You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GKE集成Cloud Armor限制Ingress访问时遇400错误求助

GKE Cloud Armor 策略绑定报错解决方案

错误根源

报错信息deny action is only supported for TCP and SSL load balancers明确指出:当前使用的负载均衡器类型不支持将带deny动作的Cloud Armor策略通过BackendConfig绑定到Service。

问题原因

GKE中,通过BackendConfig给Service绑定Cloud Armor策略的方式,仅适配TCP/SSL类型负载均衡器(对应Service类型为LoadBalancer)。而你是通过Ingress创建HTTP(S)负载均衡器,这类场景下Cloud Armor策略需要直接关联到Ingress资源,而非Service的BackendConfig。

修正步骤

  • 移除Service上关联BackendConfig的注解:删除Service中cloud.google.com/backend-config相关配置。
  • 创建FrontendConfig资源关联Cloud Armor策略,示例YAML:
    apiVersion: networking.gke.io/v1beta1
    kind: FrontendConfig
    metadata:
      name: frontend-config-demo
    spec:
      securityPolicy:
        name: armor-policy-name
    
  • 在Ingress资源中添加注解关联上述FrontendConfig:
    apiVersion: networking.k8s.io/v1
    kind: Ingress
    metadata:
      name: your-ingress-name
      annotations:
        networking.gke.io/v1beta1.FrontendConfig: "frontend-config-demo"
    spec:
      rules:
      - http:
          paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: your-service-name
                port:
                  number: 80
    
  • 应用配置:
    kubectl apply -f frontend-config.yaml
    kubectl apply -f your-ingress.yaml
    

注意事项

  • 确保Ingress为GKE默认创建的HTTP(S)负载均衡器类型。
  • 已配置的Security admin权限无需调整,满足权限要求。

内容的提问来源于stack exchange,提问作者raghu_manne

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 22:13:22