You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在AWS EKS环境下为Spring应用暴露WebSocket端点

EKS Nginx Ingress 暴露WebSocket端点实施方案

WebSocket需要特殊的请求头完成握手,且对长连接超时配置有要求,按照以下步骤配置即可实现需求:

1. 调整Ingress资源配置

你只需要在原有Ingress配置中新增4个专属注解,同时确保/api/ws路径能正确路由到你的Spring应用Pod即可,参考配置如下:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: spring-app-ingress
  annotations:
    # 开启WebSocket支持的核心头配置
    nginx.ingress.kubernetes.io/upgrade: "$http_upgrade"
    nginx.ingress.kubernetes.io/connection: "upgrade"
    # 调整长连接超时时间,单位为秒,可根据业务需要调整
    nginx.ingress.kubernetes.io/proxy-read-timeout: "3600"
    nginx.ingress.kubernetes.io/proxy-send-timeout: "3600"
spec:
  tls:
  - hosts:
    - bala.something.com
    secretName: your-tls-secret # 替换为你的域名证书对应的Secret名称
  rules:
  - host: bala.something.com
    http:
      paths:
      - path: /api/ws
        pathType: Prefix
        backend:
          service:
            name: your-spring-app-service # 替换为你的Spring应用对应的Service名称
            port:
              number: 8080 # 替换为你的Spring应用Service暴露的端口
      # 你原来的其他路径配置保留即可
      - path: /
        pathType: Prefix
        backend:
          service:
            name: your-spring-app-service
            port:
              number: 8080

2. AWS ELB侧配置校验

  • 确保ELB的443监听器已经绑定了bala.something.com域名的有效证书,WSS协议基于HTTPS运行,证书不匹配会导致握手失败
  • 将ELB的空闲超时时间调整为和Nginx侧一致的3600秒,避免中间链路主动断开空闲的长连接

3. Spring应用侧校验

  • 确认WebSocket端点确实挂载在/api/ws路径下,如果应用配置了server.servlet.context-path,需要将Ingress的路径调整为{context-path}/api/ws
  • 若应用配置了跨域校验,需要放行bala.something.com域名的请求

4. 连通性验证

配置生效后执行命令测试:websocat wss://bala.something.com/api/ws,无报错且能正常收发消息即配置成功。如果出现握手失败,优先查看Nginx Ingress Pod的日志排查错误原因。

内容的提问来源于stack exchange,提问作者Bala krishna

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 19:15:05