You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Terraform创建带私有IP应用网关的AGIC版AKS集群

解决方案:通过预创建带私有IP的应用网关关联AGIC

由于Terraform的azurerm_kubernetes_cluster中ingress_application_gateway块不支持直接配置自动生成的应用网关私有IP,我们需要先手动用Terraform创建带有私有IP的应用网关,再让AKS的AGIC插件关联这个已存在的网关。

步骤1:创建带私有IP的Application Gateway

先定义完整的应用网关资源,确保配置私有IP前端:

resource "azurerm_resource_group" "example" {
  name     = "example-rg"
  location = "East US"
}

resource "azurerm_virtual_network" "example" {
  name                = "example-vnet"
  address_space       = ["10.0.0.0/16"]
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
}

# 应用网关专属子网(必须是/24或更大)
resource "azurerm_subnet" "appgw_subnet" {
  name                 = "appgw-subnet"
  resource_group_name  = azurerm_resource_group.example.name
  virtual_network_name = azurerm_virtual_network.example.name
  address_prefixes     = ["10.0.1.0/24"]
}

# 可选:公共IP(如果需要对外暴露流量)
resource "azurerm_public_ip" "appgw_public" {
  name                = "appgw-public-ip"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  allocation_method   = "Static"
  sku                 = "Standard"
}

# 创建静态私有IP(推荐静态,避免IP变动)
resource "azurerm_private_ip" "appgw_private" {
  name                = "appgw-private-ip"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  allocation_method   = "Static"
  subnet_id           = azurerm_subnet.appgw_subnet.id
  ip_address          = "10.0.1.10" # 选择子网内的可用IP
}

resource "azurerm_application_gateway" "example" {
  name                = "example-appgw"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location

  # AGIC仅支持Standard_v2/WAF_v2 SKU
  sku {
    name     = "Standard_v2"
    tier     = "Standard_v2"
    capacity = 2
  }

  # 网关IP配置关联子网
  gateway_ip_configuration {
    name      = "appgw-ip-config"
    subnet_id = azurerm_subnet.appgw_subnet.id
  }

  # 前端端口(HTTP示例)
  frontend_port {
    name = "http"
    port = 80
  }

  # 公共IP前端(可选)
  frontend_ip_configuration {
    name                 = "public-ip-config"
    public_ip_address_id = azurerm_public_ip.appgw_public.id
  }

  # 私有IP前端(核心配置)
  frontend_ip_configuration {
    name                 = "private-ip-config"
    private_ip_address_id = azurerm_private_ip.appgw_private.id
    private_ip_address   = azurerm_private_ip.appgw_private.ip_address
  }

  # 基础后端配置(AGIC后续会接管大部分规则,但基础结构需存在)
  backend_address_pool {
    name = "default-pool"
  }

  backend_http_settings {
    name                  = "default-settings"
    port                  = 80
    protocol              = "Http"
    cookie_based_affinity = "Disabled"
  }

  http_listener {
    name                           = "http-listener"
    frontend_ip_configuration_name = "public-ip-config"
    frontend_port_name             = "http"
    protocol                       = "Http"
  }

  request_routing_rule {
    name                       = "default-rule"
    rule_type                  = "Basic"
    http_listener_name         = "http-listener"
    backend_address_pool_name  = "default-pool"
    backend_http_settings_name = "default-settings"
  }
}

步骤2:在AKS中关联预创建的应用网关

修改AKS集群配置,通过gateway_id指定已创建的应用网关:

resource "azurerm_kubernetes_cluster" "example" {
  name                = "example-aks"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  dns_prefix          = "example-aks"

  default_node_pool {
    name       = "default"
    node_count = 3
    vm_size    = "Standard_D2s_v3"
    private_network_ip_address = "10.0.2.0/24" # 私有集群子网配置
  }

  role_based_access_control {
    enabled = true
  }

  private_cluster_enabled = true

  # 关联预创建的应用网关
  ingress_application_gateway {
    gateway_id = azurerm_application_gateway.example.id
  }

  identity {
    type = "SystemAssigned"
  }
}

步骤3:验证Ingress注解生效

部署带有appgw.ingress.kubernetes.io/use-private-ip: "true"注解的Ingress资源时,AGIC会自动将流量路由到应用网关的私有IP,此时不会再出现NoPrivateIP警告。

关键注意事项

  • 应用网关必须使用Standard_v2或WAF_v2 SKU,AGIC不支持旧版SKU。
  • 应用网关与AKS集群必须在同一个虚拟网络(或已配置对等互联的网络)中,确保节点与网关的网络连通性。
  • AGIC会接管应用网关的后端池、路由规则等配置,预创建时仅需搭建基础结构即可。

内容的提问来源于stack exchange,提问作者Jananath Banuka

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 13:33:32