You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google Cloud上K8s集群(GCE Ingress)特定端点访问限制方案咨询

解决方案

方案一:Nginx Sidecar + 静态Token认证(轻量首选)

这个方案无需额外复杂服务,仅给应用Pod添加一个Nginx Sidecar容器,通过简单的Token验证限制/test/*路径,其余路径直接放行,完全匹配你轻量、灵活的需求。

步骤1:编写Nginx配置文件

创建ConfigMap定义路由与认证规则,这里提供两种认证方式可选:

方式A:基于请求头的Token验证(更适合手机端)

server {
    listen 8080;

    # 公开路径:直接转发到应用容器(假设应用监听80端口)
    location / {
        proxy_pass http://localhost:80;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
    }

    # 受限路径:验证请求头中的X-API-Key
    location /test/ {
        if ($http_x_api_key != "YOUR_CUSTOM_SECRET_TOKEN") {
            return 403;
        }
        proxy_pass http://localhost:80;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
    }
}

手机端访问时,只需在请求头中添加X-API-Key: YOUR_CUSTOM_SECRET_TOKEN即可。

方式B:基于HTTP Basic认证

server {
    listen 8080;

    location / {
        proxy_pass http://localhost:80;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
    }

    location /test/ {
        auth_basic "Restricted Test Area";
        auth_basic_user_file /etc/nginx/htpasswd;
        proxy_pass http://localhost:80;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
    }
}

需要额外生成htpasswd文件并挂载到Sidecar中,适合习惯账号密码验证的场景。

步骤2:更新Deployment添加Sidecar

修改应用Deployment,加入Nginx Sidecar并挂载ConfigMap:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: your-app
spec:
  replicas: 3
  selector:
    matchLabels:
      app: your-app
  template:
    metadata:
      labels:
        app: your-app
    spec:
      containers:
      - name: your-app
        image: your-app-image:latest
        ports:
        - containerPort: 80
      - name: nginx-sidecar
        image: nginx:alpine
        ports:
        - containerPort: 8080
        volumeMounts:
        - name: nginx-config
          mountPath: /etc/nginx/conf.d/default.conf
          subPath: nginx.conf
      volumes:
      - name: nginx-config
        configMap:
          name: nginx-sidecar-config

步骤3:调整GCE Ingress配置

将Ingress后端指向Sidecar的8080端口(需确保对应Service已暴露该端口):

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: your-ingress
  annotations:
    kubernetes.io/ingress.class: "gce"
spec:
  rules:
  - host: your-domain.com
    http:
      paths:
      - path: /*
        pathType: ImplementationSpecific
        backend:
          service:
            name: your-app-service
            port:
              number: 8080

方案优势

  • 轻量:仅引入几十MB的Nginx Alpine容器,资源消耗可忽略
  • 灵活:Token可通过更新ConfigMap随时修改,手机端用Postman或自定义App添加请求头即可访问
  • 简单:无需服务网格或复杂云服务,配置全程不超过10分钟

方案二:应用代码内嵌简单认证(无Sidecar备选)

如果不想添加Sidecar,可直接在应用代码中加入少量认证逻辑,配合GCE Ingress路径分流实现需求:

  1. 复制现有应用Deployment,命名为your-app-restricted,在该实例的代码中添加路径认证逻辑。以Python Flask为例:
from flask import Flask, request, abort

app = Flask(__name__)
SECRET_TOKEN = "YOUR_CUSTOM_SECRET_TOKEN"

@app.before_request
def restrict_test_paths():
    if request.path.startswith('/test/'):
        if request.headers.get('X-API-Key') != SECRET_TOKEN:
            abort(403)

# 原有业务路由保留
@app.route('/')
def public_index():
    return "Public Content"

@app.route('/test/foo')
def restricted_test():
    return "Restricted Test Content"
  1. 配置GCE Ingress,将/test/*路径指向受限服务,其余路径指向原公开服务:
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: your-ingress
  annotations:
    kubernetes.io/ingress.class: "gce"
spec:
  rules:
  - host: your-domain.com
    http:
      paths:
      - path: /test/*
        pathType: ImplementationSpecific
        backend:
          service:
            name: your-app-restricted-service
            port:
              number: 80
      - path: /*
        pathType: ImplementationSpecific
        backend:
          service:
            name: your-app-service
            port:
              number: 80

排除方案说明

  • IAP:确实无法实现路径级细粒度限制,排除
  • VPN:配置复杂,需客户端安装软件,对手机用户来说反而不如Token认证便捷,排除
  • IP限制:手机IP频繁变动,维护成本极高,仅作为最终备选

内容的提问来源于stack exchange,提问作者Artem Dumanov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 19:18:39