跨Azure区域的Azure Kubernetes集群应用如何实现负载均衡?
Awesome question! When you're running apps across AKS clusters in two different Azure regions, you've got a handful of robust Azure-native options to set up cross-region load balancing. Let's walk through the most practical approaches, with pros and use cases for each:
This is the go-to choice for global public-facing apps, since it operates at Layer 7 (HTTP/HTTPS) and packs extra features like WAF, caching, and SSL termination. Here's how to set it up:
- First, deploy your app to each AKS cluster. Expose the app using an Ingress Controller (like NGINX, deploy via
helm install nginx-ingress ingress-nginx/ingress-nginx --set controller.service.type=LoadBalancer) or a standard LoadBalancer service to get a public endpoint for each cluster. - Create an Azure Front Door instance, then add each AKS cluster's public endpoint (Ingress/LoadBalancer IP) as a backend pool. For private clusters, you can use Azure Private Link to connect AFD directly to your cluster's internal endpoints without exposing them to the public internet.
- Configure routing rules to define how traffic is distributed: use Performance-based routing to send users to the closest healthy region, Weighted routing to split traffic proportionally, or Priority routing for failover (send traffic to the primary region unless it's unhealthy).
- Set up health probes (e.g., pointing to your app's
/healthzendpoint) so AFD automatically stops sending traffic to any unhealthy cluster instances.
Pros: Global coverage, built-in security (WAF/DDoS protection), seamless failover, and HTTPS termination at the edge.
If you need a lightweight, cost-effective Layer 4 option, Traffic Manager works by resolving DNS queries to direct users to the right region. Here's the workflow:
- Ensure each AKS cluster's app has a public, reachable endpoint (again, via LoadBalancer or Ingress).
- Create a Traffic Manager profile, then add each cluster's endpoint as an External Endpoint (input the public IP or FQDN).
- Choose a routing method:
- Performance: Routes users to the region with the lowest latency.
- Weighted: Lets you assign traffic percentages to each region (great for canary deployments).
- Priority: Uses one region as primary, switches to secondary only if the primary fails.
- Configure health checks to validate endpoint availability – Traffic Manager will automatically remove unhealthy endpoints from DNS resolution.
Note: Since this is DNS-based, failover depends on DNS TTL settings (keep it short, like 30 seconds, to speed up switches, but be aware of client-side DNS caching).
If your app is only for internal enterprise use (no public access), you can combine VNet peering with internal load balancing tools:
- First, set up cross-region VNet peering between the VNets hosting your two AKS clusters. This lets resources in each VNet communicate directly.
- Deploy an Internal Load Balancer (ILB) for your app in each AKS cluster, so the app is only accessible within the VNet.
- Use Traffic Manager Premium (which supports internal endpoints) to route internal traffic between the two ILBs. Alternatively, deploy an Azure Application Gateway v2 (which supports cross-VNet access) to act as a central internal load balancer.
Pros: No public exposure, secure internal traffic routing, and full control over network access.
For larger, more complex multi-cluster setups, Azure Arc helps you unify management across your AKS clusters, while pairing with one of the above load balancing tools:
- Register both AKS clusters with Azure Arc to get centralized monitoring, policy enforcement, and configuration management.
- Use Arc's Cluster Connect to access and manage both clusters from a single pane, without needing direct VPN or public access.
- Pair Arc with Azure Front Door or Traffic Manager for global load balancing, and use Arc Policies to ensure app configurations are consistent across both regions.
Quick Decision Guide
- Need global public access with advanced security/features? Go with Azure Front Door.
- Want simple, low-cost DNS-based routing/failover? Choose Azure Traffic Manager.
- Internal-only app? Use VNet Peering + Traffic Manager Premium (Internal Endpoints).
- Enterprise multi-cluster management? Combine Azure Arc with one of the above load balancers.
内容的提问来源于stack exchange,提问作者One Developer

