You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EKS 1.14分支化部署场景下Nginx Ingress正则配置方案问询

Solution for Branch-Based Routing with Single Nginx Ingress in EKS 1.14

Alright, let's fix this up so you can manage all your branch routes with a single Ingress resource. Your current config hardcodes each branch, which won't scale—we'll use Nginx Ingress's regex capabilities and dynamic service routing to make this work smoothly.

Key Concepts to Implement

  • Regex host matching to capture the branch name from URLs like apache-b1.example.com
  • Dynamic routing to the corresponding namespace's service_A using Nginx configuration snippets
  • TLS configuration aligned with wildcard certificate coverage for all branch subdomains

Final Ingress Configuration

apiVersion: networking.k8s.io/v1beta1
kind: Ingress
metadata:
  name: branch-apache-ingress
  annotations:
    kubernetes.io/ingress.class: "nginx"
    cert-manager.io/cluster-issuer: "letsencrypt-prod"
    # Enable regex processing for host rules
    nginx.ingress.kubernetes.io/use-regex: "true"
    # Extract branch name and route to the correct namespace's service
    nginx.ingress.kubernetes.io/server-snippet: |
      set $branch "";
      if ($host ~* "^apache-(?<branch>[a-z0-9-]+)\.example\.com$") {
        set $branch $branch;
      }
      proxy_pass http://service_A.$branch.svc.cluster.local:80;
spec:
  tls:
  - hosts:
      - "*.example.com" # Adjust to match your wildcard certificate's coverage
    secretName: prod-crt
  rules:
  - host: "apache-*.example.com" # Catch-all for all branch subdomains
    http:
      paths:
      - backend:
          # Dummy backend (overridden by server-snippet, required for schema validation)
          serviceName: default-http-backend
          servicePort: 80

Breakdown of the Configuration

  1. Regex Host Matching:

    • The use-regex: "true" annotation turns on regex processing for host rules.
    • The apache-*.example.com host acts as a catch-all, and the server-snippet uses a regex to extract the branch name (e.g., b1 from apache-b1.example.com) into a variable.
  2. Dynamic Service Routing:

    • The captured $branch variable is used to build the full service FQDN: service_A.$branch.svc.cluster.local. This directly targets the service_A running in the branch's dedicated namespace (e.g., service_A.b1.svc.cluster.local for branch B1).
  3. TLS Setup:

    • The wildcard certificate *.example.com covers all apache-*.example.com subdomains. Ensure your cert-manager ClusterIssuer is configured to issue valid wildcard certificates for your domain.

Important Notes

  • Namespace Alignment: Make sure your branch namespaces exactly match the branch name in the URL (e.g., namespace b1 for apache-b1.example.com).
  • Ingress Controller Compatibility: For EKS 1.14, use a Nginx Ingress Controller version v0.26.x or newer to support the use-regex and server-snippet annotations.
  • DNS Configuration: Point all apache-*.example.com records to the external IP of your Nginx Ingress Controller's LoadBalancer service.
  • Dummy Backend: The default-http-backend is a placeholder required to pass Kubernetes Ingress schema validation—Nginx will override this with the dynamic proxy_pass rule.

内容的提问来源于stack exchange,提问作者me25

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 00:54:09