You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AKS Ingress用ExternalName对接Azure静态网站遇ErrorFetchingEndpoints问题

问题解决思路及修正方案

错误原因分析

  1. ExternalName Service配置冗余:ExternalName类型Service仅用于指向外部域名,不需要selector字段。你添加的selector: app: xxxblobbackend会让Kubernetes尝试寻找匹配该标签的Pod生成Endpoint,但实际不存在这类Pod,因此触发Endpoint not found错误。
  2. Ingress后端参数不匹配:全局设置的backend-hostname: localhost和backend-protocol: http与Azure Blob静态网站的实际访问要求(HTTPS协议、专属Blob域名)不符,导致流量无法正确路由。

修正后的配置文件

1. 修正ExternalName Service

移除多余的selector字段,保留核心外部域名与端口配置:

apiVersion: v1
kind: Service
metadata:
  name: xxxblobbackend
  namespace: nodepool
spec:
  type: ExternalName
  externalName: xxxyyyprod.z16.web.core.windows.net
  ports:
    - protocol: TCP
      port: 443
      targetPort: 443

2. 调整Ingress配置

针对/static/*路径单独配置后端参数,确保与Blob静态网站的访问规则匹配:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  annotations:
    # 全局通用配置
    appgw.ingress.kubernetes.io/request-timeout: "180"
    appgw.ingress.kubernetes.io/proxy-body-size: "0"
    appgw.ingress.kubernetes.io/proxy-read-timeout: "900"
    appgw.ingress.kubernetes.io/proxy-send-timeout: "900"
    appgw.ingress.kubernetes.io/ssl-redirect: "true"
    kubernetes.io/ingress.class: azure/application-gateway
    # /static/*路径专属后端配置
    appgw.ingress.kubernetes.io/backend-hostname: "xxxyyyprod.z16.web.core.windows.net"
    appgw.ingress.kubernetes.io/backend-protocol: "https"
    appgw.ingress.kubernetes.io/health-probe-path: "/"
    appgw.ingress.kubernetes.io/health-probe-protocol: "Https"
  generation: 5
  name: ingress-api
  namespace: nodepool
spec:
  rules:
    - http:
        paths:
        - path: /
          pathType: ImplementationSpecific
          backend:
            service:
              name: defaultbackend
              port:
                number: 80
        - path: /api/*
          pathType: Prefix
          backend:
            service:
              name: api-service
              port:
                number: 8081
        - path: /static/*
          pathType: ImplementationSpecific
          backend:
            service:
              name: xxxblobbackend
              port:
                number: 443
  tls:
  - secretName: xxxme-yyy-tls-certificate

额外注意事项

  • 若需为不同路径设置差异化后端参数(如默认路径用HTTP、/static用HTTPS),可使用AGIC的appgw.ingress.kubernetes.io/override-path-annotations实现单路径专属配置,避免全局参数冲突。
  • 确认Azure Blob静态网站已配置正确的访问权限,允许Application Gateway的IP地址访问(公网IP或VNet内网地址,依网络架构而定)。

内容的提问来源于stack exchange,提问作者jawad846

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 17:25:17