You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP共享VPC与VPC对等连接跨区域内部LB访问异常

GCP跨VPC内部负载均衡访问异常问题

架构背景

  • 网络项目下设有dev、pro两个VPC,每个VPC包含两个子网:europe-west1区域的Subnet A、us-central1区域的Subnet B
  • 两个VPC已共享给其他项目,每个子网对应部署一个GKE集群
  • 项目B拥有独立VPC(含europe-west1区域子网),部署了Grafana、Vault等工具及GKE集群,通过VPC对等连接与dev VPC建立连通

问题现象

项目B的GKE集群可正常访问dev VPC中Subnet A内的内部负载均衡(Internal Load Balancer)服务,但无法访问dev VPC中Subnet B内的同类服务。

已排查情况

  • 已配置允许全量流量及对应端口的防火墙规则,问题未解决
  • 可从项目B的GKE集群ping通Subnet B内的Pod或节点,但无法访问该子网的Internal LoadBalancer服务(相同配置的服务在Subnet A中可正常访问)

正常服务配置示例

apiVersion: v1
kind: Service
metadata:
  annotations:
    networking.gke.io/load-balancer-type: Internal
  name: prometheus
  namespace: monitoring
spec:
  ports:
  - name: http
    port: 9090
    protocol: TCP
    targetPort: 9090
  selector:
    app: prometheus
    prometheus: prometheus-kube-prometheus-prometheus
  sessionAffinity: None
  type: LoadBalancer

网络测试截图

网络测试截图

内容的提问来源于stack exchange,提问作者EMG

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 09:15:48