EKS 1.19环境下CLB迁移至NLB+Nginx Ingress后目标组属性与健康检查配置未生效问题咨询
Let's break down your problem and walk through the fix step by step:
核心问题分析
The root cause here is that you're using the default Kubernetes AWS cloud provider controller (via the old ingress-nginx deploy manifest) to create your NLB, but the annotations you're trying to use (aws-load-balancer-target-group-attributes, aws-load-balancer-healthcheck-protocol, etc.) are exclusive to the AWS Load Balancer Controller (formerly the ALB Ingress Controller) version 2.2+. The default cloud provider controller doesn't recognize these advanced NLB annotations, which is why they're not taking effect.
解决方案步骤
1. 部署AWS Load Balancer Controller(v2.2+)到EKS 1.19集群
首先,你需要用专门的AWS Load Balancer Controller替换默认的云提供商处理逻辑。对于EKS 1.19,推荐使用IRSA(IAM Roles for Service Accounts)为控制器授予必要的AWS权限:
- 创建包含NLB、目标组及相关资源管理权限的IAM策略
- 通过IRSA将该策略关联到Kubernetes服务账户
- 通过官方Helm Chart或YAML清单部署控制器(确保选择与EKS 1.19兼容的2.2.x+版本)
2. 更新Ingress-Nginx Service注解
控制器运行后,调整Service清单,使用AWS Load Balancer Controller能识别的正确注解,移除默认云提供商的冲突注解,只保留NLB相关配置:
apiVersion: v1 kind: Service metadata: annotations: service.beta.kubernetes.io/aws-load-balancer-type: "nlb" service.beta.kubernetes.io/aws-load-balancer-cross-zone-load-balancing-enabled: "true" service.beta.kubernetes.io/aws-load-balancer-ssl-cert: "SSL_CERT_ARN" service.beta.kubernetes.io/aws-load-balancer-ssl-ports: "https" # 启用目标组的Proxy Protocol v2 service.beta.kubernetes.io/aws-load-balancer-target-group-attributes: proxy_protocol_v2.enabled=true # 设置TCP健康检查并使用流量端口 service.beta.kubernetes.io/aws-load-balancer-healthcheck-protocol: "TCP" service.beta.kubernetes.io/aws-load-balancer-healthcheck-port: "traffic-port" name: ingress-nginx-controller namespace: ingress-nginx spec: type: LoadBalancer ports: - name: http port: 80 targetPort: http - name: https port: 443 targetPort: https selector: app.kubernetes.io/name: ingress-nginx app.kubernetes.io/instance: ingress-nginx app.kubernetes.io/component: controller
注意:移除
service.beta.kubernetes.io/aws-load-balancer-backend-protocol注解——使用NLB TCP模式时,AWS Load Balancer Controller会自动处理后端协议。
3. 为Ingress-Nginx启用Proxy Protocol支持
既然你在NLB上启用了Proxy Protocol v2,需要配置ingress-nginx控制器信任并处理这些请求头。更新控制器的ConfigMap:
apiVersion: v1 kind: ConfigMap metadata: name: ingress-nginx-controller namespace: ingress-nginx data: use-proxy-protocol: "true"
这会确保nginx正确从NLB发送的Proxy Protocol头中提取原始客户端IP和连接信息。
4. 验证配置
应用更新后:
- 查看AWS控制台中的NLB:
- 确认目标组已启用Proxy Protocol v2
- 验证健康检查使用TCP协议并匹配流量端口
- 查看ingress-nginx控制器日志,确保它能正确处理带有真实客户端IP的请求(不会出现
unknown客户端地址)
关于Liveness/Readiness Probe配置的疑问
你不需要调整ingress-nginx控制器的livenessProbe或readinessProbe。默认情况下,这些探针直接访问控制器的localhost端口(绕过NLB),因此不会受到Proxy Protocol配置的影响。即使启用了use-proxy-protocol,控制器的内置逻辑也允许本地回环请求正常工作。
内容的提问来源于stack exchange,提问作者Chris

