You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

HAProxy Kubernetes Ingress日志显示节点IP,如何获取真实客户端IP?

解决方案

方案一:改回hostPort部署(直接获取真实客户端IP)

直接在DaemonSet的容器配置中添加hostPort,让HAProxy直接绑定节点的端口,客户端请求直接到达HAProxy进程,此时默认日志格式中的%ci会直接记录真实客户端IP。

修改DaemonSet的容器端口配置片段:

containers:
- name: haproxy-ingress
  image: haproxytech/kubernetes-ingress:latest
  ports:
  - name: http
    containerPort: 80
    hostPort: 80  # 绑定节点80端口
  - name: https
    containerPort: 443
    hostPort: 443  # 绑定节点443端口
  securityContext:
    privileged: true  # 部分环境需特权模式以绑定主机端口

部署后,客户端直接访问节点的80/443端口,HAProxy日志中的%ci字段将显示真实客户端IP。

方案二:保留externalTrafficPolicy=local的Service,修正源IP传递

如果坚持使用Service而非hostPort,需确保以下配置正确:

  1. Service配置要求
    必须使用NodePort或LoadBalancer类型的Service,且externalTrafficPolicy设为Local,避免Kubernetes对请求做SNAT(源地址转换),确保真实客户端IP传递到Pod:

    apiVersion: v1
    kind: Service
    metadata:
      name: haproxy-ingress
    spec:
      type: NodePort
      externalTrafficPolicy: Local
      ports:
      - name: http
        port: 80
        nodePort: 30080  # 可指定节点端口,或留空自动分配
      - name: https
        port: 443
        nodePort: 30443
      selector:
        app: haproxy-ingress  # 匹配DaemonSet的Pod标签
    
  2. 确认HAProxy配置
    确保HAProxy Ingress的前端监听配置为0.0.0.0(默认配置通常已满足),无额外修改源IP的配置项。此时Pod接收的请求源IP应为客户端真实IP,默认日志格式的%ci字段即可正确记录。

若仍显示节点IP,可检查:

  • 节点的kube-proxy配置是否支持保留源IP(需确认kube-proxy处于iptables或ipvs模式,且externalTrafficPolicy=Local生效)
  • 集群网络插件是否支持源IP保留(如Calico、Flannel等多数主流插件均支持)

内容的提问来源于stack exchange,提问作者Pharaoh Tools

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 13:30:42