请求协助适配配置,在GCP GKE部署带NGINX Ingress的外部HTTP云LB
在GCP GKE中部署关联NEG的NGINX Ingress + 外部HTTP负载均衡器
以下是适配Hodo.dev方案的完整可执行脚本,已针对NGINX Ingress进行更新,解决原脚本过时问题:
# 定义环境变量 PROJECT_ID=$(gcloud config list project --format='value(core.project)') ; echo $PROJECT_ID ZONE=europe-west2-b ; echo $ZONE CLUSTER_NAME=negs-lb ; echo $CLUSTER_NAME # 创建VPC-native模式的GKE集群(必须开启该模式以支持NEG) gcloud container clusters create $CLUSTER_NAME --zone $ZONE --machine-type "e2-medium" --enable-ip-alias --num-nodes=2 # 获取集群认证凭据,确保kubectl能正常访问集群 gcloud container clusters get-credentials $CLUSTER_NAME --zone $ZONE # 部署官方稳定版NGINX Ingress Controller kubectl apply -f https://raw.githubusercontent.com/kubernetes/ingress-nginx/controller-v1.8.2/deploy/static/provider/cloud/deploy.yaml # 创建关联NEG的NGINX Ingress Service(替换默认Service,添加NEG注解) cat << EOF > ingress-neg-service.yaml apiVersion: v1 kind: Service metadata: name: ingress-nginx-controller namespace: ingress-nginx annotations: cloud.google.com/neg: '{"exposed_ports": {"80":{"name": "ingress-nginx-80-neg"}}}' spec: type: ClusterIP ports: - port: 80 targetPort: http name: http selector: app.kubernetes.io/name: ingress-nginx app.kubernetes.io/instance: ingress-nginx app.kubernetes.io/component: controller EOF kubectl apply -f ingress-neg-service.yaml # 部署示例NGINX应用 cat << EOF > app-deployment.yaml apiVersion: apps/v1 kind: Deployment metadata: name: nginx-app spec: replicas: 3 selector: matchLabels: app: nginx-app template: metadata: labels: app: nginx-app spec: containers: - name: nginx image: nginx:latest ports: - containerPort: 80 EOF kubectl apply -f app-deployment.yaml # 创建示例应用的ClusterIP Service cat << EOF > app-service.yaml apiVersion: v1 kind: Service metadata: name: nginx-app-service spec: type: ClusterIP ports: - port: 80 targetPort: 80 selector: app: nginx-app EOF kubectl apply -f app-service.yaml # 创建Ingress资源,配置路由规则将流量转发到示例应用 cat << EOF > app-ingress.yaml apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: nginx-app-ingress annotations: nginx.ingress.kubernetes.io/rewrite-target: / spec: ingressClassName: nginx rules: - http: paths: - path: / pathType: Prefix backend: service: name: nginx-app-service port: number: 80 EOF kubectl apply -f app-ingress.yaml # 验证NEG是否成功创建 gcloud compute network-endpoint-groups list # 获取集群节点的网络标签,用于配置防火墙规则 NETWORK_TAGS=$(gcloud compute instances describe \ $(kubectl get nodes -o jsonpath='{.items[0].metadata.name}') \ --zone=$ZONE --format="value(tags.items[0])") echo $NETWORK_TAGS # 创建允许GCP负载均衡器流量进入集群的防火墙规则 gcloud compute firewall-rules create $CLUSTER_NAME-lb-fw \ --allow tcp:80 \ --source-ranges 130.211.0.0/22,35.191.0.0/16 \ --target-tags $NETWORK_TAGS # 创建针对NGINX Ingress的健康检查(使用Ingress Controller默认健康端点) gcloud compute health-checks create http ingress-nginx-80-health-check \ --request-path /healthz \ --port 80 \ --check-interval 60 \ --unhealthy-threshold 3 \ --healthy-threshold 1 \ --timeout 5 # 创建全局后端服务,关联健康检查 gcloud compute backend-services create $CLUSTER_NAME-lb-backend \ --health-checks ingress-nginx-80-health-check \ --port-name http \ --global \ --enable-cdn \ --connection-draining-timeout 300 # 将NGINX Ingress的NEG添加到后端服务 gcloud compute backend-services add-backend $CLUSTER_NAME-lb-backend \ --network-endpoint-group=ingress-nginx-80-neg \ --network-endpoint-group-zone=$ZONE \ --balancing-mode=RATE \ --capacity-scaler=1.0 \ --max-rate-per-endpoint=1.0 \ --global # 创建URL映射,指向后端服务 gcloud compute url-maps create $CLUSTER_NAME-url-map --default-service $CLUSTER_NAME-lb-backend # 创建HTTP目标代理 gcloud compute target-http-proxies create $CLUSTER_NAME-http-proxy --url-map $CLUSTER_NAME-url-map # 创建全局转发规则,分配公网IP gcloud compute forwarding-rules create $CLUSTER_NAME-forwarding-rule \ --global \ --ports 80 \ --target-http-proxy $CLUSTER_NAME-http-proxy # 获取负载均衡器公网IP并测试(等待120秒让负载均衡器完成初始化) IP_ADDRESS=$(gcloud compute forwarding-rules describe $CLUSTER_NAME-forwarding-rule --global --format="value(IPAddress)") echo "负载均衡器公网IP: $IP_ADDRESS" sleep 120 curl -s -I http://$IP_ADDRESS/
关键适配说明
- 核心服务替换:将原脚本中直接绑定应用的Service,替换为NGINX Ingress Controller的Service,并添加
cloud.google.com/neg注解生成对应NEG,让外部负载均衡器直接对接Ingress Pod端点。 - 健康检查修正:将健康检查路径改为
/healthz,匹配NGINX Ingress Controller默认的健康检查端点,避免健康检查失败导致负载均衡器无法正常转发。 - Ingress规则配置:新增Ingress资源,实现外部流量到后端应用的路由转发,发挥NGINX Ingress的路由管理能力。
- 标签选择器适配:调整Service的标签选择器,匹配官方NGINX Ingress Controller的Pod标签,确保流量能正确转发到Controller。
内容的提问来源于stack exchange,提问作者rrob
相关产品推荐
相关产品推荐

