You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EKS 1.19环境下CLB迁移至NLB+Nginx Ingress后目标组属性与健康检查配置未生效问题咨询

解决NLB注解不生效及Ingress Controller迁移问题

Let's break down your problem and walk through the fix step by step:

核心问题分析

The root cause here is that you're using the default Kubernetes AWS cloud provider controller (via the old ingress-nginx deploy manifest) to create your NLB, but the annotations you're trying to use (aws-load-balancer-target-group-attributes, aws-load-balancer-healthcheck-protocol, etc.) are exclusive to the AWS Load Balancer Controller (formerly the ALB Ingress Controller) version 2.2+. The default cloud provider controller doesn't recognize these advanced NLB annotations, which is why they're not taking effect.

解决方案步骤

1. 部署AWS Load Balancer Controller(v2.2+)到EKS 1.19集群

首先,你需要用专门的AWS Load Balancer Controller替换默认的云提供商处理逻辑。对于EKS 1.19,推荐使用IRSA(IAM Roles for Service Accounts)为控制器授予必要的AWS权限:

  • 创建包含NLB、目标组及相关资源管理权限的IAM策略
  • 通过IRSA将该策略关联到Kubernetes服务账户
  • 通过官方Helm Chart或YAML清单部署控制器(确保选择与EKS 1.19兼容的2.2.x+版本)

2. 更新Ingress-Nginx Service注解

控制器运行后,调整Service清单,使用AWS Load Balancer Controller能识别的正确注解,移除默认云提供商的冲突注解,只保留NLB相关配置:

apiVersion: v1
kind: Service
metadata:
  annotations:
    service.beta.kubernetes.io/aws-load-balancer-type: "nlb"
    service.beta.kubernetes.io/aws-load-balancer-cross-zone-load-balancing-enabled: "true"
    service.beta.kubernetes.io/aws-load-balancer-ssl-cert: "SSL_CERT_ARN"
    service.beta.kubernetes.io/aws-load-balancer-ssl-ports: "https"
    # 启用目标组的Proxy Protocol v2
    service.beta.kubernetes.io/aws-load-balancer-target-group-attributes: proxy_protocol_v2.enabled=true
    # 设置TCP健康检查并使用流量端口
    service.beta.kubernetes.io/aws-load-balancer-healthcheck-protocol: "TCP"
    service.beta.kubernetes.io/aws-load-balancer-healthcheck-port: "traffic-port"
  name: ingress-nginx-controller
  namespace: ingress-nginx
spec:
  type: LoadBalancer
  ports:
  - name: http
    port: 80
    targetPort: http
  - name: https
    port: 443
    targetPort: https
  selector:
    app.kubernetes.io/name: ingress-nginx
    app.kubernetes.io/instance: ingress-nginx
    app.kubernetes.io/component: controller

注意:移除service.beta.kubernetes.io/aws-load-balancer-backend-protocol注解——使用NLB TCP模式时,AWS Load Balancer Controller会自动处理后端协议。

3. 为Ingress-Nginx启用Proxy Protocol支持

既然你在NLB上启用了Proxy Protocol v2,需要配置ingress-nginx控制器信任并处理这些请求头。更新控制器的ConfigMap:

apiVersion: v1
kind: ConfigMap
metadata:
  name: ingress-nginx-controller
  namespace: ingress-nginx
data:
  use-proxy-protocol: "true"

这会确保nginx正确从NLB发送的Proxy Protocol头中提取原始客户端IP和连接信息。

4. 验证配置

应用更新后:

  • 查看AWS控制台中的NLB:
    • 确认目标组已启用Proxy Protocol v2
    • 验证健康检查使用TCP协议并匹配流量端口
  • 查看ingress-nginx控制器日志,确保它能正确处理带有真实客户端IP的请求(不会出现unknown客户端地址)

关于Liveness/Readiness Probe配置的疑问

你不需要调整ingress-nginx控制器的livenessProbe或readinessProbe。默认情况下,这些探针直接访问控制器的localhost端口(绕过NLB),因此不会受到Proxy Protocol配置的影响。即使启用了use-proxy-protocol,控制器的内置逻辑也允许本地回环请求正常工作。

内容的提问来源于stack exchange,提问作者Chris

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 23:47:43