GKE Gateway负载均衡生成错误健康检查路径问题求助
GKE Gateway API健康检查路径不匹配问题排查
问题场景
按教程及官方文档配置GKE Gateway API后,Gateway资源运行正常,已在GCP创建负载均衡器并分配静态IP;HTTPRoute资源也能被Gateway正常识别。但负载均衡器的健康检查显示服务状态为UNHEALTHY,实际Pod本身是健康的。
在GCP控制台中发现健康检查路径使用的是/,而非Deployment中配置的/health,手动修改路径后状态会自动恢复,但未找到在HTTPRoute中配置该路径的方法,同时疑惑为何健康检查路径不自动读取Pod的livenessProbe/readinessProbe配置。
相关配置
Gateway及命名空间配置
apiVersion: v1 kind: Namespace metadata: name: infra-ns labels: shared-gateway-access: "true" --- kind: Gateway apiVersion: gateway.networking.k8s.io/v1beta1 metadata: name: external-http namespace: infra-ns spec: gatewayClassName: gke-l7-gxlb listeners: - name: http protocol: HTTP port: 80 allowedRoutes: namespaces: from: Selector selector: matchLabels: shared-gateway-access: "true"
HTTPRoute、Service及命名空间配置
apiVersion: v1 kind: Namespace metadata: name: other-namespace labels: shared-gateway-access: "true" --- apiVersion: v1 kind: Service metadata: annotations: cloud.google.com/neg: '{"ingress": true}' name: myservice namespace: other-namespace spec: ports: - name: myservice port: 80 protocol: TCP targetPort: 8080 selector: app: myservice type: NodePort --- kind: HTTPRoute apiVersion: gateway.networking.k8s.io/v1beta1 metadata: name: myhttproute namespace: other-namespace spec: parentRefs: - kind: Gateway name: external-http namespace: infra-ns hostnames: - "demo.example.com" rules: - backendRefs: - name: myservice port: 80
Deployment探针配置
$ kubectl -n other-namespace describe deployment myservice ... Containers: myservice: Image: myserviceimage:latest Port: 8080/TCP Host Port: 0/TCP Requests: cpu: 1m memory: 1Mi Liveness: http-get http://:8080/health delay=10s timeout=5s period=10s #success=1 #failure=3 Readiness: http-get http://:8080/health delay=2s timeout=3s period=2s #success=1 #failure=2 ...
原因分析
GKE Gateway Controller(gke-l7-gxlb网关类)默认不会自动从Pod的探针配置中继承健康检查路径,核心原因:
- Gateway API的HTTPRoute资源本身没有直接配置健康检查的字段,健康检查由GKE根据Service和NEG的配置自动生成
- 默认情况下,GKE为NEG创建的健康检查会使用路径
/,除非通过Service注解显式指定
解决方案
在Service中添加cloud.google.com/health-check-path注解,指定健康检查路径:
apiVersion: v1 kind: Service metadata: annotations: cloud.google.com/neg: '{"ingress": true}' cloud.google.com/health-check-path: "/health" name: myservice namespace: other-namespace spec: ports: - name: myservice port: 80 protocol: TCP targetPort: 8080 selector: app: myservice type: NodePort
补充说明
- 除路径外,还可通过其他注解配置健康检查参数,比如
cloud.google.com/health-check-port指定端口、cloud.google.com/health-check-interval指定检查间隔等 - 手动修改GCP控制台的健康检查配置会被GKE控制器覆盖,因为控制器会同步K8s资源配置状态,必须通过K8s注解实现持久化配置
内容的提问来源于stack exchange,提问作者e_v_e
相关产品推荐
相关产品推荐

