如何为GKE Ingress健康检查配置自定义响应码(Kibana认证场景)
在GKE中配置Kibana Ingress健康检查以接受302响应码
问题背景
Kibana启用认证后,健康检查路径/app/kibana会返回302重定向响应,而GKE默认的Ingress健康检查仅接受200状态码,导致健康检查失败。尝试在BackendConfig中添加expectedResponse: 302字段时,出现如下报错:
Error from server (BadRequest): error when creating "healthcheck-backendconfig.yml": BackendConfig in version "v1" cannot be handled as a BackendConfig: strict decoding error: unknown field "spec.healthCheck.expectedResponse"
解决方案
GKE的cloud.google.com/v1版本BackendConfig并不支持expectedResponse字段,正确的做法是使用healthyHttpResponseCodes字段来指定允许的健康响应码或响应码范围。
1. 修改BackendConfig配置
更新后的BackendConfig配置如下,这里配置接受所有2xx和3xx的响应码(覆盖所有非5xx的健康状态):
## healthcheck-backendconfig.yml ## apiVersion: cloud.google.com/v1 kind: BackendConfig metadata: name: healthcheck-backendconfig namespace: monit spec: logging: enable: true sampleRate: 0.1 healthCheck: checkIntervalSec: 600 timeoutSec: 40 healthyThreshold: 1 unhealthyThreshold: 3 type: HTTP requestPath: /app/kibana port: 5601 healthyHttpResponseCodes: - "2xx" - "3xx"
如果只需要接受302响应,也可以将数组改为["302"]。
2. 将BackendConfig绑定到Kibana Service
BackendConfig需要与对应的Service关联才能生效,修改Kibana的Service,添加cloud.google.com/backend-config注解:
apiVersion: v1 kind: Service metadata: name: kibana-kibana namespace: monit annotations: cloud.google.com/backend-config: '{"default": "healthcheck-backendconfig"}' spec: # 保留原Service的端口、选择器等配置 ports: - port: 5601 targetPort: 5601 selector: app.kubernetes.io/name: kibana
3. 应用配置并验证
执行以下命令应用配置:
kubectl apply -f healthcheck-backendconfig.yml kubectl apply -f kibana-service.yml
等待GKE更新Ingress的健康检查配置后,通过kubectl get ingress kibana-ingress查看Ingress状态,或在GCP控制台查看后端服务的健康检查状态,确认健康检查已正常通过。
内容的提问来源于stack exchange,提问作者bachr
相关产品推荐
相关产品推荐

