You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GKE内部负载均衡Ingress状态UNHEALTHY问题排查求助

问题描述

在Google Kubernetes Engine(GKE)中部署内网Web应用,参考官方文档配置了内部负载均衡Ingress,但Ingress状态显示UNHEALTHY。相关配置如下:

Deployment配置

apiVersion: apps/v1
kind: Deployment
metadata:
  name: test
  namespace: default
spec:
  replicas: 2
  selector:
    matchLabels:
      app: test
  template:
    metadata:
      labels:
        app: test
    spec:
      containers:
      - name: test
        image: xxxxxxxx
        ports:
        - containerPort: 5000
          protocol: TCP

Service配置

apiVersion: v1
kind: Service
metadata:
  name: test
  namespace: default
  annotations:
   cloud.google.com/neg: '{"ingress": true}'
spec:
  selector:
    app: test
  ports:
  - protocol: TCP
    port: 80
    targetPort: 5000
  type: ClusterIP

Ingress配置

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: test
  namespace: default
  annotations:
    ingress.gcp.kubernetes.io/pre-shared-cert: "cert"
    kubernetes.io/ingress.class: "gce-internal"
    kubernetes.io/ingress.regional-static-ip-name: "ip"
    kubernetes.io/ingress.allow-http: "false"
spec:
  rules:
  - host: hostname
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: test
            port:
              number: 80

当前现象:Service使用80端口转发到容器的5000端口,但Ingress后端健康检查直接针对5000端口显示异常,状态如下:

IP address Health status Port Host vm
******* 5000
******* 5000

需要解决Ingress状态异常问题,实现内网Web应用正常运行。


解决方案

1. 确保Pod提供健康检查端点

GCE内部Ingress配合NEG使用时,默认会直接检查Pod的容器端口(此处为5000),因此需要确保Web应用在5000端口上提供一个健康检查路径(比如/healthz),且该路径返回HTTP 200 OK状态码。

如果应用本身没有健康检查端点,可在Deployment中添加livenessProbe和readinessProbe,示例如下:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: test
  namespace: default
spec:
  replicas: 2
  selector:
    matchLabels:
      app: test
  template:
    metadata:
      labels:
        app: test
    spec:
      containers:
      - name: test
        image: xxxxxxxx
        ports:
        - containerPort: 5000
          protocol: TCP
        livenessProbe:
          httpGet:
            path: /healthz
            port: 5000
          initialDelaySeconds: 5
          periodSeconds: 10
        readinessProbe:
          httpGet:
            path: /healthz
            port: 5000
          initialDelaySeconds: 3
          periodSeconds: 5

2. 通过Service Annotation覆盖健康检查配置

若希望通过Service的80端口进行健康检查,而非直接访问Pod的5000端口,可在Service中添加以下Annotation指定健康检查的端口和路径:

apiVersion: v1
kind: Service
metadata:
  name: test
  namespace: default
  annotations:
   cloud.google.com/neg: '{"ingress": true}'
   cloud.google.com/health-check-port: "80"  # 指定健康检查使用Service的80端口
   cloud.google.com/health-check-path: "/healthz"  # 指定健康检查路径
spec:
  selector:
    app: test
  ports:
  - protocol: TCP
    port: 80
    targetPort: 5000
  type: ClusterIP

3. 适配HTTPS健康检查(因Ingress禁用HTTP)

由于Ingress配置了kubernetes.io/ingress.allow-http: "false",仅接受HTTPS流量,需确保健康检查使用HTTPS协议,可在Service中添加以下Annotation:

cloud.google.com/health-check-protocol: "HTTPS"

4. 重新部署并验证

更新Deployment和Service配置后,执行以下命令重新部署:

kubectl apply -f deployment.yaml
kubectl apply -f service.yaml

等待数分钟后,通过以下命令查看Ingress状态:

kubectl describe ingress test

检查输出中的Backend部分,确认健康状态变为HEALTHY。


内容的提问来源于stack exchange,提问作者Bhaskar T

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 09:42:39