AKS应用网关Ingress控制器(AGIC)无法正常工作求助
AGIC扇出Ingress配置问题修复指南
问题核心
启用AGIC后创建的Ingress无法正常工作,存在以下异常:
- 访问根路径出现502错误,未配置的
/graphana/路径反而可正常访问 - 无法配置多路径实现扇出路由
当前Ingress配置:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: guestbook namespace: monitoring annotations: kubernetes.io/ingress.class: azure/application-gateway appgw.ingress.kubernetes.io/backend-path-prefix: / spec: rules: - host: genix-health-hub.westeurope.cloudapp.azure.com http: paths: - backend: service: name: prometheus-monitoring-grafana port: number: 80 pathType: ImplementationSpecific
修复步骤
1. 补全Ingress路径配置
当前配置缺少path字段,AGIC无法生成明确的路由规则,这是根路径502的主要原因。添加路径匹配规则,让根路径指向Grafana服务:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: guestbook namespace: monitoring annotations: kubernetes.io/ingress.class: azure/application-gateway appgw.ingress.kubernetes.io/backend-path-prefix: / spec: rules: - host: genix-health-hub.westeurope.cloudapp.azure.com http: paths: - path: / pathType: ImplementationSpecific backend: service: name: prometheus-monitoring-grafana port: number: 80
2. 清理AGIC残留路由
/graphana/路径可访问是因为AGIC未同步删除旧的路由规则,解决方式:
- 删除当前Ingress资源,等待1-2分钟让AGIC自动清理对应网关规则,再重新创建新的Ingress
- 手动登录Azure门户,进入应用网关的
规则>基于路径的路由,删除/graphana/相关的旧规则
3. 配置多路径扇出路由
要通过同一个Ingress访问多个服务,只需在paths节点下添加更多路径条目,每个条目对应不同的后端服务。示例如下(添加Prometheus服务路由):
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: guestbook namespace: monitoring annotations: kubernetes.io/ingress.class: azure/application-gateway spec: rules: - host: genix-health-hub.westeurope.cloudapp.azure.com http: paths: - path: / pathType: ImplementationSpecific backend: service: name: prometheus-monitoring-grafana port: number: 80 - path: /prometheus/* pathType: ImplementationSpecific backend: service: name: prometheus-kube-prometheus-prometheus port: number: 9090
若后端服务的根路径与Ingress路径不一致,可给单个路径添加
backend-path-prefix注解调整。比如Ingress路径是/prometheus/,但后端服务根路径是/,可在该path的metadata.annotations中添加appgw.ingress.kubernetes.io/backend-path-prefix: "/"
4. 排查502错误的额外检查点
如果修复后仍出现502,确认以下内容:
- 后端池中的Pod处于
Running状态,且服务端口与Ingress配置一致(部分Grafana部署默认端口为3000,而非80) - 应用网关的健康探针配置正确,能正常探测到后端Pod的健康状态
- 后端服务的防火墙/网络策略未阻止应用网关的访问
内容的提问来源于stack exchange,提问作者SUJITH JULAKANTI
相关产品推荐
相关产品推荐

