You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS NLB配置Nginx Ingress Controller触发Too many redirects错误如何解决

问题根因

你遇到的重定向死循环是典型的负载均衡TLS终结后请求协议识别异常导致的:

  • NLB当前将443端口的HTTPS请求卸载证书后,以HTTP协议转发到Ingress Nginx的http端口
  • 开启SSL强制跳转后,Ingress Nginx识别到请求协议为HTTP,就返回301跳转到HTTPS,用户再次请求HTTPS后又重复上述流程,形成死循环
  • ELB运行正常是因为你把80端口直接转发到了Ingress Nginx内置的tohttps端口,该端口默认返回HTTP跳HTTPS,不会触发后续的规则判断
修复步骤

1. 调整NLB对应的Service端口配置,对齐正常的ELB配置

修改Service的ports段,把80端口的targetPort改为tohttps:

spec:
  type: LoadBalancer
  externalTrafficPolicy: Local
  ports:
    - name: http
      port: 80
      protocol: TCP
      targetPort: tohttps # 改为tohttps,直接走内置跳转逻辑
      appProtocol: http
    - name: https
      port: 443
      protocol: TCP
      targetPort: http
      appProtocol: https

2. 调整Ingress注解,正确识别转发协议

Ingress资源保留以下注解即可,保证Ingress Nginx能正确读取NLB传递的原始请求协议:

nginx.ingress.kubernetes.io/ssl-redirect: "true"
nginx.ingress.kubernetes.io/use-forwarded-headers: "true"

不需要全局强制跳转可删除nginx.ingress.kubernetes.io/force-ssl-redirect配置。

3. 确认Ingress Nginx全局配置适配Proxy Protocol

因为你在NLB注解中开启了Proxy Protocol,需要在Ingress Nginx的ConfigMap中添加以下配置,避免IP识别异常:

data:
  use-proxy-protocol: "true"
  enable-real-ip: "true"

4. 验证配置

调整后重启Ingress Nginx Pod,清空浏览器缓存测试:

  • 访问HTTP 80端口会自动301跳转到HTTPS 443端口
  • 访问HTTPS 443端口可以正常加载业务,不会出现重定向死循环

内容的提问来源于stack exchange,提问作者DisplayName

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.02 11:06:03