You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GKE环境下Ambassador HTTP→HTTPS重定向及健康检查异常求助

Fixing HTTP→HTTPS Redirect Breakage with Ambassador on GKE (Health Check Conflict)

I’ve run into this exact issue when setting up Ambassador on GKE—this is a classic conflict between GKE’s auto-managed health checks and Ambassador’s global insecure redirect rules. Here’s the step-by-step fix that worked for me:

Root Cause

When you set insecure.action: Redirect on your Ambassador Host, it redirects all HTTP traffic (including GKE’s health check requests to /ambassador/v0/check_ready) to HTTPS. GKE’s load balancer interprets this 301 redirect as a failed health check, which takes your backend out of service. To make matters worse, GKE automatically recreates default health checks if you delete them, and manual edits get overwritten by the GKE controller.

Solution

We need two key changes:

  1. Exempt Ambassador’s health check path from the HTTP→HTTPS redirect
  2. Force GKE to use a custom health check that works with our modified Ambassador config

1. Update Ambassador Host to Skip Redirect for Health Checks

Modify your existing Host resource to add a mapping that routes (instead of redirects) traffic to the health check endpoint:

apiVersion: getambassador.io/v3alpha1
kind: Host
metadata:
  name: your-host-name
spec:
  hostname: your-domain.tld
  insecure:
    action: Redirect
    redirect_port: 443
  # Add this mapping to exempt health checks from redirect
  mappings:
  - name: ambassador-health-check-route
    prefix: /ambassador/v0/check_ready
    service: ambassador  # Points to your Ambassador service
    insecure:
      action: Route  # Critical: this skips the redirect for this path

2. Configure GKE to Use a Custom Health Check via BackendConfig

GKE uses annotations on your Service to attach custom backend configurations, which prevents it from overwriting your health check settings.

First, create a BackendConfig resource:

apiVersion: cloud.google.com/v1
kind: BackendConfig
metadata:
  name: ambassador-backend-config
spec:
  healthCheck:
    type: HTTP
    requestPath: /ambassador/v0/check_ready
    port: 8080  # Match Ambassador's HTTP target port
    checkIntervalSec: 5
    timeoutSec: 5
    healthyThreshold: 2
    unhealthyThreshold: 3

Then update your Ambassador Service to reference this BackendConfig:

apiVersion: v1
kind: Service
metadata:
  name: ambassador
  annotations:
    # Attach the custom backend config
    cloud.google.com/backend-config: '{"default": "ambassador-backend-config"}'
spec:
  type: LoadBalancer
  ports:
  - name: http
    port: 80
    targetPort: 8080
  - name: https
    port: 443
    targetPort: 8443
  selector:
    service: ambassador

Verification Steps

  • Check Ambassador’s pod logs: You should see 200 OK responses for /ambassador/v0/check_ready instead of 301s.
  • In the GCP Console, navigate to your Load Balancer → Backend Services: Confirm the health check is using the correct path (/ambassador/v0/check_ready) and port (8080).
  • Test the HTTP→HTTPS redirect: Visit your domain over HTTP—you should be redirected to HTTPS immediately, and the service should stay healthy long-term.

内容的提问来源于stack exchange,提问作者Admir Sabanovic

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 08:12:53