Google Cloud负载均衡器健康检查路径变更后失败求助
GCP负载均衡HTTP健康检查切换路径后失败排查
环境与背景
- 运行Ubuntu+Apache2的VM实例,通过GCP负载均衡的HTTP 80端口对外提供服务
- 外部HTTP请求通过Apache的Rewrite规则(
RewriteCond %{HTTP:X-Forwarded-Proto} =http)301重定向到HTTPS - 健康检查路径设为
/时正常,改为轻量页面/some-dir/some-page.html后失败,但该路径在非托管实例组中可正常工作
健康检查配置详情
执行gcloud compute health-checks describe health-check-name输出:
checkIntervalSec: 5 creationTimestamp: '2023-06-01T19:21:19.177-07:00' description: '' healthyThreshold: 2 httpHealthCheck: host: '' port: 80 proxyHeader: NONE requestPath: /some-dir/some-page.html id: '7467560598743870704' kind: compute#healthCheck logConfig: enable: false name: dp-instance-heartbeat-check-exclude-home selfLink: https://www.googleapis.com/compute/v1/projects/project-name/global/healthChecks/health-check-name timeoutSec: 5 type: HTTP unhealthyThreshold: 2
本地测试结果
执行curl -v example.com/some-dir/some-page.html返回:
StatusCode : 200 StatusDescription : OK Content : <!DOCTYPE HTML>... RawContent : HTTP/1.1 200 OK Pragma: no-cache... Forms : {} Headers : {[Pragma, no-cache], [Cache-Control,...} ParsedHtml : mshtml.HTMLDocumentClass ..... RawContentLength : 114051
排查方向与解决方案
检查Apache重写规则覆盖范围
GCP负载均衡的健康检查请求不会携带X-Forwarded-Proto头,若重写规则未给新路径添加例外,会触发301重定向,而健康检查不接受重定向响应。调整Apache规则:RewriteCond %{REQUEST_URI} !^/some-dir/some-page.html$ RewriteCond %{HTTP:X-Forwarded-Proto} =http RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]验证健康检查请求的Host头
健康检查配置中host字段为空,会使用实例内部IP作为Host头请求,但本地curl用的是example.com,可能Apache虚拟主机仅响应example.com的请求。可在健康检查中设置host为example.com,或修改Apache配置允许内部IP/空Host访问目标路径。检查实例防火墙与路径权限
确认VM防火墙允许GCP健康检查源IP段(130.211.0.0/22和35.191.0.0/16)访问80端口,同时排查目标路径是否有.htaccess等额外权限限制。查看Apache访问日志
直接查看VM上的Apache访问日志(通常在/var/log/apache2/access.log),过滤健康检查请求的状态码,定位实际响应问题:grep "/some-dir/some-page.html" /var/log/apache2/access.log
内容的提问来源于stack exchange,提问作者Sharad Upadhyay
相关产品推荐
相关产品推荐

