AWS EKS多租户请求路由方案咨询:如何将请求导向对应租户实例
多租户请求路由解决方案(AWS EKS环境)
针对你在AWS EKS上的多租户应用场景,这里提供几个落地可行的方案,结合你已有的Ocelot网关和K8s架构:
方案1:Ingress Nginx + 子域名/路径路由(推荐,用户体验最优)
这种方式不用暴露多个端口,统一通过443端口访问,用子域名或路径前缀区分租户:
步骤:
- 配置租户服务:每个租户的Ocelot网关部署为ClusterIP服务(不用NodePort,更安全),确保服务在各自命名空间内可访问(比如
tenant1-ocelot-gateway.tenant1.svc.cluster.local:80)。 - 部署Ingress Nginx Controller:如果集群还没部署,用AWS官方的Helm chart部署Ingress Nginx,它会自动创建AWS ALB/NLB作为入口。
- 编写Ingress规则:
- 子域名模式:为每个租户分配子域名(如
client1.example.com),路由到对应命名空间的网关服务。 - 路径前缀模式:用
example.com/client1/*这类路径,转发到对应租户服务。
- 子域名模式:为每个租户分配子域名(如
子域名模式Ingress示例:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: multi-tenant-ingress annotations: nginx.ingress.kubernetes.io/ssl-redirect: "true" alb.ingress.kubernetes.io/scheme: internet-facing # AWS ALB配置 spec: tls: - hosts: - client1.example.com - client2.example.com - client3.example.com secretName: example-wildcard-tls # 通配符证书*.example.com rules: - host: client1.example.com http: paths: - path: / pathType: Prefix backend: service: name: tenant1-ocelot-gateway port: number: 80 - host: client2.example.com http: paths: - path: / pathType: Prefix backend: service: name: tenant2-ocelot-gateway port: number: 80
- DNS解析:在Route53中把所有子域名指向Ingress对应的ALB/NLB地址。
方案2:利用现有Ocelot网关做全局路由
既然你已经在用Ocelot,可以部署一个全局Ocelot网关作为统一入口,根据租户标识转发到各个租户的网关:
步骤:
- 部署全局网关:将全局Ocelot网关暴露为公网服务(用LoadBalancer或Ingress),监听443端口。
- 配置全局Ocelot路由:根据请求头、路径或Cookie识别租户,转发到对应命名空间的租户网关。
基于请求头X-Tenant-ID的路由配置示例:
{ "Routes": [ { "DownstreamPathTemplate": "/{everything}", "DownstreamScheme": "http", "DownstreamHostAndPorts": [ { "Host": "tenant1-ocelot-gateway.tenant1.svc.cluster.local", "Port": 80 } ], "UpstreamPathTemplate": "/{everything}", "UpstreamHttpMethod": ["*"], "RouteConstraints": { "X-Tenant-ID": "client1" } }, { "DownstreamPathTemplate": "/{everything}", "DownstreamScheme": "http", "DownstreamHostAndPorts": [ { "Host": "tenant2-ocelot-gateway.tenant2.svc.cluster.local", "Port": 80 } ], "UpstreamPathTemplate": "/{everything}", "UpstreamHttpMethod": ["*"], "RouteConstraints": { "X-Tenant-ID": "client2" } } ], "GlobalConfiguration": { "BaseUrl": "https://example.com" } }
- 前端适配:Angular UI在发起请求时自动携带
X-Tenant-ID头(可从登录信息或配置中获取)。
方案3:AWS NLB + NodePort端口映射(满足你指定端口的需求)
如果必须用同一域名+不同端口的模式,用AWS NLB直接映射端口到租户的NodePort服务:
步骤:
- 配置租户NodePort服务:为每个租户的网关指定固定NodePort(如3100、3200、3300),确保EKS节点安全组开放这些端口。
- 创建NLB和Target Groups:
- 为每个端口创建Target Group,目标类型选
IP,添加所有EKS节点IP,端口设置为对应NodePort。 - 在NLB上创建监听:3100、3200、3300端口分别对应各自的Target Group。
- 为每个端口创建Target Group,目标类型选
- DNS解析:将
example.com指向NLB的DNS名称,用户访问example.com:3100即可到达对应租户实例。
关键注意事项
- TLS证书:用通配符证书覆盖所有子域名,或在NLB/ALB上为每个端口配置证书,确保HTTPS访问安全。
- 命名空间隔离:通过K8s网络策略限制跨命名空间访问,避免租户间的权限泄漏。
- 监控与日志:用CloudWatch收集Ingress/NLB/Ocelot的访问日志,结合Prometheus监控租户服务的性能指标。
内容的提问来源于stack exchange,提问作者Rohitesh
相关产品推荐
相关产品推荐

