You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

跨命名空间GKE内部Ingress配置问题:单ILB访问多服务

问题:GCE内部Ingress跨命名空间访问服务失败

需求:使用单个带内部IP的GCE内部应用负载均衡器,访问不同命名空间中的多个服务。
现状:Ingress与服务同命名空间时可正常工作,Ingress在namespace1、服务在其他命名空间时无法运行。尝试用ExternalName Service做桥接失败,报错:Translation failed: invalid ingress spec: could not find port "&ServiceBackendPort{Name:,Number:80,}" in service "namespace1/hostname-bridge"

当前配置如下:

Ingress配置(namespace1)

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: ilb-demo-ingress
  namespace: namespace1
  annotations:
    kubernetes.io/ingress.class: "gce-internal"
spec:
  rules:
  - host: test.de
    http:
      paths:
      - backend:
          service:
            name: paketmap
            port:
              number: 80
        path: /
        pathType: ImplementationSpecific
  - host: test2.de
    http:
      paths:
      - backend:
          service:
            name: hostname
            port:
              number: 80
        path: /
        pathType: ImplementationSpecific

Service1配置(paketmap命名空间)

kind: Service
metadata:
  name: hostname
  namespace: paketmap
  annotations:
    cloud.google.com/neg: '{"ingress": true}'
spec:
  ports:
  - name: host1
    port: 80
    protocol: TCP
    targetPort: 9376
  selector:
    app: hostname
  type: ClusterIP

Service2配置(namespace1命名空间)

apiVersion: v1
kind: Service
metadata:
  name: paketmap
  namespace: namespace1
  annotations:
    cloud.google.com/neg: '{"ingress": true}'
spec:
  ports:
  - name: host1
    port: 80
    protocol: TCP
    targetPort: 8080
  selector:
    app: paketmap
  type: ClusterIP

解决方案

GCE内部Ingress不支持直接引用其他命名空间的Service,ExternalName Service无法满足要求是因为它没有端口的端点映射,GCE Ingress需要关联的Service具备可解析的端口和后端端点(或NEG配置)。正确做法是在Ingress所在的namespace1中创建一个ClusterIP代理Service,指向目标命名空间的Service:

步骤1:在namespace1中创建代理Service

创建名为hostname-bridge的ClusterIP Service,通过externalName指向paketmap命名空间的hostname Service(格式为hostname.paketmap.svc.cluster.local),同时明确端口配置:

apiVersion: v1
kind: Service
metadata:
  name: hostname-bridge
  namespace: namespace1
  annotations:
    cloud.google.com/neg: '{"ingress": true}' # 与原Service保持一致的NEG配置
spec:
  type: ClusterIP
  ports:
  - name: host1
    port: 80
    protocol: TCP
    targetPort: 80
  externalName: hostname.paketmap.svc.cluster.local

步骤2:修改Ingress配置

将Ingress中指向其他命名空间的Service部分,替换为刚创建的代理Service:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: ilb-demo-ingress
  namespace: namespace1
  annotations:
    kubernetes.io/ingress.class: "gce-internal"
spec:
  rules:
  - host: test.de
    http:
      paths:
      - backend:
          service:
            name: paketmap
            port:
              number: 80
        path: /
        pathType: ImplementationSpecific
  - host: test2.de
    http:
      paths:
      - backend:
          service:
            name: hostname-bridge # 替换为代理Service名称
            port:
              number: 80
        path: /
        pathType: ImplementationSpecific

关键说明

  • GCE Ingress仅能引用同一命名空间的Service,必须通过同命名空间的代理Service中转
  • 代理Service需要配置与目标Service一致的端口名称和编号,确保Ingress能正确识别端口
  • 保留cloud.google.com/neg注解,确保Ingress能创建对应的网络端点组(NEG),维持原有的负载均衡能力

内容的提问来源于stack exchange,提问作者Asis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 13:05:14