You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于AGIC直接指向AKS Pod而非Service的三类技术疑问

AGIC(应用网关入口控制器)相关疑问解答

场景背景

此前使用APIM Premium,借助VNet集成可直接与AKS中部署的内部负载均衡类型Service通信。当前测试AGIC,部署了包含2个Pod的Deployment、一个内部LoadBalancer类型的Service(存疑是否需要)以及关联该Service的Ingress。原本预期部署后App Gateway后端池指向Service的IP,但实际Ingress创建的后端池添加了两个Pod的IP,针对此场景的疑问及解答如下:


1. 是否需要使用内部LoadBalancer类型的Service,还是仅使用默认的ClusterIP类型即可?

不需要使用内部LoadBalancer类型的Service,ClusterIP类型完全满足需求。AGIC的工作逻辑是通过Kubernetes API直接获取Pod的端点(Endpoints)信息,而非依赖Service的内部负载均衡IP。内部LB Service在此场景下属于冗余配置,AGIC并不会使用它的IP地址,直接对接Pod即可。将Service改为ClusterIP类型,既能减少不必要的云资源开销,也更贴合AGIC的设计机制。

2. 目前我的.NET应用暴露8080端口,而该Service曾暴露8000端口,由于AGIC直接指向Pod,Service与Pod是否需要暴露相同端口?

不需要强制端口完全一致,但需满足两个核心匹配规则:

  • Service定义中的targetPort必须与Pod的containerPort一致(即指向应用实际监听的端口)
  • Ingress规则中指定的Service端口(port.number)必须与Service定义的port字段一致

从你提供的YAML来看,Service的port和targetPort均为8080,与Pod的containerPort匹配,这是正确的配置。若之前Service用8000端口,只要targetPort指向Pod的8080,同时Ingress中指定Service的8000端口,AGIC也能正确路由到Pod,但保持端口一致可提升配置的可读性,降低维护成本。

3. 若AGIC直接使用Pod IP,那么在自动扩缩容场景下,它能否同步添加或移除Pod的IP?

完全可以实现自动同步。AGIC会持续监听Kubernetes集群中的Endpoints资源变化:当HPA触发Pod扩缩容时,Endpoints会自动更新关联的Pod列表,AGIC会实时感知到这些变更,并同步更新App Gateway的后端池——自动添加新扩容的Pod IP,移除已销毁的Pod IP,全程无需手动干预。


示例部署YAML文件

---
apiVersion: apps/v1
kind: Deployment
metadata:
  name: sampleservice-deployment
  labels:
    app: sampleservice
spec:
  replicas: 2
  selector:
    matchLabels:
      app: sampleservice
  template:
    metadata:
      labels:
        app: sampleservice
    spec:
      containers:
        - name: sampleapi
          image: #{containerRepo}#/samplesvc:#{tag}#
          imagePullPolicy: Always
          ports:
            - containerPort: 8080
              protocol: TCP
          resources:
            requests:
              cpu: #{hpa_samplesvc_requestedcpu}#
            limits:
              cpu: #{hpa_samplesvc_maxcpulimit}#
---
apiVersion: v1
kind: Service
metadata:
  name: samplesvc
  annotations:
    service.beta.kubernetes.io/azure-load-balancer-internal: "true"
  labels:
    app: samplesvc
spec:
  ports:
    - name: http-port
      port: 8080
      protocol: TCP
      targetPort: 8080
  selector:
    app: sampleservice
  type: LoadBalancer
---
apiVersion: autoscaling/v2
<not relevant>
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: sampleingress
  annotations:
    kubernetes.io/ingress.class: azure/application-gateway
spec:
  rules:
  - http:
      paths:
      - path: /sample-path
        backend:
          service:
            name: samplesvc
            port:
              number: 8080
        pathType: Exact

内容的提问来源于stack exchange,提问作者prakashrajansakthivel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 15:07:44