You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过GCP Kubernetes Gateway API实现IP白名单过滤?

在GCP Gateway API中实现IP白名单过滤

核心实现方式:使用Gateway API关联Cloud Armor安全策略
GCP的Gateway API(基于GKE L7 Gateway Controller)可以通过绑定Cloud Armor安全策略实现IP白名单,功能等效于Nginx Ingress的nginx.ingress.kubernetes.io/whitelist-source-range注解。

步骤1:创建Cloud Armor安全策略

定义仅允许指定IP段访问的安全策略,示例如下(允许192.168.1.0/24和10.0.0.0/8,拒绝其他所有IP):

apiVersion: compute.cnrm.cloud.google.com/v1beta1
kind: ComputeSecurityPolicy
metadata:
  name: ip-whitelist-policy
spec:
  description: "仅允许可信IP段访问"
  rules:
    - action: "allow"
      priority: 1000
      match:
        versionedExpr: "SRC_IPS_V1"
        config:
          srcIpRanges:
            - "192.168.1.0/24"
            - "10.0.0.0/8"
    - action: "deny(403)"
      priority: 2000
      match:
        versionedExpr: "SRC_IPS_V1"
        config:
          srcIpRanges:
            - "0.0.0.0/0"

步骤2:关联安全策略到Gateway API资源

方式A:全局绑定到Gateway(所有路由生效)

如果要让该Gateway下的所有路由都应用白名单,在Gateway资源的注解中添加绑定:

apiVersion: gateway.networking.k8s.io/v1beta1
kind: Gateway
metadata:
  name: my-gateway
  annotations:
    networking.gke.io/security-policy: "ip-whitelist-policy"
spec:
  gatewayClassName: gke-l7-gateway-v2
  listeners:
    - name: http
      port: 80
      protocol: HTTP

方式B:单独绑定到HTTPRoute(指定路由生效)

仅给特定路由应用白名单,在HTTPRoute的filters中添加SecurityPolicy扩展引用:

apiVersion: gateway.networking.k8s.io/v1beta1
kind: HTTPRoute
metadata:
  name: my-route
spec:
  parentRefs:
    - name: my-gateway
  hostnames:
    - "example.com"
  rules:
    - matches:
        - path:
            type: PathPrefix
            value: /
      filters:
        - type: ExtensionRef
          extensionRef:
            group: networking.gke.io
            kind: SecurityPolicy
            name: ip-whitelist-policy
      backendRefs:
        - name: my-service
          port: 80

关键注意事项

  • 必须使用GKE L7 Gateway Controller v2(对应gatewayClassName: gke-l7-gateway-v2),旧版本不支持该功能。
  • Cloud Armor策略优先级:数值越小优先级越高,因此先匹配允许规则,再执行全局拒绝。
  • 可通过gcloud compute security-policies describe ip-whitelist-policy命令验证策略配置。

内容的提问来源于stack exchange,提问作者Capybara

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 00:45:21