EKS集群ALB实现不同端口Flask服务路径路由配置方法
问题原因
ALB与NGINX Ingress的默认转发逻辑存在本质差异:
- 此前搭配Classic LB使用NGINX Ingress时,你配置了
rewrite-target正则重写规则,访问/console/api1时NGINX会自动剥离/console/前缀,将路径为/api1的请求转发给后端Flask服务,正好匹配Flask中定义的路由,因此访问正常。 - 迁移到ALB后未配置路径重写规则,当Ingress路径设置为
/console时,ALB会将完整请求路径/console/api1直接转发给Flask服务,但你的Flask代码仅注册了/、/api1、/api2这类无/console前缀的路由,因此会直接返回404,导致访问失败。
另外你将Service类型修改为NodePort属于多余配置,当使用alb.ingress.kubernetes.io/target-type: ip模式时,Service使用默认的ClusterIP即可,无需通过NodePort转发。
修复配置步骤
1. 修正Service配置
将两个Flask服务对应的Service类型从NodePort改回ClusterIP即可,无需暴露节点端口。以console服务为例,console2服务仅需修改端口与标签匹配规则:
apiVersion: v1 kind: Service metadata: name: console namespace: check spec: type: ClusterIP selector: app.kubernetes.io/name: console ports: - protocol: TCP port: 3000 targetPort: 3000
2. 配置带路径重写的ALB Ingress规则
ALB的路径重写通过AWS Load Balancer Controller的专属注解实现,无需配置正则捕获组,直接定义路径前缀替换规则即可。以下配置可实现与原NGINX Ingress完全一致的路由效果:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: namespace: check name: ingress-check annotations: kubernetes.io/ingress.class: alb alb.ingress.kubernetes.io/load-balancer-name: t3 alb.ingress.kubernetes.io/scheme: internet-facing alb.ingress.kubernetes.io/target-type: ip alb.ingress.kubernetes.io/tags: product=check alb.ingress.kubernetes.io/group.name: test alb.ingress.kubernetes.io/listen-ports: '[{"HTTP": 80}]' # /console路径自动补全斜杠重定向 alb.ingress.kubernetes.io/actions.console-redirect: > {"type":"redirect","redirectConfig":{"path":"/console/","statusCode":"HTTP_302"}} alb.ingress.kubernetes.io/conditions.console-redirect: > [{"field":"path-pattern","pathPatternConfig":{"values":["/console"]}}] # 剥离/console前缀后转发到3000端口console服务 alb.ingress.kubernetes.io/actions.console-rewrite: > {"type":"rewrite","rewriteConfig":{"path":"/#{path[2]}"}} alb.ingress.kubernetes.io/conditions.console-rewrite: > [{"field":"path-pattern","pathPatternConfig":{"values":["/console/*"]}}] alb.ingress.kubernetes.io/actions.console-forward: > {"type":"forward","forwardConfig":{"targetGroups":[{"serviceName":"console","servicePort":3000}]}} # /console2路径自动补全斜杠重定向 alb.ingress.kubernetes.io/actions.console2-redirect: > {"type":"redirect","redirectConfig":{"path":"/console2/","statusCode":"HTTP_302"}} alb.ingress.kubernetes.io/conditions.console2-redirect: > [{"field":"path-pattern","pathPatternConfig":{"values":["/console2"]}}] # 剥离/console2前缀后转发到3001端口console2服务 alb.ingress.kubernetes.io/actions.console2-rewrite: > {"type":"rewrite","rewriteConfig":{"path":"/#{path[2]}"}} alb.ingress.kubernetes.io/conditions.console2-rewrite: > [{"field":"path-pattern","pathPatternConfig":{"values":["/console2/*"]}}] alb.ingress.kubernetes.io/actions.console2-forward: > {"type":"forward","forwardConfig":{"targetGroups":[{"serviceName":"console2","servicePort":3001}]}} spec: rules: - http: paths: - path: /console pathType: ImplementationSpecific backend: service: name: console-redirect port: name: use-annotation - path: /console/* pathType: ImplementationSpecific backend: service: name: console-rewrite port: name: use-annotation - path: /console/* pathType: ImplementationSpecific backend: service: name: console-forward port: name: use-annotation - path: /console2 pathType: ImplementationSpecific backend: service: name: console2-redirect port: name: use-annotation - path: /console2/* pathType: ImplementationSpecific backend: service: name: console2-rewrite port: name: use-annotation - path: /console2/* pathType: ImplementationSpecific backend: service: name: console2-forward port: name: use-annotation
配置中/#{path[2]}的作用是提取按斜杠分割的路径中第3段及之后的内容:例如请求路径/console/api1分割后为["", "console", "api1"],提取索引为2的片段拼接后得到/api1,正好匹配Flask中定义的路由。
3. 生效验证
应用配置后等待1-2分钟待ALB规则同步完成,即可验证路由效果:
- 访问
http://<ALB分配的DNS地址>/console/api1,将返回3000端口console服务的接口响应 - 访问
http://<ALB分配的DNS地址>/console2/api1,将返回3001端口console2服务的接口响应
与原Classic LB+NGINX Ingress的路由逻辑完全一致。
注意事项
- ALB Ingress与NGINX Ingress的注解完全不通用,原NGINX配置中的超时、CORS、请求体大小限制等参数,需要替换为ALB对应的注解才能生效,直接照搬NGINX注解不会被ALB识别。
- 路径匹配类型必须使用
ImplementationSpecific,不要使用Prefix类型,否则重写规则无法正常生效。 - 若需要内网访问ALB,将
alb.ingress.kubernetes.io/scheme参数值改为internal即可。
可选快速方案:如果不想配置ALB重写规则,也可以直接修改Flask代码,为对应服务的所有路由添加统一前缀(例如console服务的路由全部添加
/console前缀,console2服务的路由全部添加/console2前缀),这种方式无需配置重写规则,但后续路径调整需要修改业务代码,灵活度较低,仅适合临时测试场景。
内容的提问来源于stack exchange,提问作者Nandha
相关产品推荐
相关产品推荐

