GKE Ingress中ExternalName服务的NEG网络端点未自动配置问题
问题分析与解决方案
核心问题原因
ExternalName类型的服务本质是DNS别名映射,它没有Pod选择器(selector),也不直接关联任何后端Pod实例。而GCE NEG(网络端点组)需要服务能直接关联Pod端点信息才能自动同步,ExternalName服务无法提供这些端点数据,因此NEG会处于空状态,必须手动添加端点才能工作——这是Kubernetes和GCE NEG的设计限制,和Ingress类型(GCE/Nginx)无关。
解决方案
方案1:ClusterIP服务+手动Endpoint(推荐,适配GCE NEG)
在app2-namespace创建一个无selector的ClusterIP服务,手动添加Endpoint指向app1-svc的ClusterIP。ClusterIP服务支持NEG自动同步端点,无需手动维护NEG:
# app2-namespace中的ClusterIP代理服务 apiVersion: v1 kind: Service metadata: name: proxy-to-app1-svc namespace: app2-namespace annotations: cloud.google.com/neg: '{"ingress": true}' spec: type: ClusterIP ports: - name: http port: 80 protocol: TCP targetPort: 8080 --- # 关联app1-svc的Endpoint apiVersion: v1 kind: Endpoints metadata: name: proxy-to-app1-svc namespace: app2-namespace subsets: - addresses: - ip: <app1-svc的ClusterIP> # 替换为app1-svc.app1-namespace.svc.cluster.local对应的IP ports: - name: http port: 8080 protocol: TCP
之后将Ingress的后端服务改为这个proxy-to-app1-svc即可,NEG会自动同步Endpoint中的IP作为端点。
方案2:GCE Ingress直接跨namespace引用服务
GCE Ingress支持直接跨namespace指定后端服务,无需中间的ExternalName服务。修改Ingress配置如下:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: ingress-ns2 namespace: app2-namespace annotations: kubernetes.io/ingress.allow-http: "false" cert-manager.io/cluster-issuer: letsencrypt kubernetes.io/ingress.class: gce-internal kubernetes.io/ingress.regional-static-ip-name: <ip-address> spec: tls: - secretName: ingress-ns2-tls hosts: - <app1.example.com> rules: - host: <app1.example.com> http: paths: - path: /* pathType: ImplementationSpecific backend: service: name: app1-svc port: number: 8080 namespace: app1-namespace # 直接指定目标服务的命名空间
确保app2-namespace有访问app1-svc的权限,GCE Ingress会自动创建关联app1-svc的NEG并同步其Pod端点。
方案3:Nginx Ingress适配ExternalName服务
如果使用Nginx Ingress,可以通过添加annotation让Ingress直接通过DNS解析ExternalName服务的地址转发流量,无需依赖NEG:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: ingress-ns2 namespace: app2-namespace annotations: kubernetes.io/ingress.allow-http: "false" cert-manager.io/cluster-issuer: letsencrypt kubernetes.io/ingress.class: nginx nginx.ingress.kubernetes.io/upstream-vhost: "app1-svc.app1-namespace.svc.cluster.local" spec: tls: - secretName: ingress-ns2-tls hosts: - <app1.example.com> rules: - host: <app1.example.com> http: paths: - path: /* pathType: ImplementationSpecific backend: service: name: external-svc-for-app1-svc port: number: 80
这种方式下Nginx会直接解析ExternalName对应的DNS地址转发流量,不需要维护NEG端点。
内容的提问来源于stack exchange,提问作者Aamir Five
相关产品推荐
相关产品推荐

