如何用Terraform创建带私有IP应用网关的AGIC版AKS集群
解决方案:通过预创建带私有IP的应用网关关联AGIC
由于Terraform的azurerm_kubernetes_cluster中ingress_application_gateway块不支持直接配置自动生成的应用网关私有IP,我们需要先手动用Terraform创建带有私有IP的应用网关,再让AKS的AGIC插件关联这个已存在的网关。
步骤1:创建带私有IP的Application Gateway
先定义完整的应用网关资源,确保配置私有IP前端:
resource "azurerm_resource_group" "example" { name = "example-rg" location = "East US" } resource "azurerm_virtual_network" "example" { name = "example-vnet" address_space = ["10.0.0.0/16"] location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name } # 应用网关专属子网(必须是/24或更大) resource "azurerm_subnet" "appgw_subnet" { name = "appgw-subnet" resource_group_name = azurerm_resource_group.example.name virtual_network_name = azurerm_virtual_network.example.name address_prefixes = ["10.0.1.0/24"] } # 可选:公共IP(如果需要对外暴露流量) resource "azurerm_public_ip" "appgw_public" { name = "appgw-public-ip" location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name allocation_method = "Static" sku = "Standard" } # 创建静态私有IP(推荐静态,避免IP变动) resource "azurerm_private_ip" "appgw_private" { name = "appgw-private-ip" location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name allocation_method = "Static" subnet_id = azurerm_subnet.appgw_subnet.id ip_address = "10.0.1.10" # 选择子网内的可用IP } resource "azurerm_application_gateway" "example" { name = "example-appgw" resource_group_name = azurerm_resource_group.example.name location = azurerm_resource_group.example.location # AGIC仅支持Standard_v2/WAF_v2 SKU sku { name = "Standard_v2" tier = "Standard_v2" capacity = 2 } # 网关IP配置关联子网 gateway_ip_configuration { name = "appgw-ip-config" subnet_id = azurerm_subnet.appgw_subnet.id } # 前端端口(HTTP示例) frontend_port { name = "http" port = 80 } # 公共IP前端(可选) frontend_ip_configuration { name = "public-ip-config" public_ip_address_id = azurerm_public_ip.appgw_public.id } # 私有IP前端(核心配置) frontend_ip_configuration { name = "private-ip-config" private_ip_address_id = azurerm_private_ip.appgw_private.id private_ip_address = azurerm_private_ip.appgw_private.ip_address } # 基础后端配置(AGIC后续会接管大部分规则,但基础结构需存在) backend_address_pool { name = "default-pool" } backend_http_settings { name = "default-settings" port = 80 protocol = "Http" cookie_based_affinity = "Disabled" } http_listener { name = "http-listener" frontend_ip_configuration_name = "public-ip-config" frontend_port_name = "http" protocol = "Http" } request_routing_rule { name = "default-rule" rule_type = "Basic" http_listener_name = "http-listener" backend_address_pool_name = "default-pool" backend_http_settings_name = "default-settings" } }
步骤2:在AKS中关联预创建的应用网关
修改AKS集群配置,通过gateway_id指定已创建的应用网关:
resource "azurerm_kubernetes_cluster" "example" { name = "example-aks" location = azurerm_resource_group.example.location resource_group_name = azurerm_resource_group.example.name dns_prefix = "example-aks" default_node_pool { name = "default" node_count = 3 vm_size = "Standard_D2s_v3" private_network_ip_address = "10.0.2.0/24" # 私有集群子网配置 } role_based_access_control { enabled = true } private_cluster_enabled = true # 关联预创建的应用网关 ingress_application_gateway { gateway_id = azurerm_application_gateway.example.id } identity { type = "SystemAssigned" } }
步骤3:验证Ingress注解生效
部署带有appgw.ingress.kubernetes.io/use-private-ip: "true"注解的Ingress资源时,AGIC会自动将流量路由到应用网关的私有IP,此时不会再出现NoPrivateIP警告。
关键注意事项
- 应用网关必须使用
Standard_v2或WAF_v2SKU,AGIC不支持旧版SKU。 - 应用网关与AKS集群必须在同一个虚拟网络(或已配置对等互联的网络)中,确保节点与网关的网络连通性。
- AGIC会接管应用网关的后端池、路由规则等配置,预创建时仅需搭建基础结构即可。
内容的提问来源于stack exchange,提问作者Jananath Banuka
相关产品推荐
相关产品推荐

