You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置K3S与Traefik Ingress暴露SSH的TCP端口求助

问题:通过Traefik Ingress暴露GitLab的SSH端口(TCP/22)

已部署GitLab服务,Pod监听TCP端口22,Service将自身2222端口映射到Pod的22端口,该Service运行正常。现需通过Traefik Ingress把外部TCP/2222流量路由至该Service的2222端口,最终转发到Pod的22端口。


现有配置

GitLab Deployment

apiVersion: apps/v1
kind: Deployment
metadata:
  name: gitlab
  namespace: gitlab
spec:
  replicas: 1
  selector:
    matchLabels:
      app: gitlab
  template:
    metadata:
      labels:
        app: gitlab
    spec:
      containers:
        - name: gitlab
          image: gitlab/gitlab-ce:16.7.7-ce.0
          ports:
            - containerPort: 80
            - containerPort: 443
            - containerPort: 22

GitLab Service

apiVersion: v1
kind: Service
metadata:
  name: gitlab-service
  namespace: gitlab
spec:
  selector:
    app: gitlab-shell
  ports:
    - protocol: TCP
      port: 2222
      targetPort: 22

当前Traefik IngressRouteTCP配置

apiVersion: traefik.containo.us/v1alpha1
kind: IngressRouteTCP
metadata:
  name: gitlab-shell
  namespace: gitlab
spec:
  entryPoints:
    - gitlab-shell
  routes:
  - match: HostSNI(`*`)
    services:
    - name: gitlab-gitlab-shell
      namespace: gitlab
      port: 2222

已尝试的操作

  1. 修改Traefik Deployment,添加EntryPoint和端口:
kubectl edit deployment traefik -n kube-system
# 新增内容:
args:                                          
  - --entrypoints.gitlab-shell.address=:2222/tcp 
ports:                                                                                                                                              
  - containerPort: 2222                                                               
    name: gitlab-shell                                                                
    protocol: TCP
  1. 修改Traefik Service,添加2222端口映射:
kubectl edit service traefik -n kube-system
# 新增端口配置:
ports:                                         
  - name: gitlab-shell            
    nodePort: 31250              
    port: 2222                   
    protocol: TCP                 
    targetPort: 2222 

以上操作后仍无法成功暴露TCP端口,期望流量路径:
外部流量 → Traefik IngressController (2222) → IngressRouteTCP → GitLab Service (2222) → GitLab Pod (22)


解决方案

步骤1:修正Traefik Deployment的EntryPoint配置

确保Traefik的EntryPoint配置正确,且重启Pod生效:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: traefik
  namespace: kube-system
spec:
  template:
    spec:
      containers:
        - name: traefik
          args:
            # 保留原有args,新增EntryPoint配置
            - --entrypoints.gitlab-shell.address=:2222/tcp
          ports:
            # 保留原有端口,新增容器端口
            - name: gitlab-shell
              containerPort: 2222
              protocol: TCP

执行命令应用并重启:

kubectl apply -f traefik-deployment-update.yaml -n kube-system
kubectl rollout restart deployment traefik -n kube-system

步骤2:修正Traefik Service的端口映射

Service的targetPort需对应容器端口的名称(而非端口号):

apiVersion: v1
kind: Service
metadata:
  name: traefik
  namespace: kube-system
spec:
  ports:
    # 保留原有web、websecure端口
    - name: gitlab-shell
      port: 2222
      protocol: TCP
      targetPort: gitlab-shell
      nodePort: 31250 # 可选,固定NodePort时配置

应用修改:

kubectl apply -f traefik-service-update.yaml -n kube-system

步骤3:修正IngressRouteTCP的Service指向

当前IngressRouteTCP中指定的Service名称错误,需修正为实际的gitlab-service:

apiVersion: traefik.containo.us/v1alpha1
kind: IngressRouteTCP
metadata:
  name: gitlab-shell
  namespace: gitlab
spec:
  entryPoints:
    - gitlab-shell
  routes:
  - match: HostSNI(`*`)
    services:
    - name: gitlab-service
      namespace: gitlab
      port: 2222

应用修改:

kubectl apply -f gitlab-ingressroute.yaml -n gitlab

步骤4:验证配置

  1. 检查Traefik Pod状态:
kubectl get pods -n kube-system | grep traefik
  1. 检查Traefik Service端口:
kubectl get service traefik -n kube-system
  1. 测试SSH连接:
ssh -p 2222 git@<集群节点IP/LoadBalancer IP>

关键注意点

  • Traefik的EntryPoint名称必须与IngressRouteTCP中指定的一致(此处为gitlab-shell)
  • Traefik Service的targetPort需对应容器端口名称,避免端口号变更后失效
  • IngressRouteTCP中的Service名称必须与实际GitLab Service名称匹配
  • 修改Traefik配置后必须重启Pod才能生效

内容的提问来源于stack exchange,提问作者Artem

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 18:58:10