You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GKE启用SSL后健康检查与Kubernetes探针失效问题求助

解决GKE上Spring Boot微服务的GCP健康检查与K8s探针问题

Hey there! Let’s work through this GCP health check issue you’re hitting with your Spring Boot microservices on GKE. You mentioned you’ve already found a solution for the Kubernetes probe scheme, so I’ll dive into the GCP health check service annotation details you need, plus some extra context to make sure everything works smoothly.

一、先确认你的Kubernetes探针配置(补充细节)

Since your microservices use self-signed certificates, just setting the scheme: HTTPS isn’t enough—you also need to disable certificate verification for the probes (otherwise they’ll fail because the self-signed cert isn’t trusted by the K8s control plane). Here’s a complete probe config example:

livenessProbe:
  httpGet:
    path: /actuator/health  # 匹配你的Spring Boot健康检查端点
    port: 8443              # 微服务的HTTPS端口
    scheme: HTTPS
  initialDelaySeconds: 30
  periodSeconds: 10
  failureThreshold: 3
readinessProbe:
  httpGet:
    path: /actuator/health
    port: 8443
    scheme: HTTPS
  initialDelaySeconds: 5
  periodSeconds: 5
  failureThreshold: 3

# 关键:添加注解跳过探针的SSL证书验证(自签证书场景必需)
metadata:
  annotations:
    probe.alpha.kubernetes.io/skip-verify: "true"

二、修复GCP健康检查自动切回HTTP的问题

你手动修改HTTPS健康检查后自动切回HTTP,核心原因是GCE Ingress会根据Service配置自动生成健康检查——你需要通过Service注解和BackendConfig资源明确告诉GCP使用HTTPS健康检查。

步骤1:给Service添加BackendConfig绑定注解

通过注解将Service与自定义BackendConfig关联:

apiVersion: v1
kind: Service
metadata:
  name: your-spring-boot-service
  annotations:
    # 将Service绑定到自定义BackendConfig(替换为你的配置名称)
    cloud.google.com/backend-config: '{"default": "spring-boot-https-backend"}'
spec:
  ports:
  - port: 443
    targetPort: 8443  # 匹配微服务的HTTPS端口
    protocol: TCP
  selector:
    app: your-spring-boot-app

步骤2:创建BackendConfig资源

这个资源定义HTTPS健康检查的具体规则,包括关闭自签证书的验证:

apiVersion: cloud.google.com/v1
kind: BackendConfig
metadata:
  name: spring-boot-https-backend
spec:
  healthCheck:
    checkIntervalSec: 10
    timeoutSec: 5
    healthyThreshold: 2
    unhealthyThreshold: 3
    type: HTTPS  # 强制GCP使用HTTPS进行健康检查
    requestPath: /actuator/health  # 匹配你的健康检查端点
    port: 8443  # 微服务的HTTPS端口
    # 自签证书场景必需:关闭证书验证
    sslHealthCheck:
      verifyCertificate: false
      portSpecification: USE_FIXED_PORT
      proxyHeader: NONE

配置关键说明:

  • cloud.google.com/backend-config:这个注解是Service与自定义健康检查配置的纽带——没有它,GCP会默认生成HTTP健康检查。
  • type: HTTPS:明确指定健康检查协议为HTTPS。
  • verifyCertificate: false:自签证书场景下必须设置,因为GCP健康检查系统默认不信任未受信的证书。
  • 确保BackendConfig和Service在同一个Namespace下,否则绑定会失败。

三、验证配置是否生效

部署更新后的Service和BackendConfig后:

  1. 执行kubectl apply -f your-service.yaml -f your-backend-config.yaml应用配置。
  2. 查看GCP控制台:进入负载均衡 > 后端服务,确认健康检查使用HTTPS,路径和端口配置正确。
  3. 检查Pod状态:kubectl describe pod <your-pod-name>——查看探针事件是否成功(无SSL错误)。
  4. 查看Spring Boot日志:现在应该能看到健康检查请求命中HTTPS端点了(之前无记录是因为HTTP请求被HTTPS端口拒绝)。

四、需要避免的常见坑点

  • 不要遗漏探针和健康检查的证书验证配置:同时需要给K8s探针添加probe.alpha.kubernetes.io/skip-verify注解,以及在BackendConfig中设置verifyCertificate: false——缺一个都会导致失败。
  • 端口匹配要准确:确保Service的targetPort和BackendConfig的port与微服务实际的HTTPS端口一致(比如8443,不是8080)。
  • Namespace要一致:Service和BackendConfig必须在同一个Namespace下,GCP不会跨Namespace关联健康检查资源。

内容的提问来源于stack exchange,提问作者BertKlinger

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 23:42:39