如何在Azure应用网关中永久固定后端设置的超时值?
解决方案
1. 通过Ingress注解固化Azure应用网关超时配置
如果你的AKS集群使用应用网关Ingress控制器(AGIC),手动修改应用网关的配置会被AGIC自动覆盖——因为AGIC会根据Kubernetes Ingress资源的定义同步应用网关设置。你需要在Ingress资源中添加专属注解,让AGIC自动配置超时参数:
在Ingress YAML文件中添加以下注解:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: your-ingress-name annotations: # 设置后端请求超时时间(单位:秒) appgw.ingress.kubernetes.io/backend-request-timeout: "120" # 设置健康探测请求超时时间(根据实际需求调整) appgw.ingress.kubernetes.io/probe-request-timeout: "30" # 可选:设置健康探测间隔时间 appgw.ingress.kubernetes.io/probe-interval: "30" spec: # 你的Ingress规则配置...
应用更新后的Ingress配置:
kubectl apply -f your-ingress-file.yaml
AGIC会自动将这些配置同步到Azure应用网关,后续Pod重建或扩缩容时,应用网关的超时设置不会被重置。
2. 固化Nginx超时配置(避免Pod重建后重置)
手动修改Pod内的nginx.conf.d文件是临时性的,Pod重建后会恢复镜像默认配置,你需要通过以下两种方式持久化配置:
方式一:使用ConfigMap挂载自定义配置
创建包含超时参数的ConfigMap:
apiVersion: v1 kind: ConfigMap metadata: name: nginx-timeout-config data: custom-timeouts.conf: | keepalive_timeout 120s; send_timeout 120s; client_body_timeout 120s; client_header_timeout 120s; proxy_connect_timeout 120s; proxy_read_timeout 120s; proxy_send_timeout 120s; fastcgi_connect_timeout 120s; fastcgi_read_timeout 120s; fastcgi_send_timeout 120s; memcached_connect_timeout 120s; memcached_read_timeout 120s; memcached_send_timeout 120s;
将ConfigMap挂载到Nginx Pod的conf.d目录下,修改后端Deployment的YAML:
apiVersion: apps/v1 kind: Deployment metadata: name: your-backend-deployment spec: template: spec: containers: - name: nginx-container image: your-nginx-image volumeMounts: - name: nginx-config-volume mountPath: /etc/nginx/conf.d/custom-timeouts.conf subPath: custom-timeouts.conf volumes: - name: nginx-config-volume configMap: name: nginx-timeout-config
应用更新后的Deployment:
kubectl apply -f your-backend-deployment.yaml
方式二:将配置打包进自定义镜像
基于官方Nginx镜像构建包含自定义超时配置的镜像,创建Dockerfile:
FROM nginx:alpine # 将本地的自定义配置文件复制到容器内的conf.d目录 COPY custom-timeouts.conf /etc/nginx/conf.d/
构建并推送镜像到容器注册表(比如Azure Container Registry):
docker build -t your-acr-registry.azurecr.io/custom-nginx:v1 . docker push your-acr-registry.azurecr.io/custom-nginx:v1
更新后端Deployment使用这个自定义镜像:
spec: template: spec: containers: - name: nginx-container image: your-acr-registry.azurecr.io/custom-nginx:v1
3. 检查部署模板的硬编码配置
如果你的应用是通过Helm或其他部署工具部署的,检查部署模板(比如Helm的values.yaml)中是否存在硬编码的默认超时参数,确保将其修改为120秒后重新部署,避免Pod重建时加载默认值。
内容的提问来源于stack exchange,提问作者Harry1234
相关产品推荐
相关产品推荐

