You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

NestJS+AKS+AGIC部署遇502 Bad Gateway错误,求排查方案

NestJS应用部署AKS+AGIC后502 Bad Gateway排查与解决

问题概述

  • 基于NestJS开发的后端应用部署到AKS,通过Application Gateway Ingress Controller(AGIC)暴露至公网,Deployment、Service、Ingress均部署成功,但通过配置域名访问API时返回502 Bad Gateway错误。
  • 相同配置部署React应用可正常运行,NestJS应用触发错误;已确认Pod与Service处于运行状态,应用启动日志无异常。
  • 执行kubectl port-forward svc/app-nestjs -n default 8082:80后测试NestJS应用,功能符合预期。

现有配置

Ingress配置

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: test
  namespace: default
  annotations:
    kubernetes.io/ingress.class: azure/application-gateway
    cert-manager.io/cluster-issuer: letsencrypt-production
    appgw.ingress.kubernetes.io/ssl-redirect: "true"
    # appgw.ingress.kubernetes.io/backend-path-prefix: "/"
spec:
  tls:
    - hosts:
      - domain.dev
      secretName: app-tls
  rules:
    - host: domain.dev
      http:
        paths:
        # - path: /
        #   pathType: Prefix
        #   backend:
        #     service:
        #       name: app-react
        #       port:
        #         number: 80
        - path: / 
          pathType: Prefix
          backend:
            service:
              name: app-nestjs
              port:
                number: 80

Ingress状态信息

Name:             test
Labels:           <none>
Namespace:        default
Address:          xx.xxx.xx.xxx
Ingress Class:    <none>
Default backend:  <default>
TLS:
  app-tls terminates domain.dev
Rules:
  Host          Path  Backends
  ----          ----  --------
  domain.dev  
                /   app-nestjs:80 (192.168.0.53:80)
Annotations:    appgw.ingress.kubernetes.io/ssl-redirect: true
                cert-manager.io/cluster-issuer: letsencrypt-production
                kubernetes.io/ingress.class: azure/application-gateway
Events:         <none>

调试排查方法

  • 查看AGIC同步日志:执行kubectl logs -n kube-system deployment/azure-ingress -f,监控AGIC与Application Gateway的配置同步过程,排查是否存在配置推送失败、后端实例注册异常等信息。
  • 检查Application Gateway后端池健康状态:登录Azure门户,找到对应的Application Gateway,进入「后端池」查看NestJS服务对应的实例状态。若实例显示不健康,说明健康检查未通过,是502的常见原因。
  • 验证健康检查规则匹配性:AGIC默认使用/作为健康检查路径,若NestJS应用在/路径未返回200状态码(比如根路径无接口返回404),会导致健康检查失败。可通过Ingress注解指定健康检查接口。
  • 测试跨子网连通性:在AKS集群中创建调试Pod,执行kubectl run -it --rm debug-pod --image=curlimages/curl,然后curl NestJS Pod的IP:80,确认Application Gateway所在子网能正常访问Pod。
  • 分析Application Gateway诊断日志:在Azure门户开启Application Gateway的诊断日志,查看「ApplicationGatewayAccessLog」和「ApplicationGatewayPerformanceLog」,定位502请求的具体错误细节(如连接超时、后端无响应等)。

解决方案建议

  • 配置自定义健康检查路径:如果NestJS根路径不返回200,添加Ingress注解指定健康检查接口,示例:
    annotations:
      appgw.ingress.kubernetes.io/health-probe-path: "/health"
      appgw.ingress.kubernetes.io/health-probe-port: "80"
      appgw.ingress.kubernetes.io/health-probe-protocol: "Http"
    
  • 确认NestJS监听地址:确保NestJS应用监听0.0.0.0而非localhost,否则仅Pod内部可访问,外部无法连接。
  • 临时关闭SSL重定向排查:注释appgw.ingress.kubernetes.io/ssl-redirect: "true",用HTTP访问测试是否正常,排除TLS配置导致的问题。
  • 调整路径转发规则:若NestJS接口有统一前缀(如/api),添加appgw.ingress.kubernetes.io/backend-path-prefix: "/api"注解,确保路径转发正确匹配。

内容的提问来源于stack exchange,提问作者user13597830

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 00:01:37