You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在K8S的ingress-nginx-controller中配置类似Apache的Proxypass与Proxypassrereverse

在Ingress-Nginx中实现类似Apache的ProxyPass/ProxyPassReverse配置

完全可以通过Ingress-Nginx的注解功能实现和Apache ProxyPass、ProxyPassReverse等价的反向代理效果,以下是针对你的AKS环境的具体解决方案:

核心实现思路

Ingress-Nginx本质是基于Nginx的反向代理,因此可以通过注解插入原生Nginx配置来实现需求:

  • Nginx的proxy_pass指令对应Apache的ProxyPass,负责将请求转发到目标地址
  • Nginx的proxy_redirect指令对应Apache的ProxyPassReverse,负责修改后端返回的Location等响应头,避免客户端被重定向到后端域名

具体配置示例

方法1:使用Dummy Service + Server Snippets

由于Ingress资源必须指定后端Service,我们可以先创建一个占位用的Dummy Service(无需实际运行Pod):

apiVersion: v1
kind: Service
metadata:
  name: dummy-backend
spec:
  ports:
  - port: 443
    protocol: TCP
    targetPort: 443
  selector:
    app: dummy # 不需要存在对应Pod

然后创建Ingress资源,通过注解插入反向代理规则:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: cross-domain-proxy
  annotations:
    # 指定后端用HTTPS协议
    nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
    # 配置请求头,确保后端能获取客户端真实信息
    nginx.ingress.kubernetes.io/configuration-snippet: |
      proxy_set_header Host $host;
      proxy_set_header X-Real-IP $remote_addr;
      proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
      proxy_set_header X-Forwarded-Proto $scheme;
    # 插入Nginx Server块的配置,定义反向代理规则
    nginx.ingress.kubernetes.io/server-snippets: |
      location /test {
        # 对应Apache ProxyPass:转发请求到目标地址
        proxy_pass https://example.b.com/test;
        # 对应Apache ProxyPassReverse:修改后端返回的Location头
        proxy_redirect https://example.b.com/test https://example.a.com/test;
        # 如果目标地址证书是自签名,可临时关闭验证(不推荐生产环境使用)
        # proxy_ssl_verify off;
      }
spec:
  ingressClassName: nginx
  # 配置example.a.com的TLS证书
  tls:
  - hosts:
    - example.a.com
    secretName: example-a-tls-secret # 替换为你的TLS证书Secret名称
  rules:
  - host: example.a.com
    http:
      paths:
      - path: /test
        pathType: Prefix
        backend:
          service:
            name: dummy-backend
            port:
              number: 443

方法2:使用ExternalName Service(更规范)

如果不想用Dummy Service,可以创建ExternalName类型的Service直接指向目标域名:

apiVersion: v1
kind: Service
metadata:
  name: example-b-service
spec:
  type: ExternalName
  externalName: example.b.com

然后调整Ingress配置,后端指向这个ExternalName Service,并通过注解补充proxy_redirect规则:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: cross-domain-proxy
  annotations:
    nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
    nginx.ingress.kubernetes.io/configuration-snippet: |
      proxy_set_header Host $host;
      proxy_set_header X-Real-IP $remote_addr;
      proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
      proxy_set_header X-Forwarded-Proto $scheme;
      # 对应Apache ProxyPassReverse
      proxy_redirect https://example.b.com/test https://example.a.com/test;
spec:
  ingressClassName: nginx
  tls:
  - hosts:
    - example.a.com
    secretName: example-a-tls-secret
  rules:
  - host: example.a.com
    http:
      paths:
      - path: /test
        pathType: Prefix
        backend:
          service:
            name: example-b-service
            port:
              number: 443

关键配置说明

  • proxy_pass https://example.b.com/test:将/test路径的请求转发到目标域名的同路径,完全等价于Apache的ProxyPass /test https://example.b.com/test
  • proxy_redirect https://example.b.com/test https://example.a.com/test:当后端返回包含https://example.b.com/test的Location头时,自动替换为https://example.a.com/test,避免客户端被重定向到后端域名,等价于Apache的ProxyPassReverse /test https://example.b.com/test
  • 请求头配置:确保后端服务能正确获取客户端的真实IP、协议等信息,避免出现访问异常

注意事项

  1. 确保AKS集群节点能解析example.b.com并建立HTTPS连接
  2. 生产环境请勿关闭proxy_ssl_verify,如果目标域名使用自签名证书,需配置nginx.ingress.kubernetes.io/proxy-ssl-secret指定CA证书Secret
  3. 确认你的Ingress-Nginx Controller版本支持上述注解(主流版本均支持)

内容的提问来源于stack exchange,提问作者ziv ziv

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 16:26:05