GKE集成Cloud Armor限制Ingress访问时遇400错误求助
GKE Cloud Armor 策略绑定报错解决方案
错误根源
报错信息deny action is only supported for TCP and SSL load balancers明确指出:当前使用的负载均衡器类型不支持将带deny动作的Cloud Armor策略通过BackendConfig绑定到Service。
问题原因
GKE中,通过BackendConfig给Service绑定Cloud Armor策略的方式,仅适配TCP/SSL类型负载均衡器(对应Service类型为LoadBalancer)。而你是通过Ingress创建HTTP(S)负载均衡器,这类场景下Cloud Armor策略需要直接关联到Ingress资源,而非Service的BackendConfig。
修正步骤
- 移除Service上关联BackendConfig的注解:删除Service中
cloud.google.com/backend-config相关配置。 - 创建
FrontendConfig资源关联Cloud Armor策略,示例YAML:apiVersion: networking.gke.io/v1beta1 kind: FrontendConfig metadata: name: frontend-config-demo spec: securityPolicy: name: armor-policy-name - 在Ingress资源中添加注解关联上述FrontendConfig:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: your-ingress-name annotations: networking.gke.io/v1beta1.FrontendConfig: "frontend-config-demo" spec: rules: - http: paths: - path: / pathType: Prefix backend: service: name: your-service-name port: number: 80 - 应用配置:
kubectl apply -f frontend-config.yaml kubectl apply -f your-ingress.yaml
注意事项
- 确保Ingress为GKE默认创建的HTTP(S)负载均衡器类型。
- 已配置的Security admin权限无需调整,满足权限要求。
内容的提问来源于stack exchange,提问作者raghu_manne
相关产品推荐
相关产品推荐

