You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为Azure Kubernetes Service中的Python Flask API容器启用HTTPS

在Azure Kubernetes Service (AKS) 中为Flask API配置HTTPS的具体方案

针对AKS环境,推荐采用Ingress Controller + 证书管理的生产级方案,避免直接在容器内维护SSL证书(不利于自动化更新和管理)。以下是两种适配Azure环境的落地方案:


方案一:NGINX Ingress Controller + Cert-Manager(自动签发Let's Encrypt证书)

1. 安装NGINX Ingress Controller

通过Helm部署官方NGINX Ingress Controller:

helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx
helm repo update
helm install ingress-nginx ingress-nginx/ingress-nginx

2. 部署Cert-Manager实现证书自动化管理

Cert-Manager可自动签发/续期Let's Encrypt免费证书:

helm repo add jetstack https://charts.jetstack.io
helm repo update
helm install cert-manager jetstack/cert-manager --namespace cert-manager --create-namespace --version v1.13.0 --set installCRDs=true

3. 配置ClusterIssuer(对接Let's Encrypt)

创建全局证书签发配置:

apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
  name: letsencrypt-prod
spec:
  acme:
    server: https://acme-v02.api.letsencrypt.org/directory
    email: your-email@example.com  # 替换为你的邮箱(用于证书过期提醒)
    privateKeySecretRef:
      name: letsencrypt-prod
    solvers:
    - http01:
        ingress:
          class: nginx

4. 修改原有Service为ClusterIP

LoadBalancer类型不再需要,Ingress会直接访问集群内部服务:

apiVersion: v1
kind: Service
metadata:
  name: flask-app-service
spec:
  selector:
    app: test-app
  ports:
  - port: <port>
    protocol: TCP
    targetPort: <port>
  type: ClusterIP

5. 配置Ingress资源(绑定HTTPS)

创建Ingress规则,关联证书和Flask服务:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: flask-app-ingress
  annotations:
    cert-manager.io/cluster-issuer: "letsencrypt-prod"
spec:
  tls:
  - hosts:
    - your-domain.com  # 替换为你的自定义域名
    secretName: flask-app-tls  # 自动生成的证书Secret名称
  rules:
  - host: your-domain.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: flask-app-service
            port:
              number: <port>

6. 调整Flask应用信任代理

由于Ingress会处理HTTPS并转发HTTP请求到Flask,需让Flask识别原始请求协议:
在Deployment中添加环境变量:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: flask-app-deployment
spec:
  selector:
    matchLabels:
      app: test-app
  template:
    metadata:
      labels:
        app: test-app
    spec:
      containers:
      - name: test-app
        image: <image>
        env:
        - name: <token-secret-env-name>
          valueFrom:
            secretKeyRef:
              name: <token-secret-name>
              key: <token-secret>
        # 添加信任代理配置,让Flask识别HTTPS请求
        - name: FLASK_TRUSTED_PROXIES
          value: "0.0.0.0/0"  # 生产环境可限制为NGINX Ingress的IP段
        imagePullPolicy: Always
        resources:
          requests:
            cpu: "500m"
            memory: "800Mi"
          limits:
            cpu: "500m"
            memory: "800Mi"
        ports:
        - containerPort: <port>

      imagePullSecrets:
      - name: <secret>

方案二:Azure Application Gateway Ingress Controller(AGIC)

如果已经使用Azure Application Gateway作为流量入口,可通过AGIC直接集成AKS:

1. 部署AGIC到AKS

遵循Azure官方流程部署AGIC(需提前创建Application Gateway)。

2. 上传SSL证书到Application Gateway

在Azure Portal将SSL证书(自签/购买/Let's Encrypt)上传到Application Gateway的证书存储。

3. 配置Ingress资源

通过Ingress注解指定Application Gateway使用的证书:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: flask-app-ingress
  annotations:
    kubernetes.io/ingress.class: azure/application-gateway
    appgw.ingress.kubernetes.io/ssl-redirect: "true"
    appgw.ingress.kubernetes.io/certificate-name: "your-cert-name"  # 替换为Application Gateway中的证书名称
spec:
  tls:
  - hosts:
    - your-domain.com
  rules:
  - host: your-domain.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: flask-app-service
            port:
              number: <port>

注意事项

  • 生产环境禁止直接在Flask容器内配置SSL证书,证书管理和续期成本极高。
  • 需确保自定义域名已解析到Ingress Controller的外部IP(或Application Gateway的公网IP)。
  • 如果使用私有证书,需将证书导入Azure Key Vault,并通过secrets-store-csi-driver挂载到Ingress Controller。

内容的提问来源于stack exchange,提问作者Jens Voorpyl

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 23:47:36