Azure中API Gateway Ingress Controller路由重定向异常求助
问题描述
在Azure环境部署了两个微服务,运行及内部通信均正常,但通过网关IP结合Ingress路由访问时出现以下异常:
- 仅默认路径可正常工作:若默认路径指向store微服务,则仅store可访问;指向admin则仅admin可访问,无法通过
http://<ip-gateway>/store或/admin分别访问对应服务。 - 访问
http://<ip-gateway>/admin时,短暂显示admin微服务界面后,会立即被重定向至默认路径的store服务。 - 调换Ingress中路径顺序后,问题依旧。
相关配置代码
Ingress配置
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: my-ingress namespace: ecommerce annotations: kubernetes.io/ingress.class: azure/application-gateway appgw.ingress.kubernetes.io/connection-draining: "true" appgw.ingress.kubernetes.io/connection-draining-timeout: "60" spec: rules: - http: paths: - path: / pathType: Prefix backend: service: name: ecommerce-store port: number: 3001 - path: /admin pathType: Prefix backend: service: name: ecommerce-admin port: number: 3000
Store微服务Service配置
apiVersion: v1 kind: Service metadata: name: ecommerce-store namespace: ecommerce spec: selector: app: ecommerce-store ports: - name: http port: 3001 targetPort: 3001 type: ClusterIP
Admin微服务Service配置
apiVersion: v1 kind: Service metadata: name: ecommerce-admin namespace: ecommerce spec: selector: app: ecommerce-admin ports: - name: http port: 3000 targetPort: 3000 type: ClusterIP
解决方案
1. 调整Ingress路径匹配规则
Azure Application Gateway Ingress Controller(AGIC)采用前缀匹配,/会匹配所有请求路径,导致后续的/admin规则被覆盖。需调整路径顺序和格式,让更具体的路径优先匹配:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: my-ingress namespace: ecommerce annotations: kubernetes.io/ingress.class: azure/application-gateway appgw.ingress.kubernetes.io/connection-draining: "true" appgw.ingress.kubernetes.io/connection-draining-timeout: "60" # 关联路径重写规则集,解决服务内部重定向问题 appgw.ingress.kubernetes.io/rewrite-rule-set: "admin-rewrite" spec: rules: - http: paths: # 优先匹配/admin开头的所有子路径 - path: /admin/* pathType: ImplementationSpecific backend: service: name: ecommerce-admin port: number: 3000 # 匹配所有非/admin的请求 - path: /* pathType: ImplementationSpecific backend: service: name: ecommerce-store port: number: 3001
2. 创建路径重写规则集
admin服务可能会将请求重定向到根路径(/),导致AGIC转发至store服务。通过RewriteRuleSet修正请求路径:
apiVersion: networking.azure.com/v1 kind: RewriteRuleSet metadata: name: admin-rewrite namespace: ecommerce spec: rewriteRules: - name: admin-path-rewrite ruleSequence: 100 conditions: - variable: Request_URI pattern: "^/admin/(.*)" ignoreCase: true actionSet: urlConfiguration: path: "/{R:1}" rewriteRuleSetActionType: Rewrite
3. 检查微服务内部重定向逻辑
确认admin微服务是否存在自动重定向到根路径的配置:
- 前端框架(如React/Vue)的路由是否设置了基准路径(
baseUrl)为/admin - 后端服务的响应头
Location是否携带/admin前缀
若存在此类配置,需修改服务使其保持/admin路径前缀,避免跨服务重定向。
4. 验证AGIC同步状态
执行命令查看AGIC日志,确认配置已同步到Azure Application Gateway:
kubectl logs -n kube-system deployment/azure-application-gateway-ingress-controller -f
检查日志中是否有Successfully applied App Gateway config类的成功提示,无同步报错。
内容的提问来源于stack exchange,提问作者Ventana
相关产品推荐
相关产品推荐

