You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GKE环境下Nginx Ingress认证缓存未生效问题求助

Nginx Ingress Controller认证缓存不生效问题

我在GKE上部署了测试应用,用于验证Nginx Ingress Controller的认证缓存系统,当前部署架构如图所示。

Hello应用Ingress配置

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: ingress-resource
  annotations:
    kubernetes.io/ingress.class: "nginx"
    nginx.ingress.kubernetes.io/auth-url: "https://example.com/be/auth/verify_tenant"
    nginx.ingress.kubernetes.io/auth-method: GET
    nginx.ingress.kubernetes.io/auth-snippet: |
      proxy_set_header Authorization "Bearer foo.bar";
      proxy_set_header X-Tenant-Slug tenant_name;
    nginx.ingress.kubernetes.io/auth-signin: "https://example.com/be/auth/login"
    nginx.ingress.kubernetes.io/auth-cache-key: "$request_uri"

    # 为保护后端应用避免无效请求 Flood,缓存返回401的验证结果,且设置短缓存时长防止缓存被占满
    nginx.ingress.kubernetes.io/auth-cache-duration: "200 202 5m, 401 30s"
spec:
  rules:
    - host: example.com
      http:
        paths:
          - pathType: Prefix
            path: "/hello"
            backend:
              service:
                name: hello-app
                port:
                  number: 8080

认证接口响应头

https://example.com/be/auth/verify_tenant接口的响应头如下:

< HTTP/2 200 
< date: Mon, 27 Mar 2023 09:16:56 GMT
< content-type: application/json
< content-length: 22
< vary: Accept, Origin
< allow: OPTIONS, GET
< x-frame-options: DENY
< x-content-type-options: nosniff
< referrer-policy: same-origin
< cross-origin-opener-policy: same-origin
< strict-transport-security: max-age=15724800; includeSubDomains

问题现象

检查Nginx Ingress Pod的/tmp/nginx/nginx-cache-auth目录时,未发现生成缓存文件。但将auth-url替换为https://httpbin.org/bearer时,缓存能正常生成,缓存文件内容如下:

> cat 4/cc/d642f1567f26999312ce18e77d4b4cc4
\k!d0j!dᥞsS
KEY: hXxx6T5vj3V3grZBQrZv/Ff8z+A=
HTTP/1.1 200 OK
Date: Mon, 27 Mar 2023 10:04:32 GMT
Content-Type: application/json
Content-Length: 56
Connection: close
Server: gunicorn/19.9.0
Access-Control-Allow-Origin: *
Access-Control-Allow-Credentials: true

{
  "authenticated": true, 
  "token": "kdwjdkwjdwkj"
}

排查尝试

初步判断问题出在后端Ingress或服务配置中,但后端Ingress配置无特殊之处;尝试让后端返回与httpbin完全一致的响应头,问题仍未解决。

后端Ingress配置

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: global-ingress
  annotations:
    kubernetes.io/ingress.class: "nginx"
    nginx.ingress.kubernetes.io/use-regex: "true"
spec:
  tls:
    - hosts:
        - example.com
      secretName: example-cert
  rules:
    - host: example.com
      http:
          - path: /be
            pathType: Prefix
            backend:
              service:
                name: backend
                port:
                  number: 8000

后端反向代理配置

upstream django {
    server localhost:${DJANGO_PORT};
}

server {
    root /usr/share/nginx/html;
    listen 80;

    # 最大上传大小
    client_max_body_size 100M;

    # 访问日志开关
    access_log on;

    location /protected {
        internal;
        alias /;
    }

    location ${DJANGO_ROOT_URL}static {
        rewrite ${DJANGO_ROOT_URL}(.*) /$1  break;

        root /;
    }

    location ${DJANGO_ROOT_URL} {
        rewrite ${DJANGO_ROOT_URL}(.*) /$1  break;

        proxy_pass http://django;
        proxy_redirect off;

        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header Host $http_host; # 为DRF资源添加端口并支持CSRF
        proxy_http_version 1.1;
        proxy_set_header Connection "";
    }
}

可提供更多细节用于进一步排查。

内容的提问来源于stack exchange,提问作者browser-bug

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 20:55:41