GKE配置GCE Ingress后端BackendConfig时遇customResponseHeaders字段错误
解决BackendConfig字段报错并启用HSTS的方案
错误原因
customResponseHeaders不属于cloud.google.com/v1版本的BackendConfig spec字段,该字段仅在cloud.google.com/v1beta1中存在。更关键的是,通过自定义响应头配置HSTS并非GKE的推荐方式,GKE提供了专门的HSTS配置字段。
解决方案
- 修改BackendConfig配置
移除无效的customResponseHeaders块,改用securitySettings.hsts字段配置HSTS,这是cloud.google.com/v1版本支持的标准配置方式:
apiVersion: cloud.google.com/v1 kind: BackendConfig metadata: creationTimestamp: "2023-03-10T14:42:35Z" generation: 1 labels: app.kubernetes.io/instance: xxxx name: xxxx namespace: xxxxxx spec: healthCheck: checkIntervalSec: 10 healthyThreshold: 1 port: 5000 requestPath: /health timeoutSec: 5 type: HTTP unhealthyThreshold: 5 customRequestHeaders: headers: - "X-Client-Region:{client_region}" - "X-Client-City:{client_city}" - "X-Client-CityLatLong:{client_city_lat_long}" securitySettings: hsts: enabled: true includeSubdomains: true maxAgeSec: 28800
- 确保Ingress配置HTTPS
HSTS仅在HTTPS连接下生效,需为Ingress配置有效的SSL证书。例如通过注解关联GKE管理的证书:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: your-ingress annotations: networking.gke.io/managed-certificates: your-managed-cert cloud.google.com/backend-config: '{"default": "xxxx"}' spec: rules: - host: your-domain.com http: paths: - path: /* pathType: ImplementationSpecific backend: service: name: your-service port: number: 5000
- 关联BackendConfig到Service
在你的Service资源中添加注解,将BackendConfig与服务绑定:
apiVersion: v1 kind: Service metadata: name: your-service annotations: cloud.google.com/backend-config: '{"default": "xxxx"}' spec: # 你的Service配置内容
关键说明
securitySettings.hsts是GKE官方提供的HSTS配置字段,比自定义响应头更可靠,且符合cloud.google.com/v1版本的Schema要求。- 必须确保Ingress已配置HTTPS证书,否则HSTS规则不会生效。
- 移除
customResponseHeaders块即可解决unknown field的报错。
内容的提问来源于stack exchange,提问作者Gustavo Peters
相关产品推荐
相关产品推荐

