GKE中GCP负载均衡源IP注解配置与Jenkins代理服务咨询
1. Does service.beta.kubernetes.io/load-balancer-source-ranges work for GCP Load Balancers?
Absolutely! This annotation is not exclusive to AWS—it’s fully supported on GKE and works exactly as intended to harden your GCP Load Balancer.
When you apply this annotation to a LoadBalancer type Service in GKE:
- GCP automatically creates (or updates) a VPC firewall rule that restricts incoming traffic to the Load Balancer’s frontend IPs to only the CIDR ranges you specify (in your case,
172.0.0.0/8and10.0.0.0/8). - This blocks unauthorized public access to your Jenkins agent service, ensuring only traffic from those private IP ranges can reach it.
Just double-check that the CIDRs you list cover all remote agents that need to connect—if you miss any, those agents won’t be able to reach the service.
2. Will GKE-internal agents access the Load Balancer via the internet?
No, traffic from GKE-internal pods or nodes to your Jenkins agent Load Balancer won’t traverse the public internet. Here’s the breakdown:
- GCP uses hairpin NAT for external Load Balancers, which routes traffic from internal resources to the Load Balancer’s public IP back into the VPC network instead of sending it out to the internet.
- For even better efficiency and security with internal agents, you can skip the Load Balancer entirely and use the Service’s ClusterIP or DNS name (e.g.,
jenkins-agent.your-namespace.svc.cluster.local). This keeps traffic strictly within the cluster network, with lower latency and no reliance on external IPs.
If you need external remote agents to connect, keeping the Load Balancer is the right call—but internal agents will still benefit from optimized internal routing either way.
内容的提问来源于stack exchange,提问作者pkaramol

