You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

本地React客户端连接Azure K8s集群Auth服务遇403问题排查

问题描述

我在Azure上部署了两个Deployment及对应Service:React客户端和Node.js Auth服务。已将公网IP映射到Windows hosts文件的域名myexample.com,浏览器访问云端客户端时一切正常,请求能正确转发到Auth服务。

现在想本地通过npm start运行客户端,但调用Azure上的Auth服务。我已经删除了云端的客户端Deployment和Service,并且在React的axios客户端中把myexample.cloud设为基础URL。确认Azure上的ingress-nginx-controller是LoadBalancer类型,外部IP就是之前的公网IP,端口映射为80:30819/TCP、443:31077/TCP。

本地运行客户端时,请求URL显示正确(http://myexample.cloud/api/users/signin),但返回403 Forbidden错误。

补充说明:这个403不是登录凭证错误,api/users/health-check接口也返回同样错误。


云端Ingress配置(移除客户端规则后仍无效)

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: ingress-service
  annotations:
    nginx.ingress.kubernetes.io/use-regex: "true"
    kubernetes.io/ingress.class: nginx
spec:
  rules:
    - host: myexample.cloud
      http:
        paths:
          - path: /api/users/?(.*)
            pathType: Prefix
            backend:
              service:
                name: auth-srv
                port:
                  number: 3000
          - path: /
            pathType: Prefix
            backend:
              service:
                name: client-srv
                port:
                  number: 3000

云端客户端正常运行时的Deployment及Service配置

apiVersion: apps/v1
kind: Deployment
metadata:
  name: client
spec:
  replicas: 1
  selector:
    matchLabels:
      app: client
  template:
    metadata:
      labels:
        app: client
    spec:
      containers:
        - name: client
          image: client
---
apiVersion: v1
kind: Service
metadata:
  name: client
spec:
  selector:
    app: client
  ports:
    - name: client
      protocol: TCP
      port: 3000
      targetPort: 3000

Auth服务的Deployment及Service配置

apiVersion: apps/v1
kind: Deployment
metadata:
  name: auth
spec:
  replicas: 1
  selector:
    matchLabels:
      app: auth
  template:
    metadata:
      labels:
        app: auth
    spec:
      containers:
        - name: auth
          image: auth
---
apiVersion: v1
kind: Service
metadata:
  name: auth
spec:
  selector:
    app: auth
  ports:
    - name: auth
      protocol: TCP
      port: 3000
      targetPort: 3000

内容的提问来源于stack exchange,提问作者willi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 18:15:51