You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ALB Ingress混合公网与私有路径配置咨询

Hey George, great question—let’s walk through your options clearly:

Can you make specific paths private via route configuration or Ingress annotations?

Short answer: No, you can’t do this with just path routing or standard ALB Ingress annotations. Here’s why:

  • Your existing Ingress is tied to an internet-facing ALB, and the ALB’s "scheme" (public vs. internal) is a global setting for the entire load balancer. All paths routed through this ALB will be exposed to the public internet by default, since the ALB itself is publicly accessible.
  • Path routing only controls how traffic is forwarded to backend services once it reaches the ALB—it doesn’t restrict whether the path is reachable from the public internet. Annotations like alb.ingress.kubernetes.io/listen-ports or path rules don’t override the ALB’s public accessibility.

You could technically layer on AWS WAF rules or security group restrictions to block public access to specific paths, but that’s not a pure Ingress/route configuration solution, and it adds unnecessary complexity.

Can you deploy a second internal Ingress under the same ALB?

Nope, you can’t share the same ALB between public and internal Ingress resources. The ALB’s scheme (internet-facing vs. internal) is a fixed property set at creation—you can’t split traffic between public and internal on the same load balancer.

But here’s the right approach:

  • Create a separate internal ALB Ingress for your new private microservices. Use the annotation alb.ingress.kubernetes.io/scheme: internal to ensure this ALB is only accessible within your VPC.
  • Your existing public microservices (running in the same VPC) can communicate with the private microservices either:
    1. Directly via their Kubernetes ClusterIP service names (e.g., http://private-service.default.svc.cluster.local), which is the most efficient and recommended method, or
    2. Through the internal ALB’s DNS name, if you need to use path-based routing for the private services.

Quick example of an internal Ingress for private services:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: internal-private-ingress
  annotations:
    alb.ingress.kubernetes.io/scheme: internal
    alb.ingress.kubernetes.io/target-type: ip
spec:
  ingressClassName: alb
  rules:
  - http:
      paths:
      - path: /private-service/*
        pathType: Prefix
        backend:
          service:
            name: private-microservice
            port:
              number: 80

This setup keeps your private microservices isolated from the public internet while letting them communicate seamlessly with your existing public services.

内容的提问来源于stack exchange,提问作者George S.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 20:07:27