You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何仅通过AWS API Gateway访问EKS中Ingress暴露的服务?

解决方案:仅允许AWS API Gateway访问EKS Ingress服务

方法1:用VPC链路让API Gateway内网访问(推荐)

直接让API Gateway通过VPC内部链路访问Ingress,彻底关闭Ingress的公网入口,从根源上禁止外部直接访问。

步骤:

    1. 修改Ingress配置,将其改为内部负载均衡器:
    apiVersion: networking.k8s.io/v1beta1
    kind: Ingress
    metadata:
      namespace: namespace
      name: example-service-api
      annotations:
        # 若使用AWS Load Balancer Controller,指定为内部LB
        alb.ingress.kubernetes.io/scheme: internal
        # 若使用Nginx Ingress,开启内部LB并限制仅VPC内网访问
        service.beta.kubernetes.io/aws-load-balancer-internal: "true"
        service.beta.kubernetes.io/aws-load-balancer-source-ranges: "10.0.0.0/16" # 替换成你的VPC CIDR
    spec:
      rules:
        - host: example.internal # 改用内部域名,无需公网解析
          http:
            paths:
              - path: /path/read
                backend:
                  serviceName: example-service-api-service
                  servicePort: 80
              - path: /path/create
                backend:
                  serviceName: example-service-api-service
                  servicePort: 80
    
    1. 在AWS控制台创建API Gateway的VPC链路,关联EKS所在VPC,配置允许链路访问Ingress LB端口的安全组。
    1. API Gateway的HTTP集成选择该VPC链路,填入内部Ingress的域名或LB内网IP即可。

方法2:通过自定义请求头验证限制访问

保留Ingress公网属性,但只放行带有特定自定义头的请求,这个头由API Gateway统一添加。

步骤:

    1. 修改Ingress的注解,添加Nginx的请求头校验规则:
    apiVersion: networking.k8s.io/v1beta1
    kind: Ingress
    metadata:
      namespace: namespace
      name: example-service-api
      annotations:
        nginx.ingress.kubernetes.io/server-snippet: |
          # 仅允许携带指定密钥头的请求
          if ($http_x_api_gateway_token != "your-unique-secret") {
            return 403;
          }
    spec:
      rules:
        - host: example.io
          http:
            paths:
              - path: /path/read
                backend:
                  serviceName: example-service-api-service
                  servicePort: 80
              - path: /path/create
                backend:
                  serviceName: example-service-api-service
                  servicePort: 80
    
    1. 在API Gateway的集成请求配置中,添加自定义请求头X-API-Gateway-Token,值设为上面定义的密钥。
  • 直接访问Ingress URL的请求因缺少该头会返回403,只有API Gateway转发的请求能通过。

方法3:用AWS WAF过滤请求

给Ingress对应的ALB绑定WAF,只放行API Gateway的请求。

步骤:

    1. 在AWS WAF中创建规则,设置匹配条件:比如检查请求是否带有X-Amzn-Trace-Id(API Gateway请求自带的标识头),或者验证请求来源的AWS服务前缀。
    1. 将该WAF规则关联到Ingress对应的Application Load Balancer。
    1. 配置WAF拦截所有不符合条件的请求,直接访问Ingress的流量会被拦截,仅API Gateway的请求能通过。

为什么之前的IP白名单方案失效?

区域型API Gateway的出口IP是动态变化的,属于AWS公有IP段,无法通过固定IP段做可靠白名单,所以会出现拦截API Gateway请求的情况。

内容的提问来源于stack exchange,提问作者gundocan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 09:37:28