You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Kubernetes Gateway API实现应用的标准80端口外部访问?

用Gateway API实现80端口优雅外部访问的方案

要通过标准80端口访问Kubernetes集群内的服务,核心是让Gateway Controller的对外服务绑定到节点的80端口,而非默认的高位NodePort。以下分场景给出具体实现方案:

1. 云厂商K8s集群(首选:LoadBalancer类型Service)

云环境的K8s集群普遍支持LoadBalancer类型服务,可直接将外部80端口映射到Gateway Controller的内部端口:

  • 找到Gateway Controller对应的Service(比如NGINX Gateway Fabric的默认Service是nginx-gateway-fabric),将其类型改为LoadBalancer,并配置端口映射、外部流量策略:
apiVersion: v1
kind: Service
metadata:
  name: nginx-gateway-fabric
  namespace: nginx-gateway
spec:
  type: LoadBalancer
  externalTrafficPolicy: Local # 保留客户端源IP,避免SNAT导致的IP丢失
  ports:
  - name: http
    port: 80
    targetPort: 80
    protocol: TCP
  selector:
    app: nginx-gateway-fabric
  • 应用后,云厂商会分配一个公网IP,将example.com解析到该IP,即可通过http://example.com访问。

2. 自建K8s集群/单节点场景(HostPort)

如果是自建集群或单节点部署,可直接让Gateway Controller的Pod绑定节点的80端口:

  • 修改Gateway Controller的Deployment配置,在容器端口中添加hostPort: 80:
apiVersion: apps/v1
kind: Deployment
metadata:
  name: nginx-gateway-fabric
  namespace: nginx-gateway
spec:
  replicas: 1
  selector:
    matchLabels:
      app: nginx-gateway-fabric
  template:
    metadata:
      labels:
        app: nginx-gateway-fabric
    spec:
      containers:
      - name: nginx-gateway
        image: nginx/nginx-gateway-fabric:latest
        ports:
        - name: http
          containerPort: 80
          hostPort: 80 # 直接绑定节点的80端口
        resources:
          requests:
            cpu: 100m
            memory: 128Mi
  • 确保节点的80端口未被其他进程占用,且防火墙开放80端口。将example.com解析到节点的公网IP即可访问。

3. 修改NodePort范围(指定固定80端口)

如果必须用NodePort类型,可调整集群的NodePort范围包含80,再指定固定端口:

  1. 修改Kube-apiserver的启动参数,添加--service-node-port-range=80-32767(需重启apiserver);
  2. 创建/修改Gateway Controller的Service为NodePort类型,指定nodePort: 80:
apiVersion: v1
kind: Service
metadata:
  name: nginx-gateway-fabric
  namespace: nginx-gateway
spec:
  type: NodePort
  ports:
  - name: http
    port: 80
    targetPort: 80
    nodePort: 80 # 指定固定80端口
    protocol: TCP
  selector:
    app: nginx-gateway-fabric
  • 注意:该方案需要集群所有节点的80端口未被占用,且防火墙开放80端口。

4. 本地开发环境(Minikube/Kind)

  • Minikube:部署Gateway Controller后,执行minikube tunnel命令,它会创建本地负载均衡器,将Service的80端口映射到本地的80端口,此时http://example.com可直接访问(需在本地hosts文件中添加127.0.0.1 example.com)。
  • Kind:创建集群时通过配置文件映射80端口到本地:
kind: Cluster
apiVersion: kind.x-k8s.io/v1alpha4
nodes:
- role: control-plane
  extraPortMappings:
  - containerPort: 80
    hostPort: 80
    protocol: TCP

最后补充Gateway资源配置

完成以上服务配置后,还需创建GatewayClass、Gateway和HTTPRoute来路由流量到后端服务:

  1. 定义GatewayClass(对应使用的Controller):
apiVersion: gateway.networking.k8s.io/v1
kind: GatewayClass
metadata:
  name: nginx-gateway-class
spec:
  controllerName: gateway.nginx.org/nginx-gateway-controller
  1. 定义Gateway,监听80端口:
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
  name: example-gateway
  namespace: default
spec:
  gatewayClassName: nginx-gateway-class
  listeners:
  - name: http
    port: 80
    protocol: HTTP
    allowedRoutes:
      namespaces:
        from: All
  1. 定义HTTPRoute,将example.com的流量路由到后端服务(假设后端服务名为my-app,端口80):
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: example-route
  namespace: default
spec:
  parentRefs:
  - name: example-gateway
  hostnames:
  - "example.com"
  rules:
  - matches:
    - path:
        type: PathPrefix
        value: /
    backendRefs:
    - name: my-app
      port: 80

内容的提问来源于stack exchange,提问作者Higuys

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 00:52:42