You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在启用ssl-passthrough的Nginx Ingress中配置HSTS头?

可行解决方案

1. 让后端服务直接返回HSTS头

由于ssl-passthrough是TCP层透传,Ingress不会解析任何HTTP流量,所有SSL握手、HTTP请求/响应都直接在客户端和后端服务之间完成,Ingress根本碰不到HTTP响应头,所以无法通过Ingress的注解来添加HSTS。

最直接的解决方式是在后端Web服务中配置HSTS响应头,比如:

  • 如果后端是Nginx,在配置中添加:
    add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload";
    
  • 如果后端是Apache,添加:
    Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
    

其他Web服务(如Tomcat、Node.js服务)也都有对应的响应头配置方式,直接在后端配置后,响应会自动携带HSTS头。

2. 放弃ssl-passthrough,改用Ingress终止SSL(业务允许的情况下)

如果你的业务不需要将SSL连接完整透传给后端,而是可以让Ingress来处理SSL终止,那么就能正常使用Ingress的HSTS配置:

  • 将SSL证书存储到Kubernetes Secret中,关联到Ingress
  • 删除ssl-passthrough注解
  • 添加HSTS相关配置,比如:
    annotations:
      nginx.ingress.kubernetes.io/hsts: "true"
      nginx.ingress.kubernetes.io/hsts-max-age: "31536000"
      nginx.ingress.kubernetes.io/hsts-include-subdomains: "true"
      nginx.ingress.kubernetes.io/hsts-preload: "true"
    
  • 如果后端需要HTTPS协议通信,额外添加:
    nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
    

内容的提问来源于stack exchange,提问作者Nithin B

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 14:56:24