You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS EKS多租户请求路由方案咨询:如何将请求导向对应租户实例

多租户请求路由解决方案(AWS EKS环境)

针对你在AWS EKS上的多租户应用场景,这里提供几个落地可行的方案,结合你已有的Ocelot网关和K8s架构:

方案1:Ingress Nginx + 子域名/路径路由(推荐,用户体验最优)

这种方式不用暴露多个端口,统一通过443端口访问,用子域名或路径前缀区分租户:

步骤:

  1. 配置租户服务:每个租户的Ocelot网关部署为ClusterIP服务(不用NodePort,更安全),确保服务在各自命名空间内可访问(比如tenant1-ocelot-gateway.tenant1.svc.cluster.local:80)。
  2. 部署Ingress Nginx Controller:如果集群还没部署,用AWS官方的Helm chart部署Ingress Nginx,它会自动创建AWS ALB/NLB作为入口。
  3. 编写Ingress规则:
    • 子域名模式:为每个租户分配子域名(如client1.example.com),路由到对应命名空间的网关服务。
    • 路径前缀模式:用example.com/client1/*这类路径,转发到对应租户服务。

子域名模式Ingress示例:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: multi-tenant-ingress
  annotations:
    nginx.ingress.kubernetes.io/ssl-redirect: "true"
    alb.ingress.kubernetes.io/scheme: internet-facing  # AWS ALB配置
spec:
  tls:
  - hosts:
    - client1.example.com
    - client2.example.com
    - client3.example.com
    secretName: example-wildcard-tls  # 通配符证书*.example.com
  rules:
  - host: client1.example.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: tenant1-ocelot-gateway
            port:
              number: 80
  - host: client2.example.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: tenant2-ocelot-gateway
            port:
              number: 80
  1. DNS解析:在Route53中把所有子域名指向Ingress对应的ALB/NLB地址。

方案2:利用现有Ocelot网关做全局路由

既然你已经在用Ocelot,可以部署一个全局Ocelot网关作为统一入口,根据租户标识转发到各个租户的网关:

步骤:

  1. 部署全局网关:将全局Ocelot网关暴露为公网服务(用LoadBalancer或Ingress),监听443端口。
  2. 配置全局Ocelot路由:根据请求头、路径或Cookie识别租户,转发到对应命名空间的租户网关。

基于请求头X-Tenant-ID的路由配置示例:

{
  "Routes": [
    {
      "DownstreamPathTemplate": "/{everything}",
      "DownstreamScheme": "http",
      "DownstreamHostAndPorts": [
        {
          "Host": "tenant1-ocelot-gateway.tenant1.svc.cluster.local",
          "Port": 80
        }
      ],
      "UpstreamPathTemplate": "/{everything}",
      "UpstreamHttpMethod": ["*"],
      "RouteConstraints": {
        "X-Tenant-ID": "client1"
      }
    },
    {
      "DownstreamPathTemplate": "/{everything}",
      "DownstreamScheme": "http",
      "DownstreamHostAndPorts": [
        {
          "Host": "tenant2-ocelot-gateway.tenant2.svc.cluster.local",
          "Port": 80
        }
      ],
      "UpstreamPathTemplate": "/{everything}",
      "UpstreamHttpMethod": ["*"],
      "RouteConstraints": {
        "X-Tenant-ID": "client2"
      }
    }
  ],
  "GlobalConfiguration": {
    "BaseUrl": "https://example.com"
  }
}
  1. 前端适配:Angular UI在发起请求时自动携带X-Tenant-ID头(可从登录信息或配置中获取)。

方案3:AWS NLB + NodePort端口映射(满足你指定端口的需求)

如果必须用同一域名+不同端口的模式,用AWS NLB直接映射端口到租户的NodePort服务:

步骤:

  1. 配置租户NodePort服务:为每个租户的网关指定固定NodePort(如3100、3200、3300),确保EKS节点安全组开放这些端口。
  2. 创建NLB和Target Groups:
    • 为每个端口创建Target Group,目标类型选IP,添加所有EKS节点IP,端口设置为对应NodePort。
    • 在NLB上创建监听:3100、3200、3300端口分别对应各自的Target Group。
  3. DNS解析:将example.com指向NLB的DNS名称,用户访问example.com:3100即可到达对应租户实例。

关键注意事项

  • TLS证书:用通配符证书覆盖所有子域名,或在NLB/ALB上为每个端口配置证书,确保HTTPS访问安全。
  • 命名空间隔离:通过K8s网络策略限制跨命名空间访问,避免租户间的权限泄漏。
  • 监控与日志:用CloudWatch收集Ingress/NLB/Ocelot的访问日志,结合Prometheus监控租户服务的性能指标。

内容的提问来源于stack exchange,提问作者Rohitesh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 15:35:21