You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在AWS集群通过Helm安装Ingress-Nginx后未分配External-IP问题

问题:Ingress-Nginx控制器安装后未分配External-IP

环境与操作背景

  • 使用AWS EKS集群,通过Helm Chart安装Ingress-Nginx控制器
  • 已手动创建Application Load Balancer(ALB)并获取其静态IP
  • 修改了Ingress-Nginx Chart的values.yaml配置,执行了Helm安装命令

修改后的values.yaml中service段配置

service:
enabled: true
# -- If enabled is adding an appProtocol option for Kubernetes service. An appProtocol field replacing annotations that were
# using for setting a backend protocol. Here is an example for AWS: service.beta.kubernetes.io/aws-load-balancer-backend-protocol: http
# It allows choosing the protocol for each backend specified in the Kubernetes service.
# See the following GitHub issue for more details about the purpose: https://github.com/kubernetes/kubernetes/issues/40244
# Will be ignored for Kubernetes versions older than 1.20
##
appProtocol: true
annotations:
  kubernetes.io/ingress.class: alb 
  alb.ingress.kubernetes.io/scheme: internet-facing
  #alb.ingress.kubernetes.io/target-type: instance 

labels: {}
clusterIP: "XXX.XXX.XXX.XXX"

# -- List of IP addresses at which the controller services are available
## Ref: https://kubernetes.io/docs/user-guide/services/#external-ips
##
externalIPs: []
# -- Used by cloud providers to connect the resulting `LoadBalancer` to a pre-existing static IP according to https://kubernetes.io/docs/concepts/services-networking/service/#loadbalancer
loadBalancerIP: "XXX.XXX.XXX.XXX"
loadBalancerSourceRanges: []
enableHttp: true
enableHttps: true
ipFamilyPolicy: "SingleStack"
# -- List of IP families (e.g. IPv4, IPv6) assigned to the service. This field is usually assigned automatically
# based on cluster configuration and the ipFamilyPolicy field.
## Ref: https://kubernetes.io/docs/concepts/services-networking/dual-stack/
ipFamilies:
  - IPv4
ports:
  http: 80
  https: 443
targetPorts:
  http: http
  https: https
type: LoadBalancer

执行的Helm安装命令

helm upgrade --install ingress-nginx ingress-nginx   --repo https://kubernetes.github.io/ingress-nginx   --namespace ingress-nginx --create-namespace -f values.yaml

问题现象

安装完成后,执行kubectl get svc -n ingress-nginx查看服务状态,发现Ingress-Nginx服务的External-IP字段为空,未绑定预先创建的ALB静态IP。


排查与解决方案

1. 修正Ingress Class配置冲突

Ingress-Nginx控制器默认使用的ingress class是nginx,你配置的kubernetes.io/ingress.class: alb会导致与AWS ALB Ingress Controller的配置逻辑混淆。需移除该注解:

annotations:
  # 移除该行:kubernetes.io/ingress.class: alb 
  alb.ingress.kubernetes.io/scheme: internet-facing

2. 明确负载均衡器类型匹配规则

Ingress-Nginx的Service类型设为LoadBalancer时,AWS默认会创建Classic Load Balancer(CLB)或Network Load Balancer(NLB),无法直接绑定手动创建的ALB。若要使用ALB,需部署AWS Load Balancer Controller,并通过Ingress资源触发ALB创建,而非直接给Ingress-Nginx的Service绑定静态IP。

3. 验证静态IP的可用性与兼容性

确保你指定的loadBalancerIP是同一VPC下未被占用的弹性公网IP(EIP),且仅用于绑定NLB(AWS不支持将EIP直接绑定到ALB)。

4. 检查服务事件与控制器日志

  • 查看Service的事件详情,排查绑定失败原因:
    kubectl describe svc ingress-nginx-controller -n ingress-nginx
    
  • 查看Ingress-Nginx控制器日志,确认配置加载与启动状态:
    kubectl logs -n ingress-nginx deployment/ingress-nginx-controller
    

5. 预创建NLB的绑定方式(若需使用静态IP)

若要让Ingress-Nginx绑定预创建的NLB:

  1. 将EIP关联到NLB的节点端口
  2. 确保Service的loadBalancerIP设置为NLB的静态IP
  3. 配置集群节点安全组,允许NLB访问Ingress-Nginx的80/443端口

内容的提问来源于stack exchange,提问作者Raj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 08:04:57