You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AKS中配置Nginx Ingress使API同时响应80与443端口

解决AKS中Ingress同时开放80和443端口的问题

你之前的Ingress配置被截断,是因为networking.k8s.io/v1版本的Ingress规范里,spec.rules下并没有https字段,这个写法不符合K8s API定义,所以提交后无效部分被自动丢弃。以下是正确的配置方案:

1. 修正Service命名空间(先解决基础错误)

你的Service和Ingress之前用了不同的命名空间(myAppe-main vs myApp-main),先统一命名空间,避免服务找不到的问题:

apiVersion: v1
kind: Service
metadata:
  name: myApp-service
  namespace: myApp-main
  labels:
    app: myApp-service
spec:
  ports:
    - port: 80
      targetPort: 80
      protocol: TCP
      name: http
    - port: 443
      targetPort: 443
      protocol: TCP
      name: https
  selector:
    app: myApp-deploy

2. 正确配置Ingress

根据你的后端是否自己处理SSL证书,分两种场景配置:

场景A:后端服务自己处理SSL证书

如果你的API服务本身在443端口提供HTTPS服务,需要开启SSL直通,让Ingress直接把TLS流量转发到后端:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: myApp-ingress
  namespace: myApp-main
  annotations:
    kubernetes.io/ingress.class: nginx
    nginx.ingress.kubernetes.io/backend-protocol: H2C
    nginx.ingress.kubernetes.io/ssl-passthrough: 'true'
spec:
  tls:
    - hosts:
        - myApp.MyInternalDns.net
      secretName: myApp-tls-secret  # 提前创建包含证书的Secret
  rules:
    - host: myApp.MyInternalDns.net
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: myApp-service
                port:
                  number: 80
  • 注意:AKS的NGINX Ingress Controller默认可能没开启SSL直通,需要确保部署Controller时添加了--enable-ssl-passthrough启动参数。
  • 提前创建TLS Secret:
kubectl create secret tls myApp-tls-secret --cert=./your-cert.crt --key=./your-cert.key -n myApp-main

场景B:由Ingress处理SSL证书(推荐)

如果不想让后端处理SSL,让Ingress Controller解密流量后转发到后端80端口,配置更简单:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: myApp-ingress
  namespace: myApp-main
  annotations:
    kubernetes.io/ingress.class: nginx
    nginx.ingress.kubernetes.io/backend-protocol: H2C
spec:
  tls:
    - hosts:
        - myApp.MyInternalDns.net
      secretName: myApp-tls-secret
  rules:
    - host: myApp.MyInternalDns.net
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: myApp-service
                port:
                  number: 80

这种配置下:

  • 客户端访问80端口时,直接转发到后端80;
  • 客户端访问443端口时,Ingress解密TLS流量后,用H2C协议转发到后端80端口;
  • 后端不需要处理SSL,减少配置复杂度。

验证配置

提交配置后,用以下命令检查Ingress状态:

kubectl get ingress -n myApp-main

正常情况下会看到ADDRESS字段显示Ingress Controller的IP,并且PORTS列显示80, 443。

内容的提问来源于stack exchange,提问作者Leonardo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 00:42:50