如何通过Kubernetes Gateway API实现应用的标准80端口外部访问?
用Gateway API实现80端口优雅外部访问的方案
要通过标准80端口访问Kubernetes集群内的服务,核心是让Gateway Controller的对外服务绑定到节点的80端口,而非默认的高位NodePort。以下分场景给出具体实现方案:
1. 云厂商K8s集群(首选:LoadBalancer类型Service)
云环境的K8s集群普遍支持LoadBalancer类型服务,可直接将外部80端口映射到Gateway Controller的内部端口:
- 找到Gateway Controller对应的Service(比如NGINX Gateway Fabric的默认Service是
nginx-gateway-fabric),将其类型改为LoadBalancer,并配置端口映射、外部流量策略:
apiVersion: v1 kind: Service metadata: name: nginx-gateway-fabric namespace: nginx-gateway spec: type: LoadBalancer externalTrafficPolicy: Local # 保留客户端源IP,避免SNAT导致的IP丢失 ports: - name: http port: 80 targetPort: 80 protocol: TCP selector: app: nginx-gateway-fabric
- 应用后,云厂商会分配一个公网IP,将
example.com解析到该IP,即可通过http://example.com访问。
2. 自建K8s集群/单节点场景(HostPort)
如果是自建集群或单节点部署,可直接让Gateway Controller的Pod绑定节点的80端口:
- 修改Gateway Controller的Deployment配置,在容器端口中添加
hostPort: 80:
apiVersion: apps/v1 kind: Deployment metadata: name: nginx-gateway-fabric namespace: nginx-gateway spec: replicas: 1 selector: matchLabels: app: nginx-gateway-fabric template: metadata: labels: app: nginx-gateway-fabric spec: containers: - name: nginx-gateway image: nginx/nginx-gateway-fabric:latest ports: - name: http containerPort: 80 hostPort: 80 # 直接绑定节点的80端口 resources: requests: cpu: 100m memory: 128Mi
- 确保节点的80端口未被其他进程占用,且防火墙开放80端口。将
example.com解析到节点的公网IP即可访问。
3. 修改NodePort范围(指定固定80端口)
如果必须用NodePort类型,可调整集群的NodePort范围包含80,再指定固定端口:
- 修改Kube-apiserver的启动参数,添加
--service-node-port-range=80-32767(需重启apiserver); - 创建/修改Gateway Controller的Service为NodePort类型,指定
nodePort: 80:
apiVersion: v1 kind: Service metadata: name: nginx-gateway-fabric namespace: nginx-gateway spec: type: NodePort ports: - name: http port: 80 targetPort: 80 nodePort: 80 # 指定固定80端口 protocol: TCP selector: app: nginx-gateway-fabric
- 注意:该方案需要集群所有节点的80端口未被占用,且防火墙开放80端口。
4. 本地开发环境(Minikube/Kind)
- Minikube:部署Gateway Controller后,执行
minikube tunnel命令,它会创建本地负载均衡器,将Service的80端口映射到本地的80端口,此时http://example.com可直接访问(需在本地hosts文件中添加127.0.0.1 example.com)。 - Kind:创建集群时通过配置文件映射80端口到本地:
kind: Cluster apiVersion: kind.x-k8s.io/v1alpha4 nodes: - role: control-plane extraPortMappings: - containerPort: 80 hostPort: 80 protocol: TCP
最后补充Gateway资源配置
完成以上服务配置后,还需创建GatewayClass、Gateway和HTTPRoute来路由流量到后端服务:
- 定义GatewayClass(对应使用的Controller):
apiVersion: gateway.networking.k8s.io/v1 kind: GatewayClass metadata: name: nginx-gateway-class spec: controllerName: gateway.nginx.org/nginx-gateway-controller
- 定义Gateway,监听80端口:
apiVersion: gateway.networking.k8s.io/v1 kind: Gateway metadata: name: example-gateway namespace: default spec: gatewayClassName: nginx-gateway-class listeners: - name: http port: 80 protocol: HTTP allowedRoutes: namespaces: from: All
- 定义HTTPRoute,将
example.com的流量路由到后端服务(假设后端服务名为my-app,端口80):
apiVersion: gateway.networking.k8s.io/v1 kind: HTTPRoute metadata: name: example-route namespace: default spec: parentRefs: - name: example-gateway hostnames: - "example.com" rules: - matches: - path: type: PathPrefix value: / backendRefs: - name: my-app port: 80
内容的提问来源于stack exchange,提问作者Higuys
相关产品推荐
相关产品推荐

