跨命名空间GKE内部Ingress配置问题:单ILB访问多服务
问题:GCE内部Ingress跨命名空间访问服务失败
需求:使用单个带内部IP的GCE内部应用负载均衡器,访问不同命名空间中的多个服务。
现状:Ingress与服务同命名空间时可正常工作,Ingress在namespace1、服务在其他命名空间时无法运行。尝试用ExternalName Service做桥接失败,报错:Translation failed: invalid ingress spec: could not find port "&ServiceBackendPort{Name:,Number:80,}" in service "namespace1/hostname-bridge"
当前配置如下:
Ingress配置(namespace1)
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: ilb-demo-ingress namespace: namespace1 annotations: kubernetes.io/ingress.class: "gce-internal" spec: rules: - host: test.de http: paths: - backend: service: name: paketmap port: number: 80 path: / pathType: ImplementationSpecific - host: test2.de http: paths: - backend: service: name: hostname port: number: 80 path: / pathType: ImplementationSpecific
Service1配置(paketmap命名空间)
kind: Service metadata: name: hostname namespace: paketmap annotations: cloud.google.com/neg: '{"ingress": true}' spec: ports: - name: host1 port: 80 protocol: TCP targetPort: 9376 selector: app: hostname type: ClusterIP
Service2配置(namespace1命名空间)
apiVersion: v1 kind: Service metadata: name: paketmap namespace: namespace1 annotations: cloud.google.com/neg: '{"ingress": true}' spec: ports: - name: host1 port: 80 protocol: TCP targetPort: 8080 selector: app: paketmap type: ClusterIP
解决方案
GCE内部Ingress不支持直接引用其他命名空间的Service,ExternalName Service无法满足要求是因为它没有端口的端点映射,GCE Ingress需要关联的Service具备可解析的端口和后端端点(或NEG配置)。正确做法是在Ingress所在的namespace1中创建一个ClusterIP代理Service,指向目标命名空间的Service:
步骤1:在namespace1中创建代理Service
创建名为hostname-bridge的ClusterIP Service,通过externalName指向paketmap命名空间的hostname Service(格式为hostname.paketmap.svc.cluster.local),同时明确端口配置:
apiVersion: v1 kind: Service metadata: name: hostname-bridge namespace: namespace1 annotations: cloud.google.com/neg: '{"ingress": true}' # 与原Service保持一致的NEG配置 spec: type: ClusterIP ports: - name: host1 port: 80 protocol: TCP targetPort: 80 externalName: hostname.paketmap.svc.cluster.local
步骤2:修改Ingress配置
将Ingress中指向其他命名空间的Service部分,替换为刚创建的代理Service:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: ilb-demo-ingress namespace: namespace1 annotations: kubernetes.io/ingress.class: "gce-internal" spec: rules: - host: test.de http: paths: - backend: service: name: paketmap port: number: 80 path: / pathType: ImplementationSpecific - host: test2.de http: paths: - backend: service: name: hostname-bridge # 替换为代理Service名称 port: number: 80 path: / pathType: ImplementationSpecific
关键说明
- GCE Ingress仅能引用同一命名空间的Service,必须通过同命名空间的代理Service中转
- 代理Service需要配置与目标Service一致的端口名称和编号,确保Ingress能正确识别端口
- 保留
cloud.google.com/neg注解,确保Ingress能创建对应的网络端点组(NEG),维持原有的负载均衡能力
内容的提问来源于stack exchange,提问作者Asis
相关产品推荐
相关产品推荐

