GKE内部负载均衡Ingress状态UNHEALTHY问题排查求助
问题描述
在Google Kubernetes Engine(GKE)中部署内网Web应用,参考官方文档配置了内部负载均衡Ingress,但Ingress状态显示UNHEALTHY。相关配置如下:
Deployment配置
apiVersion: apps/v1 kind: Deployment metadata: name: test namespace: default spec: replicas: 2 selector: matchLabels: app: test template: metadata: labels: app: test spec: containers: - name: test image: xxxxxxxx ports: - containerPort: 5000 protocol: TCP
Service配置
apiVersion: v1 kind: Service metadata: name: test namespace: default annotations: cloud.google.com/neg: '{"ingress": true}' spec: selector: app: test ports: - protocol: TCP port: 80 targetPort: 5000 type: ClusterIP
Ingress配置
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: test namespace: default annotations: ingress.gcp.kubernetes.io/pre-shared-cert: "cert" kubernetes.io/ingress.class: "gce-internal" kubernetes.io/ingress.regional-static-ip-name: "ip" kubernetes.io/ingress.allow-http: "false" spec: rules: - host: hostname http: paths: - path: / pathType: Prefix backend: service: name: test port: number: 80
当前现象:Service使用80端口转发到容器的5000端口,但Ingress后端健康检查直接针对5000端口显示异常,状态如下:
IP address Health status Port Host vm
******* 5000
******* 5000
需要解决Ingress状态异常问题,实现内网Web应用正常运行。
解决方案
1. 确保Pod提供健康检查端点
GCE内部Ingress配合NEG使用时,默认会直接检查Pod的容器端口(此处为5000),因此需要确保Web应用在5000端口上提供一个健康检查路径(比如/healthz),且该路径返回HTTP 200 OK状态码。
如果应用本身没有健康检查端点,可在Deployment中添加livenessProbe和readinessProbe,示例如下:
apiVersion: apps/v1 kind: Deployment metadata: name: test namespace: default spec: replicas: 2 selector: matchLabels: app: test template: metadata: labels: app: test spec: containers: - name: test image: xxxxxxxx ports: - containerPort: 5000 protocol: TCP livenessProbe: httpGet: path: /healthz port: 5000 initialDelaySeconds: 5 periodSeconds: 10 readinessProbe: httpGet: path: /healthz port: 5000 initialDelaySeconds: 3 periodSeconds: 5
2. 通过Service Annotation覆盖健康检查配置
若希望通过Service的80端口进行健康检查,而非直接访问Pod的5000端口,可在Service中添加以下Annotation指定健康检查的端口和路径:
apiVersion: v1 kind: Service metadata: name: test namespace: default annotations: cloud.google.com/neg: '{"ingress": true}' cloud.google.com/health-check-port: "80" # 指定健康检查使用Service的80端口 cloud.google.com/health-check-path: "/healthz" # 指定健康检查路径 spec: selector: app: test ports: - protocol: TCP port: 80 targetPort: 5000 type: ClusterIP
3. 适配HTTPS健康检查(因Ingress禁用HTTP)
由于Ingress配置了kubernetes.io/ingress.allow-http: "false",仅接受HTTPS流量,需确保健康检查使用HTTPS协议,可在Service中添加以下Annotation:
cloud.google.com/health-check-protocol: "HTTPS"
4. 重新部署并验证
更新Deployment和Service配置后,执行以下命令重新部署:
kubectl apply -f deployment.yaml kubectl apply -f service.yaml
等待数分钟后,通过以下命令查看Ingress状态:
kubectl describe ingress test
检查输出中的Backend部分,确认健康状态变为HEALTHY。
内容的提问来源于stack exchange,提问作者Bhaskar T

