Server局部配置

修正注解并在location片段中添加正确的请求头配置:

apiVersion: k8s.nginx.org/v1
kind: VirtualServer
metadata:
  namespace: xxxxxx
  name: nginx-vs-traffic-split
  annotations:
    nginx.org/ingress.class: nginx-ingress  # 注意:F5 NGINX使用此注解而非社区版注解

spec:
  host: xxxxx.com
  upstreams:
  - name: xxxxx-a
    service: xxxx-a
    port: 80
  - name: xxxx-b
    service: xxxx-b
    port: 80
  - name: xxxx-c
    service: xxxx-c
    port: 80
  routes:
  - path: /
    location-snippets: |
      # 若使用NGINX Plus或已安装headers-more模块
      more_set_input_headers "X-Original-Forwarded-For: $http_x_forwarded_for";
      # 若为开源版,替换为以下指令
      # proxy_set_header X-Original-Forwarded-For $http_x_forwarded_for;
      add_header my-test-header test-value;   
    splits:
    - weight: 33
      action:
        pass: xxxxx-a
    - weight: 33
      action:
        pass: xxxx-b
    - weight: 34
      action:
        pass: xxxxx-c 

关键注意事项

  1. 注解错误:F5 NGINX Ingress Controller的Ingress类注解为nginx.org/ingress.class,而非社区版的nginx.ingress.kubernetes.io/ingress.class,之前的注解错误会导致配置不生效。
  2. 指令选择:根据版本选择对应指令:more_set_input_headers需NGINX Plus或headers-more-nginx-module支持;开源版默认使用proxy_set_header。
  3. 变量传递:需使用$http_x_forwarded_for变量传递真实客户端的X-Forwarded-For值,而非固定字符串。

内容的提问来源于stack exchange,提问作者Jatin Mehrotra

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 17:22:15