You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure中API Gateway Ingress Controller路由重定向异常求助

问题描述

在Azure环境部署了两个微服务,运行及内部通信均正常,但通过网关IP结合Ingress路由访问时出现以下异常:

  • 仅默认路径可正常工作:若默认路径指向store微服务,则仅store可访问;指向admin则仅admin可访问,无法通过http://<ip-gateway>/store或/admin分别访问对应服务。
  • 访问http://<ip-gateway>/admin时,短暂显示admin微服务界面后,会立即被重定向至默认路径的store服务。
  • 调换Ingress中路径顺序后,问题依旧。

相关配置代码

Ingress配置

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: my-ingress
namespace: ecommerce
annotations:
kubernetes.io/ingress.class: azure/application-gateway
appgw.ingress.kubernetes.io/connection-draining: "true"
appgw.ingress.kubernetes.io/connection-draining-timeout: "60"
spec:
rules:
- http:
  paths:
  - path: /
    pathType: Prefix
    backend:
    service:
    name: ecommerce-store
    port:
    number: 3001
  - path: /admin
    pathType: Prefix
    backend:
    service:
    name: ecommerce-admin
    port:
    number: 3000

Store微服务Service配置

apiVersion: v1
kind: Service
metadata:
  name: ecommerce-store
  namespace: ecommerce
spec:
  selector:
    app: ecommerce-store
  ports:
    - name: http
      port: 3001
      targetPort: 3001
  type: ClusterIP

Admin微服务Service配置

apiVersion: v1
kind: Service
metadata:
  name: ecommerce-admin
  namespace: ecommerce
spec:
  selector:
    app: ecommerce-admin
  ports:
    - name: http
      port: 3000
      targetPort: 3000
  type: ClusterIP
解决方案

1. 调整Ingress路径匹配规则

Azure Application Gateway Ingress Controller(AGIC)采用前缀匹配,/会匹配所有请求路径,导致后续的/admin规则被覆盖。需调整路径顺序和格式,让更具体的路径优先匹配:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: my-ingress
  namespace: ecommerce
  annotations:
    kubernetes.io/ingress.class: azure/application-gateway
    appgw.ingress.kubernetes.io/connection-draining: "true"
    appgw.ingress.kubernetes.io/connection-draining-timeout: "60"
    # 关联路径重写规则集,解决服务内部重定向问题
    appgw.ingress.kubernetes.io/rewrite-rule-set: "admin-rewrite"
spec:
  rules:
  - http:
      paths:
      # 优先匹配/admin开头的所有子路径
      - path: /admin/*
        pathType: ImplementationSpecific
        backend:
          service:
            name: ecommerce-admin
            port:
              number: 3000
      # 匹配所有非/admin的请求
      - path: /*
        pathType: ImplementationSpecific
        backend:
          service:
            name: ecommerce-store
            port:
              number: 3001

2. 创建路径重写规则集

admin服务可能会将请求重定向到根路径(/),导致AGIC转发至store服务。通过RewriteRuleSet修正请求路径:

apiVersion: networking.azure.com/v1
kind: RewriteRuleSet
metadata:
  name: admin-rewrite
  namespace: ecommerce
spec:
  rewriteRules:
  - name: admin-path-rewrite
    ruleSequence: 100
    conditions:
    - variable: Request_URI
      pattern: "^/admin/(.*)"
      ignoreCase: true
    actionSet:
      urlConfiguration:
        path: "/{R:1}"
        rewriteRuleSetActionType: Rewrite

3. 检查微服务内部重定向逻辑

确认admin微服务是否存在自动重定向到根路径的配置:

  • 前端框架(如React/Vue)的路由是否设置了基准路径(baseUrl)为/admin
  • 后端服务的响应头Location是否携带/admin前缀
    若存在此类配置,需修改服务使其保持/admin路径前缀,避免跨服务重定向。

4. 验证AGIC同步状态

执行命令查看AGIC日志,确认配置已同步到Azure Application Gateway:

kubectl logs -n kube-system deployment/azure-application-gateway-ingress-controller -f

检查日志中是否有Successfully applied App Gateway config类的成功提示,无同步报错。

内容的提问来源于stack exchange,提问作者Ventana

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 00:06:11