GKE中FastAPI服务遭高频GET请求,请求源排查求助
排查GKE Ingress下/api路径高频35.191开头IP请求的方法
1. 确认IP归属
35.191开头的IP属于Google Cloud官方IP段,这类请求基本来自Google Cloud内部服务组件,而非外部恶意访问。
2. 检查后端服务健康检查配置
高频请求首先要排查默认或自定义的健康检查:
- 列出关联后端服务的健康检查:
gcloud compute health-checks list --filter="name~destination-service" - 检查健康检查的频率参数(
check-interval、timeout等),默认HTTP健康检查为每5秒一次,若后端有多副本或多个健康检查实例,可能出现请求叠加的情况。 - 注意:GKE Ingress会自动为后端创建健康检查,若未指定健康检查路径,可能默认路由到
/api(因Ingress规则将该路径指向后端),导致健康检查请求被计入业务日志。
3. 验证Ingress关联负载均衡器的配置
查看Ingress关联的负载均衡器及后端服务详情:
- 获取Ingress的负载均衡器信息:
kubectl describe ingress <你的Ingress名称> - 查看对应后端服务的健康检查配置:
gcloud compute backend-services describe <后端服务名称> --region=<你的集群区域> - 确认后端服务关联的健康检查路径是否为
/api,以及是否存在多个健康检查实例。
4. 打印请求完整头部信息
修改FastAPI日志配置,记录请求头部以获取更多线索:
- 添加日志中间件,捕获
User-Agent、X-Google-*等标识:from fastapi import FastAPI, Request import logging app = FastAPI() logger = logging.getLogger(__name__) @app.middleware("http") async def log_request_headers(request: Request, call_next): logger.info(f"Request Headers: {dict(request.headers)}") response = await call_next(request) return response - Google Cloud服务的请求通常带有
X-Google-*头,或User-Agent包含GoogleHC(健康检查)、GoogleCloudLoadBalancing等关键词。
5. 调整Ingress路径规则与健康检查路径
优化Ingress规则,避免健康检查请求误路由:
- 将
/api路径改为/api/*,明确前缀匹配范围:paths: - path: /api/* pathType: ImplementationSpecific backend: service: name: destination-service port: number: 8080 - 为后端服务配置独立的健康检查路径(如
/healthz),通过BackendConfig关联:
然后给后端Service添加注解关联BackendConfig:apiVersion: cloud.google.com/v1 kind: BackendConfig metadata: name: destination-service-backendconfig spec: healthCheck: checkIntervalSec: 30 timeoutSec: 5 type: HTTP requestPath: /healthzapiVersion: v1 kind: Service metadata: name: destination-service annotations: cloud.google.com/backend-config: '{"default": "destination-service-backendconfig"}' spec: # 你的Service配置
6. 通过Cloud Monitoring分析请求指标
在Cloud Console的Monitoring页面,用Metrics Explorer查看请求详情:
- 选择指标
loadbalancing.googleapis.com/backend_request_count,过滤对应后端服务和35.191 IP段,查看请求的时间分布、来源标识等数据。
内容的提问来源于stack exchange,提问作者Simon Nicholls
相关产品推荐
相关产品推荐

