Google Cloud上K8s集群(GCE Ingress)特定端点访问限制方案咨询
解决方案
方案一:Nginx Sidecar + 静态Token认证(轻量首选)
这个方案无需额外复杂服务,仅给应用Pod添加一个Nginx Sidecar容器,通过简单的Token验证限制/test/*路径,其余路径直接放行,完全匹配你轻量、灵活的需求。
步骤1:编写Nginx配置文件
创建ConfigMap定义路由与认证规则,这里提供两种认证方式可选:
方式A:基于请求头的Token验证(更适合手机端)
server { listen 8080; # 公开路径:直接转发到应用容器(假设应用监听80端口) location / { proxy_pass http://localhost:80; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; } # 受限路径:验证请求头中的X-API-Key location /test/ { if ($http_x_api_key != "YOUR_CUSTOM_SECRET_TOKEN") { return 403; } proxy_pass http://localhost:80; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; } }
手机端访问时,只需在请求头中添加X-API-Key: YOUR_CUSTOM_SECRET_TOKEN即可。
方式B:基于HTTP Basic认证
server { listen 8080; location / { proxy_pass http://localhost:80; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; } location /test/ { auth_basic "Restricted Test Area"; auth_basic_user_file /etc/nginx/htpasswd; proxy_pass http://localhost:80; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; } }
需要额外生成htpasswd文件并挂载到Sidecar中,适合习惯账号密码验证的场景。
步骤2:更新Deployment添加Sidecar
修改应用Deployment,加入Nginx Sidecar并挂载ConfigMap:
apiVersion: apps/v1 kind: Deployment metadata: name: your-app spec: replicas: 3 selector: matchLabels: app: your-app template: metadata: labels: app: your-app spec: containers: - name: your-app image: your-app-image:latest ports: - containerPort: 80 - name: nginx-sidecar image: nginx:alpine ports: - containerPort: 8080 volumeMounts: - name: nginx-config mountPath: /etc/nginx/conf.d/default.conf subPath: nginx.conf volumes: - name: nginx-config configMap: name: nginx-sidecar-config
步骤3:调整GCE Ingress配置
将Ingress后端指向Sidecar的8080端口(需确保对应Service已暴露该端口):
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: your-ingress annotations: kubernetes.io/ingress.class: "gce" spec: rules: - host: your-domain.com http: paths: - path: /* pathType: ImplementationSpecific backend: service: name: your-app-service port: number: 8080
方案优势
- 轻量:仅引入几十MB的Nginx Alpine容器,资源消耗可忽略
- 灵活:Token可通过更新ConfigMap随时修改,手机端用Postman或自定义App添加请求头即可访问
- 简单:无需服务网格或复杂云服务,配置全程不超过10分钟
方案二:应用代码内嵌简单认证(无Sidecar备选)
如果不想添加Sidecar,可直接在应用代码中加入少量认证逻辑,配合GCE Ingress路径分流实现需求:
- 复制现有应用Deployment,命名为
your-app-restricted,在该实例的代码中添加路径认证逻辑。以Python Flask为例:
from flask import Flask, request, abort app = Flask(__name__) SECRET_TOKEN = "YOUR_CUSTOM_SECRET_TOKEN" @app.before_request def restrict_test_paths(): if request.path.startswith('/test/'): if request.headers.get('X-API-Key') != SECRET_TOKEN: abort(403) # 原有业务路由保留 @app.route('/') def public_index(): return "Public Content" @app.route('/test/foo') def restricted_test(): return "Restricted Test Content"
- 配置GCE Ingress,将
/test/*路径指向受限服务,其余路径指向原公开服务:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: your-ingress annotations: kubernetes.io/ingress.class: "gce" spec: rules: - host: your-domain.com http: paths: - path: /test/* pathType: ImplementationSpecific backend: service: name: your-app-restricted-service port: number: 80 - path: /* pathType: ImplementationSpecific backend: service: name: your-app-service port: number: 80
排除方案说明
- IAP:确实无法实现路径级细粒度限制,排除
- VPN:配置复杂,需客户端安装软件,对手机用户来说反而不如Token认证便捷,排除
- IP限制:手机IP频繁变动,维护成本极高,仅作为最终备选
内容的提问来源于stack exchange,提问作者Artem Dumanov
相关产品推荐
相关产品推荐

