ALB Ingress混合公网与私有路径配置咨询
Hey George, great question—let’s walk through your options clearly:
Can you make specific paths private via route configuration or Ingress annotations?
Short answer: No, you can’t do this with just path routing or standard ALB Ingress annotations. Here’s why:
- Your existing Ingress is tied to an internet-facing ALB, and the ALB’s "scheme" (public vs. internal) is a global setting for the entire load balancer. All paths routed through this ALB will be exposed to the public internet by default, since the ALB itself is publicly accessible.
- Path routing only controls how traffic is forwarded to backend services once it reaches the ALB—it doesn’t restrict whether the path is reachable from the public internet. Annotations like
alb.ingress.kubernetes.io/listen-portsor path rules don’t override the ALB’s public accessibility.
You could technically layer on AWS WAF rules or security group restrictions to block public access to specific paths, but that’s not a pure Ingress/route configuration solution, and it adds unnecessary complexity.
Can you deploy a second internal Ingress under the same ALB?
Nope, you can’t share the same ALB between public and internal Ingress resources. The ALB’s scheme (internet-facing vs. internal) is a fixed property set at creation—you can’t split traffic between public and internal on the same load balancer.
But here’s the right approach:
- Create a separate internal ALB Ingress for your new private microservices. Use the annotation
alb.ingress.kubernetes.io/scheme: internalto ensure this ALB is only accessible within your VPC. - Your existing public microservices (running in the same VPC) can communicate with the private microservices either:
- Directly via their Kubernetes ClusterIP service names (e.g.,
http://private-service.default.svc.cluster.local), which is the most efficient and recommended method, or - Through the internal ALB’s DNS name, if you need to use path-based routing for the private services.
- Directly via their Kubernetes ClusterIP service names (e.g.,
Quick example of an internal Ingress for private services:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: internal-private-ingress annotations: alb.ingress.kubernetes.io/scheme: internal alb.ingress.kubernetes.io/target-type: ip spec: ingressClassName: alb rules: - http: paths: - path: /private-service/* pathType: Prefix backend: service: name: private-microservice port: number: 80
This setup keeps your private microservices isolated from the public internet while letting them communicate seamlessly with your existing public services.
内容的提问来源于stack exchange,提问作者George S.

