You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否在GKE中使用Zonal NEGs创建内部透传L4网络负载均衡器?

Istio网关结合内部透传L4负载均衡器与Zonal NEGs的可行性

完全可行,这是规避GKE工作节点只能归属一个负载均衡实例组限制的标准解决方案,具体实现可参考以下核心配置与要点:

  • 配置Istio网关Service启用内部LB与Zonal NEG
    为Istio网关的LoadBalancer类型Service添加关键注解,让GCP生成Zonal NEG而非非托管实例组:

    apiVersion: v1
    kind: Service
    metadata:
      name: istio-ingressgateway
      namespace: istio-system
      annotations:
        cloud.google.com/load-balancer-type: "internal"
        # 为指定端口创建Zonal NEG
        cloud.google.com/neg: '{"exposed_ports": {"80":{},"443":{}}}'
        # 关联BackendConfig配置L4透传与健康检查
        cloud.google.com/backend-config: '{"default": "istio-gateway-backendconfig"}'
    spec:
      type: LoadBalancer
      selector:
        istio: ingressgateway
      ports:
        - name: http
          port: 80
          targetPort: 8080
        - name: https
          port: 443
          targetPort: 8443
    
  • 创建BackendConfig定义L4透传规则
    通过BackendConfig指定L4层TCP协议处理,同时配置适配Istio网关的健康检查:

    apiVersion: cloud.google.com/v1
    kind: BackendConfig
    metadata:
      name: istio-gateway-backendconfig
      namespace: istio-system
    spec:
      loadBalancingScheme: INTERNAL
      protocol: TCP
      healthCheck:
        type: HTTP
        port: 15021
        requestPath: /healthz/ready
        checkIntervalSec: 5
        timeoutSec: 5
      connectionDraining:
        drainingTimeoutSec: 300
    
  • 核心优势说明
    Zonal NEG会直接关联GKE节点上的网络端点(Pod所在的节点端口),而非将节点加入实例组,从根本上避开了"单个节点只能属于一个负载均衡实例组"的限制,同时保留L4负载均衡的透传能力。

  • 验证与注意事项

    • 部署完成后,通过gcloud compute network-endpoint-groups list --filter="name:istio-ingressgateway"确认Zonal NEG已生成
    • 确保GKE集群版本≥1.14(该版本起全面支持Zonal NEG)
    • Istio网关Pod需正确配置就绪探针(默认已监听15021端口的/healthz/ready路径)
    • 内部LB的子网、防火墙规则需与原有环境匹配,保障流量可达

内容的提问来源于stack exchange,提问作者Isa A

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 02:15:57