You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EKS集群ALB实现不同端口Flask服务路径路由配置方法

问题原因

ALB与NGINX Ingress的默认转发逻辑存在本质差异:

  • 此前搭配Classic LB使用NGINX Ingress时,你配置了rewrite-target正则重写规则,访问/console/api1时NGINX会自动剥离/console/前缀,将路径为/api1的请求转发给后端Flask服务,正好匹配Flask中定义的路由,因此访问正常。
  • 迁移到ALB后未配置路径重写规则,当Ingress路径设置为/console时,ALB会将完整请求路径/console/api1直接转发给Flask服务,但你的Flask代码仅注册了/、/api1、/api2这类无/console前缀的路由,因此会直接返回404,导致访问失败。

另外你将Service类型修改为NodePort属于多余配置,当使用alb.ingress.kubernetes.io/target-type: ip模式时,Service使用默认的ClusterIP即可,无需通过NodePort转发。

修复配置步骤

1. 修正Service配置

将两个Flask服务对应的Service类型从NodePort改回ClusterIP即可,无需暴露节点端口。以console服务为例,console2服务仅需修改端口与标签匹配规则:

apiVersion: v1
kind: Service
metadata:
  name: console
  namespace: check
spec:
  type: ClusterIP
  selector:
    app.kubernetes.io/name: console
  ports:
  - protocol: TCP
    port: 3000
    targetPort: 3000

2. 配置带路径重写的ALB Ingress规则

ALB的路径重写通过AWS Load Balancer Controller的专属注解实现,无需配置正则捕获组,直接定义路径前缀替换规则即可。以下配置可实现与原NGINX Ingress完全一致的路由效果:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  namespace: check
  name: ingress-check
  annotations:
    kubernetes.io/ingress.class: alb
    alb.ingress.kubernetes.io/load-balancer-name: t3
    alb.ingress.kubernetes.io/scheme: internet-facing
    alb.ingress.kubernetes.io/target-type: ip
    alb.ingress.kubernetes.io/tags: product=check
    alb.ingress.kubernetes.io/group.name: test
    alb.ingress.kubernetes.io/listen-ports: '[{"HTTP": 80}]'
    # /console路径自动补全斜杠重定向
    alb.ingress.kubernetes.io/actions.console-redirect: >
      {"type":"redirect","redirectConfig":{"path":"/console/","statusCode":"HTTP_302"}}
    alb.ingress.kubernetes.io/conditions.console-redirect: >
      [{"field":"path-pattern","pathPatternConfig":{"values":["/console"]}}]
    # 剥离/console前缀后转发到3000端口console服务
    alb.ingress.kubernetes.io/actions.console-rewrite: >
      {"type":"rewrite","rewriteConfig":{"path":"/#{path[2]}"}}
    alb.ingress.kubernetes.io/conditions.console-rewrite: >
      [{"field":"path-pattern","pathPatternConfig":{"values":["/console/*"]}}]
    alb.ingress.kubernetes.io/actions.console-forward: >
      {"type":"forward","forwardConfig":{"targetGroups":[{"serviceName":"console","servicePort":3000}]}}
    # /console2路径自动补全斜杠重定向
    alb.ingress.kubernetes.io/actions.console2-redirect: >
      {"type":"redirect","redirectConfig":{"path":"/console2/","statusCode":"HTTP_302"}}
    alb.ingress.kubernetes.io/conditions.console2-redirect: >
      [{"field":"path-pattern","pathPatternConfig":{"values":["/console2"]}}]
    # 剥离/console2前缀后转发到3001端口console2服务
    alb.ingress.kubernetes.io/actions.console2-rewrite: >
      {"type":"rewrite","rewriteConfig":{"path":"/#{path[2]}"}}
    alb.ingress.kubernetes.io/conditions.console2-rewrite: >
      [{"field":"path-pattern","pathPatternConfig":{"values":["/console2/*"]}}]
    alb.ingress.kubernetes.io/actions.console2-forward: >
      {"type":"forward","forwardConfig":{"targetGroups":[{"serviceName":"console2","servicePort":3001}]}}
spec:
  rules:
    - http:
        paths:
          - path: /console
            pathType: ImplementationSpecific
            backend:
              service:
                name: console-redirect
                port:
                  name: use-annotation
          - path: /console/*
            pathType: ImplementationSpecific
            backend:
              service:
                name: console-rewrite
                port:
                  name: use-annotation
          - path: /console/*
            pathType: ImplementationSpecific
            backend:
              service:
                name: console-forward
                port:
                  name: use-annotation
          - path: /console2
            pathType: ImplementationSpecific
            backend:
              service:
                name: console2-redirect
                port:
                  name: use-annotation
          - path: /console2/*
            pathType: ImplementationSpecific
            backend:
              service:
                name: console2-rewrite
                port:
                  name: use-annotation
          - path: /console2/*
            pathType: ImplementationSpecific
            backend:
              service:
                name: console2-forward
                port:
                  name: use-annotation

配置中/#{path[2]}的作用是提取按斜杠分割的路径中第3段及之后的内容:例如请求路径/console/api1分割后为["", "console", "api1"],提取索引为2的片段拼接后得到/api1,正好匹配Flask中定义的路由。

3. 生效验证

应用配置后等待1-2分钟待ALB规则同步完成,即可验证路由效果:

  • 访问http://<ALB分配的DNS地址>/console/api1,将返回3000端口console服务的接口响应
  • 访问http://<ALB分配的DNS地址>/console2/api1,将返回3001端口console2服务的接口响应
    与原Classic LB+NGINX Ingress的路由逻辑完全一致。
注意事项
  • ALB Ingress与NGINX Ingress的注解完全不通用,原NGINX配置中的超时、CORS、请求体大小限制等参数,需要替换为ALB对应的注解才能生效,直接照搬NGINX注解不会被ALB识别。
  • 路径匹配类型必须使用ImplementationSpecific,不要使用Prefix类型,否则重写规则无法正常生效。
  • 若需要内网访问ALB,将alb.ingress.kubernetes.io/scheme参数值改为internal即可。

可选快速方案:如果不想配置ALB重写规则,也可以直接修改Flask代码,为对应服务的所有路由添加统一前缀(例如console服务的路由全部添加/console前缀,console2服务的路由全部添加/console2前缀),这种方式无需配置重写规则,但后续路径调整需要修改业务代码,灵活度较低,仅适合临时测试场景。

内容的提问来源于stack exchange,提问作者Nandha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.27 05:18:20