Tekton与KubeSphere Console Nginx Ingress路由冲突问题咨询
问题背景
创建了如下两个Ingress路由资源:
- kubesphere-console
- tekton-pipelines
对应资源清单内容
ingress-tekton-dashboard.yaml 内容
--- apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: tekton-dashboard annotations: ingress.kubernetes.io/ssl-redirect: "false" nginx.ingress.kubernetes.io/ssl-redirect: "false" ingressClassName: nginx spec: ingressClassName: nginx rules: - http: paths: - path: / pathType: Prefix backend: service: name: tekton-dashboard port: number: 9097 #host: * ...
../kubesphere/ingress-route-kubesphere.yaml 内容
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: kubesphere-console annotations: kubesphere.io/creator: admin spec: ingressClassName: nginx rules: - host: crashandburn.australiaeast.cloudapp.azure.com http: paths: - path: / pathType: ImplementationSpecific backend: service: name: ks-console port: number: 80 ---
集群资源查询结果
全量Ingress资源查询输出
k get ing -nkubesphere-system NAME CLASS HOSTS ADDRESS PORTS AGE kubesphere-console nginx * 20.92.133.79 80 28h ameya@Azure:~/tekton$ k get ing -ntekton-pipelines NAME CLASS HOSTS ADDRESS PORTS AGE tekton-dashboard <none> * 80 2m32s
tekton-pipelines命名空间下Service资源查询输出
k get svc -n tekton-pipelines NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE tekton-dashboard ClusterIP 10.0.202.127 <none> 9097/TCP 2d3h tekton-pipelines-controller ClusterIP 10.0.53.46 <none> 9090/TCP,8008/TCP,8080/TCP 2d6h tekton-pipelines-webhook ClusterIP 10.0.222.127 <none> 9090/TCP,8008/TCP,443/TCP,8080/TCP 2d6h
资源应用报错信息
k apply -f ingress-tekton-dashboard.yaml -ntekton-pipelines Error from server (BadRequest): error when applying patch: {"metadata":{"annotations":{"kubectl.kubernetes.io/last-applied-configuration":"{\"apiVersion\":\"networking.k8s.io/v1\",\"kind\":\"Ingress\",\"metadata\":{\"annotations\":{\"ingress.kubernetes.io/ssl-redirect\":\"false\",\"ingressClassName\":\"nginx\",\"nginx.ingress.kubernetes.io/ssl-redirect\":\"false\"},\"name\":\"tekton-dashboard\",\"namespace\":\"tekton-pipelines\"},\"spec\":{\"ingressClassName\":\"nginx\",\"rules\":[{\"http\":{\"paths\":[{\"backend\":{\"service\":{\"name\":\"tekton-dashboard\",\"port\":{\"number\":9097}}},\"path\":\"/\",\"pathType\":\"Prefix\"}]}}]}}\n"}},"spec":{"ingressClassName":"nginx"}} to: Resource: "networking.k8s.io/v1, Resource=ingresses", GroupVersionKind: "networking.k8s.io/v1, Kind=Ingress" Name: "tekton-dashboard", Namespace: "tekton-pipelines" for: "ingress-tekton-dashboard.yaml": admission webhook "validate.nginx.ingress.kubernetes.io" denied the request: host "_" and path "/" is already defined in ingress kubesphere-system/kubesphere-console
两个Ingress对应的后端Service分别使用9097和80不同端口,触发Nginx Ingress准入校验冲突报错,需要排查原因与解决方案。
报错原因
Nginx Ingress是七层路由,对外统一监听80/443端口,后端Service端口仅用于集群内部流量转发,不会作为路由冲突的判断依据,准入webhook判断路由冲突的唯一标准是「域名+路径」组合是否重复:
- 从集群Ingress查询结果可以看到,现有的
kubesphere-consoleIngress实际HOST为*(通配所有未匹配到其他server的请求,对应Nginx配置里的默认server块_),已经占用了根路径/的路由规则 - 待创建的
tekton-dashboardIngress没有配置指定host,默认同样匹配所有域名,且路径也是根路径/,和已有Ingress的路由规则完全重叠,因此被准入webhook拦截 - 清单文件里为
kubesphere-console配置的crashandburn.australiaeast.cloudapp.azure.com域名没有生效,查询结果HOSTS列显示*即可确认,属于之前apply资源时配置未成功更新,导致该Ingress一直占用通配根路径。
解决方案
选择任意一种方案即可解决冲突:
- 方案1:给两个Ingress分别配置独立的域名,不要留空使用通配。比如给tekton-dashboard配置单独子域名
tekton.crashandburn.australiaeast.cloudapp.azure.com,保证每个Ingress的host+path组合唯一 - 方案2:如果不想使用多域名,可以给tekton-dashboard配置独立子路径,比如将path改成
/tekton,注意这种方式需要给tekton-dashboard配置对应rewrite规则,否则静态资源访问会出现404 - 方案3:先修正
kubesphere-console的Ingress配置,重新apply让指定域名的配置生效,确保它不再占用通配域名的根路径,之后再创建tekton-dashboard的Ingress就不会触发冲突 - 额外优化:metadata.annotations里的
ingressClassName: nginx是无效配置,ingressClassName属于spec层级的标准字段,建议删除注解里的冗余无效配置。
内容的提问来源于stack exchange,提问作者hungrylearnerbenicewithme
相关产品推荐
相关产品推荐

