为何已配置AppGateway作为Ingress Controller,AKS仍创建Azure Load Balancer?
AKS配置应用网关后仍创建Azure负载均衡器的原因解析
你的理解完全正确
- LoadBalancer类型Service:由Kubernetes Azure云提供商控制器处理,会自动创建Azure负载均衡器,属于L4层流量暴露,直接将Pod端口映射到负载均衡器的公网/内网IP。
- Ingress + 应用网关:属于L7层路由转发,通过应用网关Ingress控制器(AGIC)将Ingress资源规则同步到应用网关,后端服务只需使用ClusterIP类型即可,无需额外负载均衡器。
为什么部署LoadBalancer Service仍会创建Azure负载均衡器
你在Terraform中配置的ingress_application_gateway仅用于关联AKS与指定应用网关、部署AGIC控制器,让Ingress资源可以通过应用网关转发流量,但该配置不会修改LoadBalancer类型Service的默认行为。
LoadBalancer类型Service的创建逻辑由Kubernetes的Azure云提供商独立处理,和Ingress控制器是完全分离的两个功能模块,因此只要部署LoadBalancer类型的Service,AKS就会自动调用Azure API创建对应的负载均衡器。
基于应用网关的服务暴露正确方式
如果想通过应用网关暴露服务,应该:
- 将Service类型改为
ClusterIP(默认类型,可省略显式声明):
apiVersion: v1 kind: Service metadata: name: aks-helloworld spec: ports: - port: 80 selector: app: aks-helloworld-two
- 创建对应的Ingress资源,AGIC会自动将路由规则同步到你的应用网关:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: aks-helloworld-ingress annotations: kubernetes.io/ingress.class: azure/application-gateway spec: rules: - http: paths: - path: /helloworld pathType: Prefix backend: service: name: aks-helloworld port: number: 80
附你的原始配置
Terraform AKS集群配置
# Create the Azure Kubernetes Service (AKS) Cluster resource "azurerm_kubernetes_cluster" "kubernetes_cluster" { count = var.enable_kubernetes == true ? 1 : 0 name = "aks-prjx-${var.subscription_type}-${var.environment}-${var.location}-${var.instance_number}" location = var.location resource_group_name = module.resource_group_kubernetes_cluster[0].name # "rg-aks-spoke-dev-westus3-001" dns_prefix = "dns-aks-prjx-${var.subscription_type}-${var.environment}-${var.location}-${var.instance_number}" #"dns-prjxcluster" private_cluster_enabled = false local_account_disabled = true default_node_pool { name = "npprjx${var.subscription_type}" #"prjxsyspool" # NOTE: "name must start with a lowercase letter, have max length of 12, and only have characters a-z0-9." vm_size = "Standard_B8ms" vnet_subnet_id = data.azurerm_subnet.aks-subnet.id # zones = ["1", "2", "3"] enable_auto_scaling = true max_count = 3 min_count = 1 # node_count = 3 os_disk_size_gb = 50 type = "VirtualMachineScaleSets" enable_node_public_ip = false enable_host_encryption = false node_labels = { "node_pool_type" = "npprjx${var.subscription_type}" "node_pool_os" = "linux" "environment" = "${var.environment}" "app" = "prjx_${var.subscription_type}_app" } tags = var.tags } ingress_application_gateway { gateway_id = azurerm_application_gateway.network.id } # Enabled the cluster configuration to the Azure kubernets with RBAC azure_active_directory_role_based_access_control { managed = true admin_group_object_ids = var.active_directory_role_based_access_control_admin_group_object_ids azure_rbac_enabled = true #false } network_profile { network_plugin = "azure" network_policy = "azure" outbound_type = "userDefinedRouting" } identity { type = "SystemAssigned" } oms_agent { log_analytics_workspace_id = module.log_analytics_workspace[0].id } timeouts { create = "20m" delete = "20m" } depends_on = [ azurerm_application_gateway.network ] }
原始LoadBalancer Service配置
apiVersion: v1 kind: Service metadata: name: aks-helloworld spec: type: LoadBalancer ports: - port: 80 selector: app: aks-helloworld-two
内容的提问来源于stack exchange,提问作者One Developer
相关产品推荐
相关产品推荐

