借助GKE Gateway与HTTPRoute实现HTTP转HTTPS重定向遇阻
解决GKE Gateway HTTP到HTTPS重定向的方案
由于GKE当前的Gateway实现暂不支持RequestRedirect过滤器,以下提供两种非hacky的合规解决方案:
方案一:GKE Gateway原生重定向配置(推荐)
GKE的Gateway资源支持直接在监听规则中配置HTTP到HTTPS的自动重定向,无需依赖HTTPRoute过滤器,这是官方支持的原生方式。示例配置如下:
apiVersion: gateway.networking.k8s.io/v1beta1 kind: Gateway metadata: name: my-gateway spec: gatewayClassName: gke-l7-gateway-v2 listeners: # 配置HTTP监听并开启重定向 - name: http port: 80 protocol: HTTP hostname: "redirect.example" allowedRoutes: namespaces: from: Same redirect: enabled: true port: 443 protocol: HTTPS statusCode: 301 # 配置HTTPS监听处理实际业务流量 - name: https port: 443 protocol: HTTPS hostname: "redirect.example" allowedRoutes: namespaces: from: Same tls: mode: Terminate certificateRefs: - name: my-ssl-cert
方案二:独立重定向服务(备选)
如果需要更灵活的重定向逻辑,可以部署轻量HTTP服务(如nginx)专门处理重定向,再通过HTTPRoute将80端口流量转发至该服务:
- 部署重定向服务相关资源:
apiVersion: apps/v1 kind: Deployment metadata: name: redirect-service spec: replicas: 2 selector: matchLabels: app: redirect template: metadata: labels: app: redirect spec: containers: - name: nginx image: nginx:alpine ports: - containerPort: 80 volumeMounts: - name: config mountPath: /etc/nginx/conf.d volumes: - name: config configMap: name: redirect-config --- apiVersion: v1 kind: Service metadata: name: redirect-service spec: selector: app: redirect ports: - port: 80 targetPort: 80 --- apiVersion: v1 kind: ConfigMap metadata: name: redirect-config data: default.conf: | server { listen 80; server_name redirect.example; return 301 https://$host$request_uri; }
- 创建HTTPRoute转发80端口流量:
apiVersion: gateway.networking.k8s.io/v1beta1 kind: HTTPRoute metadata: name: http-redirect-route spec: hostnames: - redirect.example rules: - matches: - path: type: PathPrefix value: / backendRefs: - name: redirect-service port: 80
同时保留HTTPS对应的HTTPRoute配置处理正常业务流量即可。
内容的提问来源于stack exchange,提问作者Vincent L.
相关产品推荐
相关产品推荐

