You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Tekton与KubeSphere Console Nginx Ingress路由冲突问题咨询

问题背景

创建了如下两个Ingress路由资源:

  • kubesphere-console
  • tekton-pipelines

对应资源清单内容

ingress-tekton-dashboard.yaml 内容

---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: tekton-dashboard
  annotations:
    ingress.kubernetes.io/ssl-redirect: "false"
    nginx.ingress.kubernetes.io/ssl-redirect: "false"
    ingressClassName: nginx
spec:
  ingressClassName: nginx
  rules:
    - http:
        paths:
        - path: /
          pathType: Prefix
          backend:
            service:
             name: tekton-dashboard
             port:
               number: 9097
      #host: *
...

../kubesphere/ingress-route-kubesphere.yaml 内容

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: kubesphere-console
  annotations:
    kubesphere.io/creator: admin
spec:
  ingressClassName: nginx
  rules:
  - host: crashandburn.australiaeast.cloudapp.azure.com
    http:
      paths:
      - path: /
        pathType: ImplementationSpecific
        backend:
          service:
            name: ks-console
            port:
              number: 80
---

集群资源查询结果

全量Ingress资源查询输出

k get ing -nkubesphere-system
NAME                 CLASS   HOSTS   ADDRESS        PORTS   AGE
kubesphere-console   nginx   *       20.92.133.79   80      28h
ameya@Azure:~/tekton$ k get ing -ntekton-pipelines
NAME               CLASS    HOSTS   ADDRESS   PORTS   AGE
tekton-dashboard   <none>   *                 80      2m32s

tekton-pipelines命名空间下Service资源查询输出

k get svc -n tekton-pipelines
NAME                          TYPE        CLUSTER-IP     EXTERNAL-IP   PORT(S)                              AGE
tekton-dashboard              ClusterIP   10.0.202.127   <none>        9097/TCP                             2d3h
tekton-pipelines-controller   ClusterIP   10.0.53.46     <none>        9090/TCP,8008/TCP,8080/TCP           2d6h
tekton-pipelines-webhook      ClusterIP   10.0.222.127   <none>        9090/TCP,8008/TCP,443/TCP,8080/TCP   2d6h

资源应用报错信息

k apply -f ingress-tekton-dashboard.yaml -ntekton-pipelines
Error from server (BadRequest): error when applying patch:
{"metadata":{"annotations":{"kubectl.kubernetes.io/last-applied-configuration":"{\"apiVersion\":\"networking.k8s.io/v1\",\"kind\":\"Ingress\",\"metadata\":{\"annotations\":{\"ingress.kubernetes.io/ssl-redirect\":\"false\",\"ingressClassName\":\"nginx\",\"nginx.ingress.kubernetes.io/ssl-redirect\":\"false\"},\"name\":\"tekton-dashboard\",\"namespace\":\"tekton-pipelines\"},\"spec\":{\"ingressClassName\":\"nginx\",\"rules\":[{\"http\":{\"paths\":[{\"backend\":{\"service\":{\"name\":\"tekton-dashboard\",\"port\":{\"number\":9097}}},\"path\":\"/\",\"pathType\":\"Prefix\"}]}}]}}\n"}},"spec":{"ingressClassName":"nginx"}}
to:
Resource: "networking.k8s.io/v1, Resource=ingresses", GroupVersionKind: "networking.k8s.io/v1, Kind=Ingress"
Name: "tekton-dashboard", Namespace: "tekton-pipelines"
for: "ingress-tekton-dashboard.yaml": admission webhook "validate.nginx.ingress.kubernetes.io" denied the request: host "_" and path "/" is already defined in ingress kubesphere-system/kubesphere-console

两个Ingress对应的后端Service分别使用9097和80不同端口,触发Nginx Ingress准入校验冲突报错,需要排查原因与解决方案。


报错原因

Nginx Ingress是七层路由,对外统一监听80/443端口,后端Service端口仅用于集群内部流量转发,不会作为路由冲突的判断依据,准入webhook判断路由冲突的唯一标准是「域名+路径」组合是否重复:

  1. 从集群Ingress查询结果可以看到,现有的kubesphere-console Ingress实际HOST为*(通配所有未匹配到其他server的请求,对应Nginx配置里的默认server块_),已经占用了根路径/的路由规则
  2. 待创建的tekton-dashboard Ingress没有配置指定host,默认同样匹配所有域名,且路径也是根路径/,和已有Ingress的路由规则完全重叠,因此被准入webhook拦截
  3. 清单文件里为kubesphere-console配置的crashandburn.australiaeast.cloudapp.azure.com域名没有生效,查询结果HOSTS列显示*即可确认,属于之前apply资源时配置未成功更新,导致该Ingress一直占用通配根路径。
解决方案

选择任意一种方案即可解决冲突:

  • 方案1:给两个Ingress分别配置独立的域名,不要留空使用通配。比如给tekton-dashboard配置单独子域名tekton.crashandburn.australiaeast.cloudapp.azure.com,保证每个Ingress的host+path组合唯一
  • 方案2:如果不想使用多域名,可以给tekton-dashboard配置独立子路径,比如将path改成/tekton,注意这种方式需要给tekton-dashboard配置对应rewrite规则,否则静态资源访问会出现404
  • 方案3:先修正kubesphere-console的Ingress配置,重新apply让指定域名的配置生效,确保它不再占用通配域名的根路径,之后再创建tekton-dashboard的Ingress就不会触发冲突
  • 额外优化:metadata.annotations里的ingressClassName: nginx是无效配置,ingressClassName属于spec层级的标准字段,建议删除注解里的冗余无效配置。

内容的提问来源于stack exchange,提问作者hungrylearnerbenicewithme

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.03 10:21:39