Azure Kubernetes Service (AKS) 1.20.7版本下如何以IPVS代理模式启动kube-proxy以实现最小连接数负载均衡
Hey there! Let's get your AKS 1.20.7 cluster set up with kube-proxy running in IPVS mode using the least connection (lc) scheduler. I've walked through this process a few times, so here's a straightforward, step-by-step guide:
- Make sure you have the Azure CLI installed and updated to version 2.18.0 or later—this is when the
--kube-proxy-configparameter became available for configuring AKS kube-proxy settings. You can check your current version withaz --version, and update it if needed using your OS's package manager or the official Azure install script. - Ensure you have contributor-level permissions to modify your AKS cluster (or the resource group it lives in).
Since you already have a running cluster, we'll use the Azure CLI to update kube-proxy's configuration directly. This is the safest approach for managed AKS clusters (avoid manually editing the kube-proxy ConfigMap, as Azure might overwrite it during automated updates).
Run this command, replacing <your-resource-group-name> and <your-aks-cluster-name> with your actual values:
az aks update --resource-group <your-resource-group-name> --name <your-aks-cluster-name> --kube-proxy-config '{"mode": "ipvs", "ipvsScheduler": "lc"}'
Wait for the update to finish—this typically takes 5-10 minutes, depending on how many nodes are in your cluster. Azure will roll out the changes node-by-node, so your applications should stay available during the process.
Once the update completes, let's confirm everything is set up correctly:
Check the kube-proxy ConfigMap
Run this command to view the active kube-proxy configuration:kubectl get configmap kube-proxy -n kube-system -o yamlLook for the
mode: ipvsandipvsScheduler: lcentries under theconfig.confsection—this confirms the scheduler is set to prioritize least active connections.Validate kube-proxy pod startup parameters
Check that the kube-proxy pods are using the correct flags on startup:kubectl logs -n kube-system -l k8s-app=kube-proxy | grep -E "(mode|ipvs-scheduler)"You should see lines like
--mode=ipvsand--ipvs-scheduler=lcin the output, which means the pods are running with the right configuration.Inspect IPVS rules (optional deep dive)
To see the actual IPVS load balancing rules in action, exec into one of the kube-proxy pods and run theipvsadmtool:# First, get the name of a kube-proxy pod kubectl get pods -n kube-system -l k8s-app=kube-proxy # Then exec into it kubectl exec -n kube-system <kube-proxy-pod-name> -- ipvsadm -LnLook for the
Schedulercolumn in the output—each cluster service should showlcas its active scheduler.
- AKS 1.20.7 fully supports IPVS mode, so you won't run into version-specific issues here.
- Keep in mind that this configures internal cluster service routing (via kube-proxy). If you need your external Azure Load Balancer to use least connections, that's a separate setting managed through Azure's LB configuration, but it sounds like your focus is on the kube-proxy level load balancing.
内容的提问来源于stack exchange,提问作者Farzad J

