You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AKS应用网关Ingress控制器(AGIC)无法正常工作求助

AGIC扇出Ingress配置问题修复指南

问题核心

启用AGIC后创建的Ingress无法正常工作,存在以下异常:

  • 访问根路径出现502错误,未配置的/graphana/路径反而可正常访问
  • 无法配置多路径实现扇出路由

当前Ingress配置:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: guestbook
  namespace: monitoring
  annotations:
    kubernetes.io/ingress.class: azure/application-gateway
    appgw.ingress.kubernetes.io/backend-path-prefix: /
spec:
  rules:
  - host: genix-health-hub.westeurope.cloudapp.azure.com
    http:
      paths:
      - backend:
          service:
            name: prometheus-monitoring-grafana
            port:
              number: 80
        pathType: ImplementationSpecific

修复步骤

1. 补全Ingress路径配置

当前配置缺少path字段,AGIC无法生成明确的路由规则,这是根路径502的主要原因。添加路径匹配规则,让根路径指向Grafana服务:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: guestbook
  namespace: monitoring
  annotations:
    kubernetes.io/ingress.class: azure/application-gateway
    appgw.ingress.kubernetes.io/backend-path-prefix: /
spec:
  rules:
  - host: genix-health-hub.westeurope.cloudapp.azure.com
    http:
      paths:
      - path: /
        pathType: ImplementationSpecific
        backend:
          service:
            name: prometheus-monitoring-grafana
            port:
              number: 80

2. 清理AGIC残留路由

/graphana/路径可访问是因为AGIC未同步删除旧的路由规则,解决方式:

  • 删除当前Ingress资源,等待1-2分钟让AGIC自动清理对应网关规则,再重新创建新的Ingress
  • 手动登录Azure门户,进入应用网关的规则>基于路径的路由,删除/graphana/相关的旧规则

3. 配置多路径扇出路由

要通过同一个Ingress访问多个服务,只需在paths节点下添加更多路径条目,每个条目对应不同的后端服务。示例如下(添加Prometheus服务路由):

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: guestbook
  namespace: monitoring
  annotations:
    kubernetes.io/ingress.class: azure/application-gateway
spec:
  rules:
  - host: genix-health-hub.westeurope.cloudapp.azure.com
    http:
      paths:
      - path: /
        pathType: ImplementationSpecific
        backend:
          service:
            name: prometheus-monitoring-grafana
            port:
              number: 80
      - path: /prometheus/*
        pathType: ImplementationSpecific
        backend:
          service:
            name: prometheus-kube-prometheus-prometheus
            port:
              number: 9090

若后端服务的根路径与Ingress路径不一致,可给单个路径添加backend-path-prefix注解调整。比如Ingress路径是/prometheus/,但后端服务根路径是/,可在该path的metadata.annotations中添加appgw.ingress.kubernetes.io/backend-path-prefix: "/"

4. 排查502错误的额外检查点

如果修复后仍出现502,确认以下内容:

  • 后端池中的Pod处于Running状态,且服务端口与Ingress配置一致(部分Grafana部署默认端口为3000,而非80)
  • 应用网关的健康探针配置正确,能正常探测到后端Pod的健康状态
  • 后端服务的防火墙/网络策略未阻止应用网关的访问

内容的提问来源于stack exchange,提问作者SUJITH JULAKANTI

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 07:00:00