在OpenShift上通过认证Operator部署的Nginx Ingress Controller暴露TCP服务的技术咨询
When dealing with an Operator-deployed Nginx Ingress Controller, manual changes to the Deployment won't persist because the Operator owns and manages that resource. Here are three reliable approaches to expose your TCP services properly:
1. Configure TCP Services via the NginxIngressController Custom Resource (Recommended)
Most certified Nginx Ingress Operators for OpenShift support defining TCP/UDP services directly in the custom resource (CR) that controls the controller. This is the cleanest method since the Operator will automatically sync the configuration to the Deployment.
Step 1: Create a TCP Services ConfigMap
First, define the mapping of external ports to your backend services in a ConfigMap. Replace the namespace and service details with your own:
apiVersion: v1 kind: ConfigMap metadata: name: tcp-services namespace: openshift-ingress # Use the namespace where your Nginx Ingress Controller is installed data: # Format: <external-port>: "<service-namespace>/<service-name>:<service-port>" 3306: "default/mysql-db:3306" 6379: "redis/redis-cluster:6379"
Apply the ConfigMap with:
oc apply -f tcp-services-configmap.yaml
Step 2: Update the NginxIngressController CR
Edit the CR that manages your Nginx Ingress Controller (replace the name and namespace as needed):
oc edit nginxingresscontroller nginx-ingress-controller -n openshift-ingress
Add the tcp section under spec to reference your ConfigMap:
spec: # ... existing fields ... tcp: services: configMapName: tcp-services
Save the changes. The Operator will automatically update the Controller Deployment to include the --tcp-services-configmap parameter, and this configuration will persist through Operator upgrades or reconciliations.
2. Add Custom Command-Line Arguments via the CR
If your Operator's CR doesn't have a dedicated tcp section, check for an extraArgs or similar field to inject the required parameter directly:
Edit the NginxIngressController CR:
oc edit nginxingresscontroller nginx-ingress-controller -n openshift-ingress
Add the argument under the controller configuration (the exact path may vary by Operator version; check the CRD definition if unsure):
spec: controller: extraArgs: tcp-services-configmap: "openshift-ingress/tcp-services"
Save and wait for the Operator to reconcile the Deployment. This will add the parameter persistently.
3. Use OpenShift TCP Routes (Alternative)
If you don't strictly need to use the Nginx Ingress Controller, OpenShift's built-in Router (HAProxy) supports TCP routes natively. This skips the need to configure the Nginx Controller entirely:
Create a TCP Route for your service:
apiVersion: route.openshift.io/v1 kind: Route metadata: name: mysql-tcp-route namespace: default spec: port: targetPort: 3306 to: kind: Service name: mysql-db # Optional: Add TLS termination if you need encrypted traffic tls: termination: passthrough wildcardPolicy: None
Apply the route with:
oc apply -f mysql-tcp-route.yaml
OpenShift will automatically allocate an external port for the route, which you can find with oc get route mysql-tcp-route.
Notes
- Always verify the CR structure for your specific Operator version by checking the CRD definition (
oc describe crd nginxingresscontrollers) or the Operator's documentation in the OpenShift Marketplace. - Ensure the ConfigMap is in the same namespace as the Nginx Ingress Controller, or reference it with the full namespace path.
内容的提问来源于stack exchange,提问作者vijaykumar nemannavar

