EKS 1.14分支化部署场景下Nginx Ingress正则配置方案问询
Solution for Branch-Based Routing with Single Nginx Ingress in EKS 1.14
Alright, let's fix this up so you can manage all your branch routes with a single Ingress resource. Your current config hardcodes each branch, which won't scale—we'll use Nginx Ingress's regex capabilities and dynamic service routing to make this work smoothly.
Key Concepts to Implement
- Regex host matching to capture the branch name from URLs like
apache-b1.example.com - Dynamic routing to the corresponding namespace's
service_Ausing Nginx configuration snippets - TLS configuration aligned with wildcard certificate coverage for all branch subdomains
Final Ingress Configuration
apiVersion: networking.k8s.io/v1beta1 kind: Ingress metadata: name: branch-apache-ingress annotations: kubernetes.io/ingress.class: "nginx" cert-manager.io/cluster-issuer: "letsencrypt-prod" # Enable regex processing for host rules nginx.ingress.kubernetes.io/use-regex: "true" # Extract branch name and route to the correct namespace's service nginx.ingress.kubernetes.io/server-snippet: | set $branch ""; if ($host ~* "^apache-(?<branch>[a-z0-9-]+)\.example\.com$") { set $branch $branch; } proxy_pass http://service_A.$branch.svc.cluster.local:80; spec: tls: - hosts: - "*.example.com" # Adjust to match your wildcard certificate's coverage secretName: prod-crt rules: - host: "apache-*.example.com" # Catch-all for all branch subdomains http: paths: - backend: # Dummy backend (overridden by server-snippet, required for schema validation) serviceName: default-http-backend servicePort: 80
Breakdown of the Configuration
Regex Host Matching:
- The
use-regex: "true"annotation turns on regex processing for host rules. - The
apache-*.example.comhost acts as a catch-all, and the server-snippet uses a regex to extract the branch name (e.g.,b1fromapache-b1.example.com) into a variable.
- The
Dynamic Service Routing:
- The captured
$branchvariable is used to build the full service FQDN:service_A.$branch.svc.cluster.local. This directly targets theservice_Arunning in the branch's dedicated namespace (e.g.,service_A.b1.svc.cluster.localfor branch B1).
- The captured
TLS Setup:
- The wildcard certificate
*.example.comcovers allapache-*.example.comsubdomains. Ensure your cert-manager ClusterIssuer is configured to issue valid wildcard certificates for your domain.
- The wildcard certificate
Important Notes
- Namespace Alignment: Make sure your branch namespaces exactly match the branch name in the URL (e.g., namespace
b1forapache-b1.example.com). - Ingress Controller Compatibility: For EKS 1.14, use a Nginx Ingress Controller version v0.26.x or newer to support the
use-regexandserver-snippetannotations. - DNS Configuration: Point all
apache-*.example.comrecords to the external IP of your Nginx Ingress Controller's LoadBalancer service. - Dummy Backend: The
default-http-backendis a placeholder required to pass Kubernetes Ingress schema validation—Nginx will override this with the dynamicproxy_passrule.
内容的提问来源于stack exchange,提问作者me25
相关产品推荐
相关产品推荐

