AWS EKS环境下如何通过ALB Ingress实现基于端口的应用路由配置?
How to Expose Services on Custom Ports (8180/8181) via ALB Ingress
First, let's break down why your original config failed:
- You tried adding
8180and8181as top-level keys in the Ingress spec, which violates the Kubernetes Ingress API schema — that's the root cause of your format error. - Ingress-Nginx uses a ConfigMap for Layer 4 TCP/UDP forwarding, but ALB Ingress is a Layer 7 load balancer, so it relies on listener-specific routing rules instead. You can't directly copy the Ingress-Nginx approach here.
Here are two tested, working solutions to achieve your goal:
Solution 1: Multiple Ingress Resources (Recommended for Clarity)
This approach creates separate Ingresses for each custom port, but groups them to share the same ALB (avoiding redundant load balancers).
Step 1: Main Ingress for 80/443
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: main-ingress annotations: alb.ingress.kubernetes.io/scheme: internet-facing alb.ingress.kubernetes.io/listen-ports: '[{"HTTP": 80}, {"HTTPS":443}]' alb.ingress.kubernetes.io/group.name: "example-com-shared-alb" # Critical for sharing the same ALB alb.ingress.kubernetes.io/ssl-redirect: "true" # Auto-redirect HTTP to HTTPS spec: tls: - hosts: - example.com secretName: your-tls-secret # Add if using HTTPS rules: - host: example.com http: paths: - path: /1.0/* pathType: Prefix backend: service: name: some-server-side-app port: number: 8080 - path: /* pathType: Prefix backend: service: name: some-webpage port: number: 80
Step 2: Ingress for Port 8180
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: ingress-8180 annotations: alb.ingress.kubernetes.io/scheme: internet-facing alb.ingress.kubernetes.io/listen-ports: '[{"HTTP": 8180}]' alb.ingress.kubernetes.io/group.name: "example-com-shared-alb" # Same group as main Ingress spec: rules: - host: example.com http: paths: - path: /* pathType: Prefix backend: service: name: app-reachable-via-port port: number: 8180
Step 3: Ingress for Port 8181
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: ingress-8181 annotations: alb.ingress.kubernetes.io/scheme: internet-facing alb.ingress.kubernetes.io/listen-ports: '[{"HTTP": 8181}]' alb.ingress.kubernetes.io/group.name: "example-com-shared-alb" # Same group spec: rules: - host: example.com http: paths: - path: /* pathType: Prefix backend: service: name: app-reachable-via-port port: number: 8181
Key Details:
- The
alb.ingress.kubernetes.io/group.nameannotation ensures all three Ingresses use the same ALB, merging their listen ports into the ALB's listener list. - We use the stable
networking.k8s.io/v1API version instead of deprecated older versions.
Solution 2: Single Ingress with Custom Actions & Conditions
If you prefer keeping everything in one file, you can define custom forwarding actions and port-matching conditions.
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: multi-port-ingress annotations: alb.ingress.kubernetes.io/scheme: internet-facing alb.ingress.kubernetes.io/listen-ports: '[{"HTTP": 80}, {"HTTPS":443}, {"HTTP":8180}, {"HTTP":8181}]' alb.ingress.kubernetes.io/ssl-redirect: "true" # Custom action for port 8180 traffic alb.ingress.kubernetes.io/actions/route-8180: | { "Type": "forward", "ForwardConfig": { "TargetGroups": [ { "ServiceName": "app-reachable-via-port", "ServicePort": "8180", "Weight": 100 } ] } } # Custom action for port 8181 traffic alb.ingress.kubernetes.io/actions/route-8181: | { "Type": "forward", "ForwardConfig": { "TargetGroups": [ { "ServiceName": "app-reachable-via-port", "ServicePort": "8181", "Weight": 100 } ] } } # Condition to match requests on port 8180 alb.ingress.kubernetes.io/conditions/port-8180: | { "Field": "listener-port", "Values": ["8180"] } # Condition to match requests on port 8181 alb.ingress.kubernetes.io/conditions/port-8181: | { "Field": "listener-port", "Values": ["8181"] } spec: tls: - hosts: - example.com secretName: your-tls-secret rules: - host: example.com http: paths: - path: /1.0/* pathType: Prefix backend: service: name: some-server-side-app port: number: 8080 - path: /* pathType: Prefix backend: service: name: some-webpage port: number: 80 # Route for port 8180 - path: /* pathType: Prefix backend: service: name: route-8180 # Reference the custom action port: name: use-annotation conditions: - port-8180 # Match the port condition # Route for port 8181 - path: /* pathType: Prefix backend: service: name: route-8181 # Reference the custom action port: name: use-annotation conditions: - port-8181 # Match the port condition
Key Details:
- Custom actions (
alb.ingress.kubernetes.io/actions/) define how traffic is forwarded to your backend services. - Conditions (
alb.ingress.kubernetes.io/conditions/) ensure routes only apply to requests arriving on the specified listener port. - When referencing custom actions, use the action name as the
service.nameandport.name: use-annotation.
Final Checks
- Confirm your backend services are running and accessible within the cluster.
- After applying the config, check the AWS Console to verify all listeners (80, 443, 8180, 8181) are created with the correct target groups.
- Test access to
http://example.com:8180andhttp://example.com:8181to confirm traffic reaches your service.
内容的提问来源于stack exchange,提问作者CodeChimpy
相关产品推荐
相关产品推荐

