Kubernetes中Traefik Ingress仅特定服务返回404问题
问题:ClusterIP服务通过Traefik Ingress公网访问返回404排查
集群内服务状态
集群中部署了两个ClusterIP类型的HTTP服务:
group-svc ClusterIP 10.47.151.73 <none> 80/TCP 18m app=group tea-svc ClusterIP 10.32.115.90 <none> 80/TCP 57m app=tea
集群内部直接请求两个服务均正常:
curl http://10.32.115.90/v1/app_update > Server address: 100.64.0.190:8080 curl http://10.47.151.73/v1/app_update > {"need_update":false}
Traefik Ingress配置
配置的Ingress规则如下:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: group-ingress spec: rules: - host: test.0ef12182-3a17-44c6-9c63-6a7fb1a188a2.nodes.k8s.fr-par.scw.cloud http: paths: - path: /tea pathType: Prefix backend: service: name: tea-svc port: number: 80 - path: /group pathType: Prefix backend: service: name: group-svc port: number: 80
公网访问结果
通过Ingress公网端点请求时,tea-svc正常响应,但group-svc返回404:
curl http://test.0ef12182-3a17-44c6-9c63-6a7fb1a188a2.nodes.k8s.fr-par.scw.cloud/tea/v1/app_update > Server address: 100.64.0.190:8080 curl http://test.0ef12182-3a17-44c6-9c63-6a7fb1a188a2.nodes.k8s.fr-par.scw.cloud/group/v1/app_update > 404 Not Found
两个Service的详细配置
group-svc配置
apiVersion: v1 kind: Service metadata: annotations: filter.by.port.name: "true" prometheus.io/scrape: "true" creationTimestamp: "2023-03-26T17:03:03Z" name: group-svc namespace: default resourceVersion: "27288648902" uid: 7a008c7a-de64-46ae-8897-40658c11741a spec: clusterIP: 10.47.151.73 clusterIPs: - 10.47.151.73 internalTrafficPolicy: Cluster ipFamilies: - IPv4 ipFamilyPolicy: SingleStack ports: - name: http port: 80 protocol: TCP targetPort: 8080 selector: app: group sessionAffinity: None type: ClusterIP status: loadBalancer: {}
tea-svc配置
apiVersion: v1 kind: Service metadata: creationTimestamp: "2023-03-26T16:24:28Z" name: tea-svc namespace: default resourceVersion: "27288196141" uid: 6b5c382c-cde0-4f26-89ff-fc3b6317c47d spec: clusterIP: 10.32.115.90 clusterIPs: - 10.32.115.90 internalTrafficPolicy: Cluster ipFamilies: - IPv4 ipFamilyPolicy: SingleStack ports: - name: http port: 80 protocol: TCP targetPort: 8080 selector: app: tea sessionAffinity: None type: ClusterIP status: loadBalancer: {}
排查分析与解决方案
核心原因
Traefik使用Prefix类型匹配路径时,默认会将**完整请求路径(包括前缀/group)**转发给后端服务。而group-svc的后端应用仅监听/v1/app_update路径,无法识别/group/v1/app_update,因此返回404。
反观tea-svc的后端应用,要么本身支持路径前缀,要么已经处理了路径剥离逻辑,所以能正常响应带/tea前缀的请求。
验证方法
在集群内部直接测试带前缀的请求,确认后端应用的路径处理逻辑:
curl http://10.47.151.73/group/v1/app_update
该请求同样会返回404,验证问题出在后端应用的路径匹配上。
解决方案
方案1:通过Ingress注解实现路径重写
修改Ingress配置,添加Traefik的路径重写注解,将前缀/group和/tea从请求路径中剥离:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: group-ingress annotations: traefik.ingress.kubernetes.io/rewrite-target: /$2 spec: rules: - host: test.0ef12182-3a17-44c6-9c63-6a7fb1a188a2.nodes.k8s.fr-par.scw.cloud http: paths: - path: /tea(/|$)(.*) pathType: Prefix backend: service: name: tea-svc port: number: 80 - path: /group(/|$)(.*) pathType: Prefix backend: service: name: group-svc port: number: 80
此配置会将/tea/v1/app_update重写为/v1/app_update转发给后端,/group/v1/app_update同理。
方案2:修改后端应用的路径配置
调整group-svc对应的后端应用,使其支持/group前缀的路径访问,例如在应用路由中添加/group作为根路径前缀。
内容的提问来源于stack exchange,提问作者Loïc Madiès
相关产品推荐
相关产品推荐

