You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCE负载均衡器未同步readinessProbe路径,求配置排查

问题分析与解决

你的核心问题是GCE负载均衡器未同步Deployment中配置的/health健康检查路径,即便重建Ingress也无效。结合你提供的配置,以下是遗漏的关键配置和问题点:

1. Service配置存在语法错误

你的Service重复定义了type字段:

spec:
  type: LoadBalancer
  ...
  type: ClusterIP

语法不规范会引发GKE控制器解析异常,影响健康检查关联。需删除重复的type: LoadBalancer,仅保留type: ClusterIP(GKE Ingress仅支持关联ClusterIP类型Service)。

2. GKE Ingress未显式指定健康检查路径

GCE负载均衡器的健康检查不会自动继承Deployment的readinessProbe配置,需通过注解显式声明,两种可选方案:

方案一:通过BackendConfig配置(精细控制)

先创建BackendConfig资源:

apiVersion: cloud.google.com/v1
kind: BackendConfig
metadata:
  name: healthcheck-config
spec:
  healthCheck:
    checkIntervalSec: 30
    timeoutSec: 5
    healthyThreshold: 2
    unhealthyThreshold: 2
    type: HTTP
    requestPath: /health
    port: 80

再在Ingress的metadata.annotations中关联该配置:

cloud.google.com/backend-config: '{"default": "healthcheck-config"}'

方案二:通过Service注解直接配置(更简洁)

在Service的metadata.annotations中添加:

cloud.google.com/app-protocols: '{"http":"HTTP"}'
cloud.google.com/health-check-path: "/health"

3. ManagedCertificate名称不匹配

Ingress注解中引用的证书名custom-app-uat-managed-cert与实际创建的证书名custom-app-managed-cert不一致,会导致证书无法关联(虽不直接影响健康检查,但需修正):

# Ingress中的注解需改为:
networking.gke.io/managed-certificates: custom-app-managed-cert

4. 强制刷新健康检查的操作步骤

若上述配置修正后仍未生效,需手动清理旧资源:

  • 删除旧Ingress:kubectl delete ingress app-ingress
  • 等待GCE负载均衡器在GCP控制台中完全销毁
  • 若使用了BackendConfig,删除旧配置:kubectl delete backendconfig healthcheck-config
  • 重新应用所有配置文件

最后需确认Pod能正常响应/health路径的HTTP请求(返回200状态码),否则健康检查仍会失败。

内容的提问来源于stack exchange,提问作者WenHao

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 04:50:25