Kubernetes Ingress Nginx金丝雀路由异常:流量全流向nginx2求助
Kubernetes Ingress Nginx金丝雀路由流量异常排查
核心问题:Ingress配置逻辑错误
你的Ingress配置存在两个致命问题,导致所有流量都流向nginx2:
1. 缺少主Ingress,两个Ingress都启用金丝雀模式
Ingress Nginx的金丝雀路由机制要求:
- 必须有一个主Ingress(不添加
nginx.ingress.kubernetes.io/canary: "true"注解)作为默认流量入口; - 金丝雀Ingress(添加
canary: "true"注解)仅用于从主Ingress分流指定比例的流量,同一域名下可以有多个金丝雀Ingress,但主Ingress必须唯一存在。
你的配置中,nginx1和nginx2的Ingress都标记为金丝雀模式,控制器无法识别默认流量入口,最终会根据资源优先级(如名称排序、创建顺序等)将所有流量导向其中一个服务,这里恰好是nginx2。
2. 对金丝雀权重的理解错误
nginx.ingress.kubernetes.io/canary-weight的作用是指定金丝雀Ingress从主Ingress分流的流量比例,而非多个金丝雀Ingress之间的流量分配。例如:
- 主Ingress接收100%流量;
- 若金丝雀Ingress权重设为20,则20%流量会被分流到金丝雀服务,剩余80%仍由主Ingress处理。
你试图给两个金丝雀Ingress分别设置80和20的权重,这不符合控制器的逻辑,无法实现预期的流量分配。
次要问题:nginx1 Deployment未挂载ConfigMap
你的nginx1 Deployment定义中,仅声明了volume,但没有给容器添加volumeMounts配置,导致ConfigMap中的自定义首页无法挂载到容器的/usr/share/nginx/html/目录,nginx1会一直使用默认首页。
修正后的配置示例
1. 主Ingress(指向nginx1,承担80%流量)
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: nginx-main namespace: test spec: rules: - host: ehsan.test.com http: paths: - pathType: Prefix path: / backend: service: name: nginx1 port: number: 80
2. 金丝雀Ingress(指向nginx2,分流20%流量)
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: nginx-canary namespace: test annotations: nginx.ingress.kubernetes.io/canary: "true" nginx.ingress.kubernetes.io/canary-weight: "20" spec: rules: - host: ehsan.test.com http: paths: - pathType: Prefix path: / backend: service: name: nginx2 port: number: 80
3. 修正后的nginx1 Deployment(添加volumeMounts)
apiVersion: apps/v1 kind: Deployment metadata: name: nginx1-deployment namespace: test labels: app: nginx1 spec: selector: matchLabels: app: nginx1 template: metadata: labels: app: nginx1 spec: containers: - name: nginx image: nginx:1.24.0 ports: - containerPort: 80 volumeMounts: - name: config-volume mountPath: /usr/share/nginx/html/ readOnly: true volumes: - name: config-volume configMap: name: nginx-configmap items: - key: nginx1-content path: index.html
验证步骤
- 应用修正后的配置:
kubectl apply -f nginx-main-ingress.yaml -f nginx-canary-ingress.yaml -f nginx1-deployment.yaml
- 查看Ingress控制器日志,确认路由规则已正确加载;
- 多次访问
ehsan.test.com,统计返回v1和v2的比例,验证流量分配是否符合预期。
内容的提问来源于stack exchange,提问作者ehsan Behnampour
相关产品推荐
相关产品推荐

