You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GKE集群Nginx Ingress客户端IP未转发致白名单失效问题排查

问题原因与解决步骤

核心问题

GKE环境中,Nginx Ingress Controller前端会经过GCP的HTTP(S)负载均衡器,实际客户端IP会被放在X-Forwarded-For请求头中。默认情况下Nginx Ingress不会使用这个请求头来匹配白名单,导致它识别到的客户端IP是GCP LB的内部IP甚至127.0.0.1,最终触发403拦截。

必要配置补充

需要给Ingress添加两个关键注解,让Nginx Ingress信任GCP负载均衡器代理,并基于X-Forwarded-For中的真实客户端IP进行白名单校验:

  • 添加nginx.ingress.kubernetes.io/configuration-snippet注解,指定Nginx使用X-Forwarded-For作为客户端IP的来源:
    real_ip_header X-Forwarded-For;
    
  • 添加nginx.ingress.kubernetes.io/trusted-proxies注解,配置GCP负载均衡器的IP段(GKE官方默认的LB出口IP段为130.211.0.0/22和35.191.0.0/16,可根据实际环境调整):
    nginx.ingress.kubernetes.io/trusted-proxies: "130.211.0.0/22,35.191.0.0/16"
    

修改后的完整Ingress清单

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: my_app
  annotations:
    nginx.ingress.kubernetes.io/whitelist-source-range: x.x.x.x/32
    nginx.ingress.kubernetes.io/configuration-snippet: |
      real_ip_header X-Forwarded-For;
    nginx.ingress.kubernetes.io/trusted-proxies: "130.211.0.0/22,35.191.0.0/16"
spec:
  ingressClassName: nginx
  rules:
  - host: my_app.company.com
    http:
      paths:
      - backend:
          service:
            name: my_app
            port:
              number: 80
        path: /
        pathType: ImplementationSpecific
  tls:
  - hosts:
    - my_app.company.com
    secretName: certificate.tls

验证操作

  1. 应用修改后的Ingress配置:
    kubectl apply -f your-ingress-file.yaml
    
  2. 等待Ingress Controller重新加载配置(通常需几秒到几十秒)
  3. 从允许的IP访问应用,检查是否返回正常响应,同时查看Ingress Controller日志,确认客户端IP已显示为真实的外部IP。

内容的提问来源于stack exchange,提问作者Naran

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 06:50:15