Kubernetes集群特定请求转发至代理机以实现在线许可证验证
Kubernetes环境下无公网集群的许可证验证流量转发方案
我们的微服务依赖付费软件,该软件需通过在线许可证验证才能运行,但集群部署在无互联网访问权限的VPC中,仅一台代理机可访问许可证服务器域名,且付费库硬编码了许可证服务器URL无法修改。以下是Kubernetes环境中的推荐实现方式:
1. 集群级DNS劫持+代理服务(推荐)
通过CoreDNS将硬编码的许可证服务器域名解析到集群内部的代理服务,再由代理服务将请求转发至外部代理机。这种方案配置集中,维护成本低,适配URL硬编码场景。
实施步骤:
部署内部代理服务:用Nginx/Envoy部署代理服务,配置其将请求转发至外部代理机。示例Nginx Deployment配置:
apiVersion: apps/v1 kind: Deployment metadata: name: license-proxy spec: replicas: 1 selector: matchLabels: app: license-proxy template: metadata: labels: app: license-proxy spec: containers: - name: nginx image: nginx:alpine volumeMounts: - name: nginx-config mountPath: /etc/nginx/conf.d ports: - containerPort: 80 volumes: - name: nginx-config configMap: name: license-proxy-config --- apiVersion: v1 kind: ConfigMap metadata: name: license-proxy-config data: default.conf: | server { listen 80; server_name license.example.com; # 替换为实际许可证服务器域名 location / { proxy_pass http://192.168.1.100:8080; # 替换为代理机IP和端口 proxy_set_header Host $host; proxy_set_header X-Forwarded-For $remote_addr; } } --- apiVersion: v1 kind: Service metadata: name: license-proxy-svc spec: selector: app: license-proxy ports: - port: 80 targetPort: 80修改CoreDNS配置:通过ConfigMap将许可证域名指向上述代理服务的ClusterIP:
apiVersion: v1 kind: ConfigMap metadata: name: coredns namespace: kube-system data: Corefile: | .:53 { errors health hosts { 10.96.1.2 license.example.com # 替换为代理服务的ClusterIP和许可证域名 fallthrough } kubernetes cluster.local in-addr.arpa ip6.arpa { pods insecure fallthrough in-addr.arpa ip6.arpa } forward . /etc/resolv.conf cache 30 loop reload loadbalance }更新后重启CoreDNS Pod使配置生效:
kubectl rollout restart deployment coredns -n kube-system
2. Sidecar代理注入(细粒度控制场景)
为需要许可证验证的微服务Pod注入Sidecar代理容器,拦截其到许可证服务器的流量并转发至代理机。适合仅部分微服务需要配置的场景。
示例Envoy Sidecar配置片段(通过Mutating Webhook自动注入):
static_resources: listeners: - name: listener_0 address: socket_address: { address: 0.0.0.0, port_value: 15001 } filter_chains: - filters: - name: envoy.filters.network.http_connection_manager typed_config: "@type": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager stat_prefix: ingress_http route_config: name: local_route virtual_hosts: - name: license_service domains: ["license.example.com"] # 许可证服务器域名 routes: - match: { prefix: "/" } route: { cluster: proxy_cluster } http_filters: - name: envoy.filters.http.router clusters: - name: proxy_cluster connect_timeout: 0.25s type: STRICT_DNS lb_policy: ROUND_ROBIN load_assignment: cluster_name: proxy_cluster endpoints: - lb_endpoints: - endpoint: address: socket_address: { address: 192.168.1.100, port_value: 8080 } # 代理机IP和端口
3. 节点级iptables配置(备选方案)
类似虚拟机环境的配置,在集群所有节点上添加iptables规则,将到许可证服务器的流量DNAT至代理机。缺点是若许可证服务器IP变更,需批量更新所有节点规则,维护成本较高。
执行命令:
# 开启IP转发 sysctl net.ipv4.ip_forward=1 # 持久化IP转发配置 echo "net.ipv4.ip_forward=1" >> /etc/sysctl.conf # 将许可证服务器的流量转发至代理机(替换实际IP和端口) iptables -t nat -A OUTPUT -p tcp -d 203.0.113.10 --dport 443 -j DNAT --to-destination 192.168.1.100:8080 # 配置SNAT确保回包正常 iptables -t nat -A POSTROUTING -j MASQUERADE # 保存iptables规则(以Ubuntu为例) iptables-save > /etc/iptables/rules.v4
方案推荐
优先选择集群级DNS劫持+代理服务,配置集中且易于维护,完美适配URL硬编码的限制;若需针对特定微服务做细粒度控制,选择Sidecar代理注入;节点级iptables仅作为小规模集群的备选方案。
内容的提问来源于stack exchange,提问作者mflame
相关产品推荐
相关产品推荐

