You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform部署时生成ELB而非ALB的问题排查求助

解决Nginx Controller部署后生成ELB而非ALB的问题

核心问题根源

你混淆了Nginx Ingress Controller和**AWS Load Balancer Controller(原ALB Ingress Controller)**的定位:

  • 之前用Nginx Controller+NLB注解,是让Nginx的Service通过AWS NLB暴露;
  • 但要创建AWS原生ALB,要么用AWS Load Balancer Controller直接管理ALB作为Ingress,要么给Nginx的Service配置正确的ALB注解(而非NLB注解)。当前配置错误导致默认生成了经典ELB。

两种解决方案路径

路径1:切换到AWS Load Balancer Controller(推荐,适配Azure AD OIDC场景)

如果需要用ALB对接Azure AD的OIDC授权,AWS ALB本身支持OIDC身份验证,无需在Nginx层处理,推荐用这种方式:

  1. 部署AWS Load Balancer Controller:
    • 替换原有的Nginx Ingress Controller部署,用Terraform的helm_release资源部署AWS Load Balancer Controller,确保其ServiceAccount有足够的IAM权限(通过IRSA或NodeRole权限)。
  2. 配置Ingress资源:
    • 创建Ingress时使用ALB专属注解,示例:
      apiVersion: networking.k8s.io/v1
      kind: Ingress
      metadata:
        annotations:
          alb.ingress.kubernetes.io/scheme: internet-facing
          alb.ingress.kubernetes.io/target-type: ip
          # Azure AD OIDC相关配置
          alb.ingress.kubernetes.io/auth-type: oidc
          alb.ingress.kubernetes.io/auth-oidc-issuer: "https://login.microsoftonline.com/<tenant-id>/v2.0"
          alb.ingress.kubernetes.io/auth-oidc-client-id: "<your-client-id>"
          alb.ingress.kubernetes.io/auth-oidc-client-secret: "<your-client-secret>"
      spec:
        rules:
          - host: example.com
            http:
              paths:
                - path: /
                  pathType: Prefix
                  backend:
                    service:
                      name: your-service
                      port:
                        number: 80
      
  3. 验证子网标签:
    • 确保公有子网带有标签kubernetes.io/role/elb: "1",私有子网带有kubernetes.io/role/internal-elb: "1"(如需内部ALB)。

路径2:让Nginx Controller的Service暴露为ALB

如果坚持使用Nginx Controller,需要修正Service的注解配置:

  1. 修改Nginx Service的注解:
    • 移除NLB相关注解,替换为ALB专属注解:
      apiVersion: v1
      kind: Service
      metadata:
        annotations:
          service.beta.kubernetes.io/aws-load-balancer-type: application  # 指定创建ALB
          service.beta.kubernetes.io/aws-load-balancer-scheme: internet-facing
          # 可选:指定安全组、子网ID
          # service.beta.kubernetes.io/aws-load-balancer-security-groups: sg-xxxxxx
          # service.beta.kubernetes.io/aws-load-balancer-subnets: subnet-xxxxxx,subnet-yyyyyy
      spec:
        type: LoadBalancer
        selector:
          app: nginx-ingress
        ports:
          - port: 80
            targetPort: 80
            protocol: TCP
      
  2. 确认IAM权限:
    • 确保集群Worker节点的IAM角色拥有elasticloadbalancing:CreateLoadBalancer、elasticloadbalancing:CreateTargetGroup等ALB相关权限。
  3. 检查Service类型:
    • 确保Service的type为LoadBalancer,而非NodePort或ClusterIP。

常见遗漏点排查

  • 注解前缀混淆:AWS Load Balancer Controller的Ingress用alb.ingress.kubernetes.io/前缀,而Service的ALB注解用service.beta.kubernetes.io/aws-load-balancer-前缀,不要混用。
  • IAM权限不足:如果是Terraform创建的EKS集群,需确保AWS Load Balancer Controller的ServiceAccount(或NodeRole)关联了AmazonEKSLoadBalancerControllerPolicy权限策略。
  • 子网标签错误:确认标签键值完全正确,比如kubernetes.io/role/elb的值必须是"1"(字符串类型,不能是布尔值)。

内容的提问来源于stack exchange,提问作者IFThenElse

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 20:20:30