GKE集群Nginx Ingress客户端IP未转发致白名单失效问题排查
问题原因与解决步骤
核心问题
GKE环境中,Nginx Ingress Controller前端会经过GCP的HTTP(S)负载均衡器,实际客户端IP会被放在X-Forwarded-For请求头中。默认情况下Nginx Ingress不会使用这个请求头来匹配白名单,导致它识别到的客户端IP是GCP LB的内部IP甚至127.0.0.1,最终触发403拦截。
必要配置补充
需要给Ingress添加两个关键注解,让Nginx Ingress信任GCP负载均衡器代理,并基于X-Forwarded-For中的真实客户端IP进行白名单校验:
- 添加
nginx.ingress.kubernetes.io/configuration-snippet注解,指定Nginx使用X-Forwarded-For作为客户端IP的来源:real_ip_header X-Forwarded-For; - 添加
nginx.ingress.kubernetes.io/trusted-proxies注解,配置GCP负载均衡器的IP段(GKE官方默认的LB出口IP段为130.211.0.0/22和35.191.0.0/16,可根据实际环境调整):nginx.ingress.kubernetes.io/trusted-proxies: "130.211.0.0/22,35.191.0.0/16"
修改后的完整Ingress清单
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: my_app annotations: nginx.ingress.kubernetes.io/whitelist-source-range: x.x.x.x/32 nginx.ingress.kubernetes.io/configuration-snippet: | real_ip_header X-Forwarded-For; nginx.ingress.kubernetes.io/trusted-proxies: "130.211.0.0/22,35.191.0.0/16" spec: ingressClassName: nginx rules: - host: my_app.company.com http: paths: - backend: service: name: my_app port: number: 80 path: / pathType: ImplementationSpecific tls: - hosts: - my_app.company.com secretName: certificate.tls
验证操作
- 应用修改后的Ingress配置:
kubectl apply -f your-ingress-file.yaml - 等待Ingress Controller重新加载配置(通常需几秒到几十秒)
- 从允许的IP访问应用,检查是否返回正常响应,同时查看Ingress Controller日志,确认客户端IP已显示为真实的外部IP。
内容的提问来源于stack exchange,提问作者Naran
相关产品推荐
相关产品推荐

