如何使用PowerShell创建包含多Backend Pool的Azure Application Gateway
PowerShell 配置多组件 Azure Application Gateway 操作步骤
你已经掌握单组件应用网关的创建逻辑,配置多组件仅需分别定义多组同类型资源,最后在创建网关时传入资源数组即可,具体操作如下:
1. 定义多个后端地址池
按业务需求分别创建后端池,示例如下:
# 后端池1:对应Web业务1的后端服务器 $backendPool1 = New-AzApplicationGatewayBackendAddressPool ` -Name "web1-backend-pool" ` -BackendIPAddresses "10.0.0.10", "10.0.0.11" # 后端池2:对应Web业务2的后端服务器 $backendPool2 = New-AzApplicationGatewayBackendAddressPool ` -Name "web2-backend-pool" ` -BackendIPAddresses "10.0.0.20", "10.0.0.21"
你可以根据实际需要创建更多后端池实例,做好命名区分即可。
2. 定义多组HTTP设置
根据不同后端业务的访问协议、端口、会话粘性等配置,分别定义HTTP设置:
# HTTP设置1:对应Web业务1,HTTP 80端口,开启会话粘性 $httpSettings1 = New-AzApplicationGatewayBackendHttpSetting ` -Name "web1-http-setting" ` -Port 80 ` -Protocol Http ` -CookieBasedAffinity Enabled ` -RequestTimeout 30 # HTTP设置2:对应Web业务2,HTTPS 443端口,禁用会话粘性 $httpSettings2 = New-AzApplicationGatewayBackendHttpSetting ` -Name "web2-https-setting" ` -Port 443 ` -Protocol Https ` -CookieBasedAffinity Disabled ` -RequestTimeout 30 ` -PickHostNameFromBackendAddress
3. 定义多个监听器
根据不同的监听端口、域名、SSL证书配置,分别创建监听器:
# 监听器1:监听80端口,匹配所有域名 $listener1 = New-AzApplicationGatewayHttpListener ` -Name "http-80-listener" ` -Protocol Http ` -FrontendIPConfiguration $fipConfig ` -FrontendPort $frontendPort80 # 监听器2:监听443端口,对应域名web1.example.com,使用指定SSL证书 $listener2 = New-AzApplicationGatewayHttpListener ` -Name "https-web1-listener" ` -Protocol Https ` -FrontendIPConfiguration $fipConfig ` -FrontendPort $frontendPort443 ` -HostName "web1.example.com" ` -SslCertificate $sslCert1 # 监听器3:监听443端口,对应域名web2.example.com,使用指定SSL证书 $listener3 = New-AzApplicationGatewayHttpListener ` -Name "https-web2-listener" ` -Protocol Https ` -FrontendIPConfiguration $fipConfig ` -FrontendPort $frontendPort443 ` -HostName "web2.example.com" ` -SslCertificate $sslCert2
注:示例中的$fipConfig、$frontendPort80、$sslCert1等变量为单实例配置时已经定义好的前端IP、前端端口、SSL证书变量,无需额外修改。
4. 定义多个路由规则
将监听器、后端池、HTTP设置一一绑定,创建对应路由规则:
# 规则1:绑定80端口监听器,转发到web1后端池,使用http设置1,优先级100 $rule1 = New-AzApplicationGatewayRequestRoutingRule ` -Name "http-web1-rule" ` -RuleType Basic ` -Priority 100 ` -HttpListener $listener1 ` -BackendAddressPool $backendPool1 ` -BackendHttpSettings $httpSettings1 # 规则2:绑定web1的443监听器,转发到web1后端池,使用http设置2,优先级10 $rule2 = New-AzApplicationGatewayRequestRoutingRule ` -Name "https-web1-rule" ` -RuleType Basic ` -Priority 10 ` -HttpListener $listener2 ` -BackendAddressPool $backendPool1 ` -BackendHttpSettings $httpSettings2 # 规则3:绑定web2的443监听器,转发到web2后端池,使用http设置2,优先级20 $rule3 = New-AzApplicationGatewayRequestRoutingRule ` -Name "https-web2-rule" ` -RuleType Basic ` -Priority 20 ` -HttpListener $listener3 ` -BackendAddressPool $backendPool2 ` -BackendHttpSettings $httpSettings2
注:规则优先级数值越小,优先级越高,需按业务需要设置,避免高优先级规则拦截低优先级规则的流量。
5. 创建应用网关
调用New-AzApplicationGateway命令时,将所有多实例资源以数组形式传入对应参数即可,其余配置(SKU、子网、公网IP等)和单实例配置逻辑一致:
New-AzApplicationGateway ` -Name "my-app-gateway" ` -ResourceGroupName "my-resource-group" ` -Location "chinanorth3" ` -Sku $sku ` -GatewayIPConfiguration $gipConfig ` -FrontendIPConfiguration $fipConfig ` -FrontendPort @($frontendPort80, $frontendPort443) ` -BackendAddressPool @($backendPool1, $backendPool2) ` -BackendHttpSettingsCollection @($httpSettings1, $httpSettings2) ` -HttpListeners @($listener1, $listener2, $listener3) ` -RequestRoutingRules @($rule1, $rule2, $rule3) ` -SslCertificate @($sslCert1, $sslCert2)
内容的提问来源于stack exchange,提问作者Sunil Katke
相关产品推荐
相关产品推荐

