如何通过单个URL让Traefik Ingress路由转发流量到多端口
问题分析
当前访问abc.xyz.com时流量轮询分发是因为你的IngressRoute将两个服务并列配置在同一条路由规则下;而abc.xyz.com:1001/1002无法访问的核心原因是:Traefik未监听这两个端口,也没有对应的路由规则将端口流量导向对应服务。
解决方案
要实现URL+端口的流量路由,需要完成以下三步配置:
1. 让Traefik监听1001/1002端口
修改Traefik的配置,添加对应入口点(entryPoints),并在DaemonSet中暴露主机端口:
修改Traefik ConfigMap(kube-system命名空间下)
apiVersion: v1 kind: ConfigMap metadata: name: traefik-config namespace: kube-system data: traefik.yaml: | entryPoints: web: address: ":80" websecure: address: ":443" foo-port: # 对应1001端口的入口点 address: ":1001" bar-port: # 对应1002端口的入口点 address: ":1002"
更新Traefik DaemonSet(kube-system命名空间下)
添加主机端口映射,让外部流量能访问到Traefik的1001/1002端口:
apiVersion: apps/v1 kind: DaemonSet metadata: name: traefik namespace: kube-system spec: template: spec: containers: - name: traefik ports: - name: web containerPort: 80 hostPort: 80 - name: websecure containerPort: 443 hostPort: 443 - name: foo-port containerPort: 1001 hostPort: 1001 # 绑定主机1001端口 - name: bar-port containerPort: 1002 hostPort: 1002 # 绑定主机1002端口
2. 配置端口对应的IngressRoute规则
创建独立的路由规则,将每个端口的流量导向对应服务。你可以选择拆分两个IngressRoute,或者在原IngressRoute中新增路由条目:
方案A:拆分独立IngressRoute
针对foo服务的IngressRoute
apiVersion: traefik.containo.us/v1alpha1 kind: IngressRoute metadata: name: ingress-foo namespace: project spec: entryPoints: - foo-port # 绑定1001端口的入口点 routes: - kind: Rule match: Host(`abc.xyz.com`) priority: 1 services: - kind: Service name: foo namespace: project port: port-foo # 确保Service中已定义该端口名称 tls: domains: - main: xyz.com sans: - "*.xyz.com" secretName: xyz-cert
针对bar服务的IngressRoute
apiVersion: traefik.containo.us/v1alpha1 kind: IngressRoute metadata: name: ingress-bar namespace: project spec: entryPoints: - bar-port # 绑定1002端口的入口点 routes: - kind: Rule match: Host(`abc.xyz.com`) priority: 1 services: - kind: Service name: bar namespace: project port: port-bar # 确保Service中已定义该端口名称 tls: domains: - main: xyz.com sans: - "*.xyz.com" secretName: xyz-cert
方案B:在原IngressRoute中新增路由条目
apiVersion: traefik.containo.us/v1alpha1 kind: IngressRoute metadata: name: ingress namespace: project spec: routes: # 原有的websecure端口(443)轮询规则 - kind: Rule match: Host(`abc.xyz.com`) priority: 1 entryPoints: - websecure services: - kind: Service name: foo namespace: project port: port-foo - kind: Service name: bar namespace: project port: port-bar # 新增1001端口路由规则 - kind: Rule match: Host(`abc.xyz.com`) priority: 1 entryPoints: - foo-port services: - kind: Service name: foo namespace: project port: port-foo # 新增1002端口路由规则 - kind: Rule match: Host(`abc.xyz.com`) priority: 1 entryPoints: - bar-port services: - kind: Service name: bar namespace: project port: port-bar tls: domains: - main: xyz.com sans: - "*.xyz.com" secretName: xyz-cert
3. 验证Service端口名称配置
确保你的foo和bar Service已正确定义端口名称port-foo和port-bar,例如:
apiVersion: v1 kind: Service metadata: name: foo namespace: project spec: ports: - name: port-foo # 必须与IngressRoute中引用的名称一致 port: 1001 targetPort: 1001 selector: app: foo
验证配置
- 重启Traefik Pod让配置生效:
kubectl rollout restart daemonset traefik -n kube-system - 应用新的IngressRoute配置:
kubectl apply -f <你的IngressRoute文件> - 访问
abc.xyz.com:1001和abc.xyz.com:1002,验证流量是否正确路由到对应服务
内容的提问来源于stack exchange,提问作者Alex
相关产品推荐
相关产品推荐

