You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

裸金属K8s集群同域名多路径Nginx-ingress配置遇主机占用报错

解决同一Hostname下多Namespace服务路径的Nginx Ingress配置问题

问题原因

你的第二个Ingress被拒绝,核心原因是Nginx Ingress Controller未监听app2命名空间,或者存在其他Ingress资源占用了web.example.com这个Host。

解决步骤

1. 检查Ingress Controller的命名空间监听范围

默认情况下,Nginx Ingress Controller会监听所有命名空间,但如果部署时手动指定了--watch-namespace参数,它只会监听指定的命名空间,导致其他命名空间的Ingress被拒绝。

执行以下命令检查Controller的启动参数:

kubectl get deployment nginx-ingress-controller -n ingress-nginx -o yaml | grep -A5 -B5 "watch-namespace"

如果输出中存在--watch-namespace=app1这类参数,说明Controller仅监听app1命名空间,需要修改Deployment移除该限制:

kubectl edit deployment nginx-ingress-controller -n ingress-nginx

找到command字段,删除包含--watch-namespace的行,保存退出后,Controller会自动重启,之后就能监听所有命名空间的Ingress资源。

2. 排查Host冲突的Ingress资源

执行以下命令检查所有命名空间中使用web.example.com的Ingress:

kubectl get ingress --all-namespaces | grep web.example.com

如果存在其他Ingress(比如路径为/的默认Ingress),会导致路径匹配冲突,需调整这些Ingress的路径规则,确保/app1和/app2的路径优先级正常。

3. 验证配置

修改完成后,查看app2的Ingress状态:

kubectl describe ingress app2-ingress -n app2

如果Events中不再出现Rejected警告,即可通过http://web.example.com/app2访问app2服务。

备选方案:合并Ingress到同一命名空间

如果希望统一管理Ingress规则,可以将两个路径配置到同一个Ingress资源中(需确保Ingress与引用的Service处于同一命名空间):

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: web-apps-ingress
  namespace: apps # 需将app1-service和app2-service迁移至此命名空间
spec:
  ingressClassName: nginx
  rules:
  - host: web.example.com
    http:
      paths:
      - path: /app1
        pathType: Prefix
        backend:
          service:
            name: app1-service
            port:
              number: 80
      - path: /app2
        pathType: Prefix
        backend:
          service:
            name: app2-service
            port:
              number: 80

内容的提问来源于stack exchange,提问作者user4948798

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 08:22:20