You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将本地Kubernetes集群连接至Google Cloud VPN

在本地Kubernetes中部署VPN网关连接GCP Classic VPN

核心思路

本地K8s集群需部署IPsec VPN网关Pod,模拟硬件VPN网关功能,与GCP Classic VPN建立单隧道连接;同时配置集群路由,让本地Pod流量转发至该VPN网关,实现和GKE集群的互通。

可用工具/镜像

1. StrongSwan Docker镜像

StrongSwan是成熟的IPsec协议实现,官方提供Docker镜像,可直接在K8s中部署。

2. Helm Chart选项

社区维护的strongswan Helm Chart可快速完成部署,也可手动编写Deployment和Service配置。

具体操作步骤

1. 准备GCP VPN配置参数

提前从GCP控制台获取以下信息:

  • GCP Classic VPN网关的公网IP
  • 预共享密钥(PSK)
  • 双方网段:GKE集群的Pod/Service CIDR、本地K8s集群的Pod/Service CIDR

2. 部署StrongSwan到本地K8s

方式一:手动编写资源配置

创建ConfigMap存储StrongSwan配置:

apiVersion: v1
kind: ConfigMap
metadata:
  name: strongswan-config
data:
  ipsec.conf: |
    config setup
      charondebug="ike 2, knl 2, cfg 2"
      uniqueids=no

    conn gcp-vpn
      auto=start
      keyexchange=ikev1
      authby=secret
      left=%defaultroute
      leftid=<本地VPN网关公网IP/WSL2宿主机公网IP>
      leftsubnets=<本地K8s Pod CIDR>,<本地K8s Service CIDR>
      right=<GCP VPN网关公网IP>
      rightsubnets=<GKE Pod CIDR>,<GKE Service CIDR>
      ike=aes256-sha1-modp1024!
      esp=aes256-sha1!
      dpddelay=30
      dpdtimeout=120
      dpdaction=restart
  ipsec.secrets: |
    <本地VPN网关公网IP> <GCP VPN网关公网IP> : PSK "<预共享密钥>"

创建Deployment部署StrongSwan:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: strongswan-vpn
spec:
  replicas: 1
  selector:
    matchLabels:
      app: strongswan-vpn
  template:
    metadata:
      labels:
        app: strongswan-vpn
    spec:
      hostNetwork: true  # 启用宿主机网络,便于处理IPsec流量
      containers:
      - name: strongswan
        image: strongswan/strongswan:latest
        securityContext:
          privileged: true  # 需特权模式操作网络栈
        volumeMounts:
        - name: config
          mountPath: /etc/ipsec.conf
          subPath: ipsec.conf
        - name: config
          mountPath: /etc/ipsec.secrets
          subPath: ipsec.secrets
        - name: ipsec-db
          mountPath: /etc/ipsec.d
      volumes:
      - name: config
        configMap:
          name: strongswan-config
      - name: ipsec-db
        emptyDir: {}

方式二:使用Helm Chart

执行以下命令添加仓库并安装:

helm repo add strongswan https://charts.strongswan.org
helm repo update

自定义values.yaml,重点配置ipsec.conn段的GCP VPN参数,同时开启hostNetwork: true和privileged: true,然后安装:

helm install gcp-vpn strongswan/strongswan -f values.yaml

3. 配置本地K8s集群路由

让本地Pod发往GKE网段的流量转发至VPN网关Pod,可通过DaemonSet在所有节点添加静态路由:

apiVersion: apps/v1
kind: DaemonSet
metadata:
  name: vpn-router
spec:
  selector:
    matchLabels:
      app: vpn-router
  template:
    metadata:
      labels:
        app: vpn-router
    spec:
      hostNetwork: true
      containers:
      - name: router
        image: alpine:latest
        command: ["/bin/sh", "-c"]
        args:
        - >
          while true; do
            ip route add <GKE Pod CIDR> via <VPN网关Pod所在宿主机IP>;
            ip route add <GKE Service CIDR> via <VPN网关Pod所在宿主机IP>;
            sleep 3600;
          done
        securityContext:
          privileged: true

4. 验证连接状态

进入StrongSwan Pod查看IPsec隧道状态:

kubectl exec -it <strongswan-pod-name> -- ipsec status

若显示ESTABLISHED状态,说明隧道已建立。随后在本地Pod中ping GKE Pod IP,测试连通性。

WSL2环境额外注意事项

  • 确保Windows防火墙允许UDP 500、4500端口的入站流量(IPsec协议所需)
  • 若WSL2无公网IP,需在Windows上配置端口转发,将UDP 500、4500转发至WSL2的内网IP
  • 建议将WSL2网络模式设置为bridge,避免NAT带来的端口穿透问题

内容的提问来源于stack exchange,提问作者Robert Crowder

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 16:55:40