GKE集群中ClamAV:1.2实例健康检查失败问题求助
解决GKE Ingress中ClamAV 1.2健康检查失败的方案
核心问题分析
ClamAV的3310端口是TCP协议的clamd扫描端口,不支持HTTP请求,而GKE Ingress仅支持HTTP/HTTPS类型的健康检查,直接对3310端口做HTTP健康检查必然失败。
可行解决方案:利用ClamAV的7357健康状态端口
官方clamav/clamav:1.2镜像内置了7357端口,提供HTTP协议的健康状态查询,当clamd服务完全就绪(病毒库加载完成)时,访问该端口会返回200 OK,完美适配GKE Ingress的健康检查要求。
具体配置调整步骤
1. 更新Deployment,开启7357端口
修改Deployment的容器端口配置,添加7357端口:
apiVersion: apps/v1 kind: Deployment metadata: name: clam-av spec: replicas: 1 selector: matchLabels: run: clam-av template: metadata: labels: run: clam-av spec: nodeSelector: cloud.google.com/gke-nodepool: XXX-XXX-pool terminationGracePeriodSeconds: 60 containers: - name: clamav-container image: clamav/clamav:1.2 resources: requests: cpu: 200m memory: 1Gi imagePullPolicy: Always ports: - containerPort: 3310 - containerPort: 7357 # 开启健康状态端口
2. 更新Service,添加7357端口映射
在Service中新增一个端口,专门用于健康检查:
apiVersion: v1 kind: Service metadata: name: clam-av-service annotations: cloud.google.com/backend-config: '{"default": "backend-for-clamAV"}' spec: selector: run: clam-av ports: - name: clamd-scan protocol: TCP port: 80 targetPort: 3310 # 业务流量走3310 - name: health-check protocol: TCP port: 8080 targetPort: 7357 # 健康检查走7357 type: ClusterIP
3. 更新BackendConfig,指向7357端口做HTTP健康检查
调整健康检查的端口和参数(适配ClamAV启动加载病毒库的耗时):
apiVersion: cloud.google.com/v1 kind: BackendConfig metadata: name: backend-for-clamAV spec: timeoutSec: 150 connectionDraining: drainingTimeoutSec: 150 healthCheck: checkIntervalSec: 30 # 延长检查间隔,避免启动阶段误判 port: 8080 type: HTTP requestPath: / healthyThreshold: 2 unhealthyThreshold: 5 timeoutSec: 10
额外验证步骤
在集群内通过kubectl exec进入任意Pod,执行curl <clamav-pod-ip>:7357,若返回200 OK则说明健康状态端口工作正常。
内容的提问来源于stack exchange,提问作者Vikram R
相关产品推荐
相关产品推荐

