Grafana通过Ingress相对路径暴露后探针失败问题求助
Got it, let's break down why your readiness probe is failing and fix it step by step.
The Root Cause
When you set GF_SERVER_ROOT_URL=http://chart-example.local/grafana/, Grafana expects all external traffic to reach it via the /grafana/ prefix. But by default, Grafana doesn't natively serve content from a subpath—so when your probe hits the root path / of the Pod, Grafana redirects it to /grafana/ (matching your root URL config).
Here's the problem: from the Pod's internal perspective, there's no Ingress forwarding /grafana/ to the Pod's /. So when the probe follows that redirect to /grafana/, Grafana doesn't recognize this as its root path and redirects again to /grafana/grafana/, creating an infinite redirect loop. After 10 redirects, Kubernetes kills the probe check and restarts the container.
Your direct access to http://${pods_ip}:3000/login works because you're bypassing the root path / entirely—Grafana doesn't trigger the subpath redirect for specific endpoints like /login.
The Fix
You need two key changes to make this work properly:
Enable subpath serving in Grafana
Add theGF_SERVER_SERVE_FROM_SUB_PATH=trueenvironment variable. This tells Grafana to treat/grafana/as its internal root path, so it won't redirect requests for that prefix.Update your probe paths
Since Grafana is now serving content from/grafana/, your liveness and readiness probes need to hit this path instead of the root/.
Here's the updated container section of your Deployment:
containers: - name: {{ .Chart.Name }}-grafana image: "{{ .Values.grafana.image.repository }}:{{ .Values.grafana.image.tag | default .Chart.AppVersion }}" env: - name: GF_SERVER_ROOT_URL value: http://chart-example.local/grafana/ - name: GF_SERVER_SERVE_FROM_SUB_PATH value: "true" ports: - name: http containerPort: 3000 protocol: TCP livenessProbe: httpGet: path: /grafana/ port: http readinessProbe: httpGet: path: /grafana/ port: http
Why This Works
GF_SERVER_SERVE_FROM_SUB_PATH=truemakes Grafana handle requests to/grafana/as if they were hitting the root/, eliminating the redirect loop.- The probes now target the correct subpath, so they get a valid 200 response instead of being redirected repeatedly.
Once you apply this change, your probes should pass, and the container will stay running while working correctly with your Ingress subpath setup.
内容的提问来源于stack exchange,提问作者zar3bski

