使用Terraform部署时生成ELB而非ALB的问题排查求助
解决Nginx Controller部署后生成ELB而非ALB的问题
核心问题根源
你混淆了Nginx Ingress Controller和**AWS Load Balancer Controller(原ALB Ingress Controller)**的定位:
- 之前用Nginx Controller+NLB注解,是让Nginx的Service通过AWS NLB暴露;
- 但要创建AWS原生ALB,要么用AWS Load Balancer Controller直接管理ALB作为Ingress,要么给Nginx的Service配置正确的ALB注解(而非NLB注解)。当前配置错误导致默认生成了经典ELB。
两种解决方案路径
路径1:切换到AWS Load Balancer Controller(推荐,适配Azure AD OIDC场景)
如果需要用ALB对接Azure AD的OIDC授权,AWS ALB本身支持OIDC身份验证,无需在Nginx层处理,推荐用这种方式:
- 部署AWS Load Balancer Controller:
- 替换原有的Nginx Ingress Controller部署,用Terraform的
helm_release资源部署AWS Load Balancer Controller,确保其ServiceAccount有足够的IAM权限(通过IRSA或NodeRole权限)。
- 替换原有的Nginx Ingress Controller部署,用Terraform的
- 配置Ingress资源:
- 创建Ingress时使用ALB专属注解,示例:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: annotations: alb.ingress.kubernetes.io/scheme: internet-facing alb.ingress.kubernetes.io/target-type: ip # Azure AD OIDC相关配置 alb.ingress.kubernetes.io/auth-type: oidc alb.ingress.kubernetes.io/auth-oidc-issuer: "https://login.microsoftonline.com/<tenant-id>/v2.0" alb.ingress.kubernetes.io/auth-oidc-client-id: "<your-client-id>" alb.ingress.kubernetes.io/auth-oidc-client-secret: "<your-client-secret>" spec: rules: - host: example.com http: paths: - path: / pathType: Prefix backend: service: name: your-service port: number: 80
- 创建Ingress时使用ALB专属注解,示例:
- 验证子网标签:
- 确保公有子网带有标签
kubernetes.io/role/elb: "1",私有子网带有kubernetes.io/role/internal-elb: "1"(如需内部ALB)。
- 确保公有子网带有标签
路径2:让Nginx Controller的Service暴露为ALB
如果坚持使用Nginx Controller,需要修正Service的注解配置:
- 修改Nginx Service的注解:
- 移除NLB相关注解,替换为ALB专属注解:
apiVersion: v1 kind: Service metadata: annotations: service.beta.kubernetes.io/aws-load-balancer-type: application # 指定创建ALB service.beta.kubernetes.io/aws-load-balancer-scheme: internet-facing # 可选:指定安全组、子网ID # service.beta.kubernetes.io/aws-load-balancer-security-groups: sg-xxxxxx # service.beta.kubernetes.io/aws-load-balancer-subnets: subnet-xxxxxx,subnet-yyyyyy spec: type: LoadBalancer selector: app: nginx-ingress ports: - port: 80 targetPort: 80 protocol: TCP
- 移除NLB相关注解,替换为ALB专属注解:
- 确认IAM权限:
- 确保集群Worker节点的IAM角色拥有
elasticloadbalancing:CreateLoadBalancer、elasticloadbalancing:CreateTargetGroup等ALB相关权限。
- 确保集群Worker节点的IAM角色拥有
- 检查Service类型:
- 确保Service的
type为LoadBalancer,而非NodePort或ClusterIP。
- 确保Service的
常见遗漏点排查
- 注解前缀混淆:AWS Load Balancer Controller的Ingress用
alb.ingress.kubernetes.io/前缀,而Service的ALB注解用service.beta.kubernetes.io/aws-load-balancer-前缀,不要混用。 - IAM权限不足:如果是Terraform创建的EKS集群,需确保AWS Load Balancer Controller的ServiceAccount(或NodeRole)关联了
AmazonEKSLoadBalancerControllerPolicy权限策略。 - 子网标签错误:确认标签键值完全正确,比如
kubernetes.io/role/elb的值必须是"1"(字符串类型,不能是布尔值)。
内容的提问来源于stack exchange,提问作者IFThenElse
相关产品推荐
相关产品推荐

