You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes集群特定请求转发至代理机以实现在线许可证验证

Kubernetes环境下无公网集群的许可证验证流量转发方案

我们的微服务依赖付费软件,该软件需通过在线许可证验证才能运行,但集群部署在无互联网访问权限的VPC中,仅一台代理机可访问许可证服务器域名,且付费库硬编码了许可证服务器URL无法修改。以下是Kubernetes环境中的推荐实现方式:


1. 集群级DNS劫持+代理服务(推荐)

通过CoreDNS将硬编码的许可证服务器域名解析到集群内部的代理服务,再由代理服务将请求转发至外部代理机。这种方案配置集中,维护成本低,适配URL硬编码场景。

实施步骤:

  • 部署内部代理服务:用Nginx/Envoy部署代理服务,配置其将请求转发至外部代理机。示例Nginx Deployment配置:

    apiVersion: apps/v1
    kind: Deployment
    metadata:
      name: license-proxy
    spec:
      replicas: 1
      selector:
        matchLabels:
          app: license-proxy
      template:
        metadata:
          labels:
            app: license-proxy
        spec:
          containers:
          - name: nginx
            image: nginx:alpine
            volumeMounts:
            - name: nginx-config
              mountPath: /etc/nginx/conf.d
            ports:
            - containerPort: 80
          volumes:
          - name: nginx-config
            configMap:
              name: license-proxy-config
    ---
    apiVersion: v1
    kind: ConfigMap
    metadata:
      name: license-proxy-config
    data:
      default.conf: |
        server {
            listen 80;
            server_name license.example.com; # 替换为实际许可证服务器域名
            location / {
                proxy_pass http://192.168.1.100:8080; # 替换为代理机IP和端口
                proxy_set_header Host $host;
                proxy_set_header X-Forwarded-For $remote_addr;
            }
        }
    ---
    apiVersion: v1
    kind: Service
    metadata:
      name: license-proxy-svc
    spec:
      selector:
        app: license-proxy
      ports:
      - port: 80
        targetPort: 80
    
  • 修改CoreDNS配置:通过ConfigMap将许可证域名指向上述代理服务的ClusterIP:

    apiVersion: v1
    kind: ConfigMap
    metadata:
      name: coredns
      namespace: kube-system
    data:
      Corefile: |
        .:53 {
            errors
            health
            hosts {
                10.96.1.2 license.example.com # 替换为代理服务的ClusterIP和许可证域名
                fallthrough
            }
            kubernetes cluster.local in-addr.arpa ip6.arpa {
                pods insecure
                fallthrough in-addr.arpa ip6.arpa
            }
            forward . /etc/resolv.conf
            cache 30
            loop
            reload
            loadbalance
        }
    

    更新后重启CoreDNS Pod使配置生效:kubectl rollout restart deployment coredns -n kube-system


2. Sidecar代理注入(细粒度控制场景)

为需要许可证验证的微服务Pod注入Sidecar代理容器,拦截其到许可证服务器的流量并转发至代理机。适合仅部分微服务需要配置的场景。

示例Envoy Sidecar配置片段(通过Mutating Webhook自动注入):

static_resources:
  listeners:
  - name: listener_0
    address:
      socket_address: { address: 0.0.0.0, port_value: 15001 }
    filter_chains:
    - filters:
      - name: envoy.filters.network.http_connection_manager
        typed_config:
          "@type": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager
          stat_prefix: ingress_http
          route_config:
            name: local_route
            virtual_hosts:
            - name: license_service
              domains: ["license.example.com"] # 许可证服务器域名
              routes:
              - match: { prefix: "/" }
                route: { cluster: proxy_cluster }
          http_filters:
          - name: envoy.filters.http.router
  clusters:
  - name: proxy_cluster
    connect_timeout: 0.25s
    type: STRICT_DNS
    lb_policy: ROUND_ROBIN
    load_assignment:
      cluster_name: proxy_cluster
      endpoints:
      - lb_endpoints:
        - endpoint:
            address:
              socket_address: { address: 192.168.1.100, port_value: 8080 } # 代理机IP和端口

3. 节点级iptables配置(备选方案)

类似虚拟机环境的配置,在集群所有节点上添加iptables规则,将到许可证服务器的流量DNAT至代理机。缺点是若许可证服务器IP变更,需批量更新所有节点规则,维护成本较高。

执行命令:

# 开启IP转发
sysctl net.ipv4.ip_forward=1
# 持久化IP转发配置
echo "net.ipv4.ip_forward=1" >> /etc/sysctl.conf

# 将许可证服务器的流量转发至代理机(替换实际IP和端口)
iptables -t nat -A OUTPUT -p tcp -d 203.0.113.10 --dport 443 -j DNAT --to-destination 192.168.1.100:8080
# 配置SNAT确保回包正常
iptables -t nat -A POSTROUTING -j MASQUERADE

# 保存iptables规则(以Ubuntu为例)
iptables-save > /etc/iptables/rules.v4

方案推荐

优先选择集群级DNS劫持+代理服务,配置集中且易于维护,完美适配URL硬编码的限制;若需针对特定微服务做细粒度控制,选择Sidecar代理注入;节点级iptables仅作为小规模集群的备选方案。

内容的提问来源于stack exchange,提问作者mflame

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 08:47:38