You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes中Traefik Ingress仅特定服务返回404问题

问题:ClusterIP服务通过Traefik Ingress公网访问返回404排查

集群内服务状态

集群中部署了两个ClusterIP类型的HTTP服务:

group-svc    ClusterIP   10.47.151.73    <none>        80/TCP    18m   app=group
tea-svc      ClusterIP   10.32.115.90    <none>        80/TCP    57m   app=tea

集群内部直接请求两个服务均正常:

curl http://10.32.115.90/v1/app_update
> Server address: 100.64.0.190:8080
curl http://10.47.151.73/v1/app_update
> {"need_update":false}

Traefik Ingress配置

配置的Ingress规则如下:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: group-ingress
spec:
  rules:
    - host: test.0ef12182-3a17-44c6-9c63-6a7fb1a188a2.nodes.k8s.fr-par.scw.cloud
      http:
        paths:
          - path: /tea
            pathType: Prefix
            backend:
              service:
                name: tea-svc
                port:
                  number: 80
          - path: /group
            pathType: Prefix
            backend:
              service:
                name: group-svc
                port:
                  number: 80

公网访问结果

通过Ingress公网端点请求时,tea-svc正常响应,但group-svc返回404:

curl http://test.0ef12182-3a17-44c6-9c63-6a7fb1a188a2.nodes.k8s.fr-par.scw.cloud/tea/v1/app_update
> Server address: 100.64.0.190:8080
curl http://test.0ef12182-3a17-44c6-9c63-6a7fb1a188a2.nodes.k8s.fr-par.scw.cloud/group/v1/app_update
> 404 Not Found

两个Service的详细配置

group-svc配置

apiVersion: v1
kind: Service
metadata:
  annotations:
    filter.by.port.name: "true"
    prometheus.io/scrape: "true"
  creationTimestamp: "2023-03-26T17:03:03Z"
  name: group-svc
  namespace: default
  resourceVersion: "27288648902"
  uid: 7a008c7a-de64-46ae-8897-40658c11741a
spec:
  clusterIP: 10.47.151.73
  clusterIPs:
  - 10.47.151.73
  internalTrafficPolicy: Cluster
  ipFamilies:
  - IPv4
  ipFamilyPolicy: SingleStack
  ports:
  - name: http
    port: 80
    protocol: TCP
    targetPort: 8080
  selector:
    app: group
  sessionAffinity: None
  type: ClusterIP
status:
  loadBalancer: {}

tea-svc配置

apiVersion: v1
kind: Service
metadata:
  creationTimestamp: "2023-03-26T16:24:28Z"
  name: tea-svc
  namespace: default
  resourceVersion: "27288196141"
  uid: 6b5c382c-cde0-4f26-89ff-fc3b6317c47d
spec:
  clusterIP: 10.32.115.90
  clusterIPs:
  - 10.32.115.90
  internalTrafficPolicy: Cluster
  ipFamilies:
  - IPv4
  ipFamilyPolicy: SingleStack
  ports:
  - name: http
    port: 80
    protocol: TCP
    targetPort: 8080
  selector:
    app: tea
  sessionAffinity: None
  type: ClusterIP
status:
  loadBalancer: {}

排查分析与解决方案

核心原因

Traefik使用Prefix类型匹配路径时,默认会将**完整请求路径(包括前缀/group)**转发给后端服务。而group-svc的后端应用仅监听/v1/app_update路径,无法识别/group/v1/app_update,因此返回404。

反观tea-svc的后端应用,要么本身支持路径前缀,要么已经处理了路径剥离逻辑,所以能正常响应带/tea前缀的请求。

验证方法

在集群内部直接测试带前缀的请求,确认后端应用的路径处理逻辑:

curl http://10.47.151.73/group/v1/app_update

该请求同样会返回404,验证问题出在后端应用的路径匹配上。

解决方案

方案1:通过Ingress注解实现路径重写

修改Ingress配置,添加Traefik的路径重写注解,将前缀/group和/tea从请求路径中剥离:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: group-ingress
  annotations:
    traefik.ingress.kubernetes.io/rewrite-target: /$2
spec:
  rules:
    - host: test.0ef12182-3a17-44c6-9c63-6a7fb1a188a2.nodes.k8s.fr-par.scw.cloud
      http:
        paths:
          - path: /tea(/|$)(.*)
            pathType: Prefix
            backend:
              service:
                name: tea-svc
                port:
                  number: 80
          - path: /group(/|$)(.*)
            pathType: Prefix
            backend:
              service:
                name: group-svc
                port:
                  number: 80

此配置会将/tea/v1/app_update重写为/v1/app_update转发给后端,/group/v1/app_update同理。

方案2:修改后端应用的路径配置

调整group-svc对应的后端应用,使其支持/group前缀的路径访问,例如在应用路由中添加/group作为根路径前缀。


内容的提问来源于stack exchange,提问作者Loïc Madiès

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 19:24:57