GKE环境下Ambassador HTTP→HTTPS重定向及健康检查异常求助
I’ve run into this exact issue when setting up Ambassador on GKE—this is a classic conflict between GKE’s auto-managed health checks and Ambassador’s global insecure redirect rules. Here’s the step-by-step fix that worked for me:
Root Cause
When you set insecure.action: Redirect on your Ambassador Host, it redirects all HTTP traffic (including GKE’s health check requests to /ambassador/v0/check_ready) to HTTPS. GKE’s load balancer interprets this 301 redirect as a failed health check, which takes your backend out of service. To make matters worse, GKE automatically recreates default health checks if you delete them, and manual edits get overwritten by the GKE controller.
Solution
We need two key changes:
- Exempt Ambassador’s health check path from the HTTP→HTTPS redirect
- Force GKE to use a custom health check that works with our modified Ambassador config
1. Update Ambassador Host to Skip Redirect for Health Checks
Modify your existing Host resource to add a mapping that routes (instead of redirects) traffic to the health check endpoint:
apiVersion: getambassador.io/v3alpha1 kind: Host metadata: name: your-host-name spec: hostname: your-domain.tld insecure: action: Redirect redirect_port: 443 # Add this mapping to exempt health checks from redirect mappings: - name: ambassador-health-check-route prefix: /ambassador/v0/check_ready service: ambassador # Points to your Ambassador service insecure: action: Route # Critical: this skips the redirect for this path
2. Configure GKE to Use a Custom Health Check via BackendConfig
GKE uses annotations on your Service to attach custom backend configurations, which prevents it from overwriting your health check settings.
First, create a BackendConfig resource:
apiVersion: cloud.google.com/v1 kind: BackendConfig metadata: name: ambassador-backend-config spec: healthCheck: type: HTTP requestPath: /ambassador/v0/check_ready port: 8080 # Match Ambassador's HTTP target port checkIntervalSec: 5 timeoutSec: 5 healthyThreshold: 2 unhealthyThreshold: 3
Then update your Ambassador Service to reference this BackendConfig:
apiVersion: v1 kind: Service metadata: name: ambassador annotations: # Attach the custom backend config cloud.google.com/backend-config: '{"default": "ambassador-backend-config"}' spec: type: LoadBalancer ports: - name: http port: 80 targetPort: 8080 - name: https port: 443 targetPort: 8443 selector: service: ambassador
Verification Steps
- Check Ambassador’s pod logs: You should see
200 OKresponses for/ambassador/v0/check_readyinstead of 301s. - In the GCP Console, navigate to your Load Balancer → Backend Services: Confirm the health check is using the correct path (
/ambassador/v0/check_ready) and port (8080). - Test the HTTP→HTTPS redirect: Visit your domain over HTTP—you should be redirected to HTTPS immediately, and the service should stay healthy long-term.
内容的提问来源于stack exchange,提问作者Admir Sabanovic

