You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为何已配置AppGateway作为Ingress Controller,AKS仍创建Azure Load Balancer?

AKS配置应用网关后仍创建Azure负载均衡器的原因解析

你的理解完全正确

  • LoadBalancer类型Service:由Kubernetes Azure云提供商控制器处理,会自动创建Azure负载均衡器,属于L4层流量暴露,直接将Pod端口映射到负载均衡器的公网/内网IP。
  • Ingress + 应用网关:属于L7层路由转发,通过应用网关Ingress控制器(AGIC)将Ingress资源规则同步到应用网关,后端服务只需使用ClusterIP类型即可,无需额外负载均衡器。

为什么部署LoadBalancer Service仍会创建Azure负载均衡器

你在Terraform中配置的ingress_application_gateway仅用于关联AKS与指定应用网关、部署AGIC控制器,让Ingress资源可以通过应用网关转发流量,但该配置不会修改LoadBalancer类型Service的默认行为。

LoadBalancer类型Service的创建逻辑由Kubernetes的Azure云提供商独立处理,和Ingress控制器是完全分离的两个功能模块,因此只要部署LoadBalancer类型的Service,AKS就会自动调用Azure API创建对应的负载均衡器。

基于应用网关的服务暴露正确方式

如果想通过应用网关暴露服务,应该:

  1. 将Service类型改为ClusterIP(默认类型,可省略显式声明):
apiVersion: v1
kind: Service
metadata:
  name: aks-helloworld 
spec:
  ports:
  - port: 80
  selector:
    app: aks-helloworld-two
  1. 创建对应的Ingress资源,AGIC会自动将路由规则同步到你的应用网关:
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: aks-helloworld-ingress
  annotations:
    kubernetes.io/ingress.class: azure/application-gateway
spec:
  rules:
  - http:
      paths:
      - path: /helloworld
        pathType: Prefix
        backend:
          service:
            name: aks-helloworld
            port:
              number: 80

附你的原始配置

Terraform AKS集群配置

# Create the Azure Kubernetes Service (AKS) Cluster
resource "azurerm_kubernetes_cluster" "kubernetes_cluster" {
  count                         = var.enable_kubernetes == true ? 1 : 0
  name                          = "aks-prjx-${var.subscription_type}-${var.environment}-${var.location}-${var.instance_number}"    
  location                      = var.location
  resource_group_name           = module.resource_group_kubernetes_cluster[0].name  # "rg-aks-spoke-dev-westus3-001"
  dns_prefix                    = "dns-aks-prjx-${var.subscription_type}-${var.environment}-${var.location}-${var.instance_number}" #"dns-prjxcluster"
  private_cluster_enabled       = false
  local_account_disabled        = true

  default_node_pool {
    name                        = "npprjx${var.subscription_type}" #"prjxsyspool" # NOTE: "name must start with a lowercase letter, have max length of 12, and only have characters a-z0-9."
    vm_size                     = "Standard_B8ms"
    vnet_subnet_id              = data.azurerm_subnet.aks-subnet.id
    # zones                     = ["1", "2", "3"]
    enable_auto_scaling         = true
    max_count                   = 3
    min_count                   = 1
    # node_count                = 3
    os_disk_size_gb             = 50
    type                        = "VirtualMachineScaleSets"
    enable_node_public_ip       = false
    enable_host_encryption      = false

    node_labels = {
      "node_pool_type"          = "npprjx${var.subscription_type}"
      "node_pool_os"            = "linux"
      "environment"             = "${var.environment}"
      "app"                     = "prjx_${var.subscription_type}_app"
    }
    tags = var.tags
  }

  ingress_application_gateway {
    gateway_id = azurerm_application_gateway.network.id
  }

  # Enabled the cluster configuration to the Azure kubernets with RBAC
  azure_active_directory_role_based_access_control { 
    managed                     = true
    admin_group_object_ids      = var.active_directory_role_based_access_control_admin_group_object_ids
    azure_rbac_enabled          = true #false
  }

  network_profile {
    network_plugin              = "azure"
    network_policy              = "azure"
    outbound_type               = "userDefinedRouting"
  }

  identity {
    type = "SystemAssigned"
  }  

  oms_agent {
    log_analytics_workspace_id  = module.log_analytics_workspace[0].id
  }

  timeouts {
    create = "20m"
    delete = "20m"
  }

  depends_on = [
    azurerm_application_gateway.network
  ]
}

原始LoadBalancer Service配置

apiVersion: v1
kind: Service
metadata:
  name: aks-helloworld 
spec:
  type: LoadBalancer
  ports:
  - port: 80
  selector:
    app: aks-helloworld-two

内容的提问来源于stack exchange,提问作者One Developer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 15:07:06