You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Application Gateway的AKS能否同时暴露HTTP和TCP端口?

解决方案

不需要额外部署不绑定Application Gateway的Ingress Controller,通过现有Azure资源组合即可满足需求,具体实现如下:

七层HTTP流量内网暴露

你当前使用的Application Gateway Ingress Controller(AGIC)本身支持内网私有IP暴露能力,仅需修改现有Ingress配置即可:

  1. 先确认你的Application Gateway已配置私有前端IP(可在Azure门户Application Gateway的「前端IP配置」页添加)
  2. 修改Ingress注解中的appgw.ingress.kubernetes.io/use-private-ip值为"true",修改后七层HTTP流量仅能通过Application Gateway的内网IP访问,公网完全无法触达。

修改后的Ingress配置示例:

apiVersion: networking.k8s.io/v1beta1
kind: Ingress
metadata:
  name: service1
  labels:
    app: service1
  annotations:
    appgw.ingress.kubernetes.io/backend-path-prefix: /
    appgw.ingress.kubernetes.io/use-private-ip: "true"
    kubernetes.io/ingress.class: azure/application-gateway
spec:
  tls:
    - hosts:
      secretName: <somesecret>
  rules:
    - host: <somehost>
      http:
        paths:
          - path: /service1/*
            backend:
              serviceName: service1
              servicePort: http

四层TCP流量内网暴露

Application Gateway为七层负载均衡产品,本身不支持TCP/UDP四层转发,这部分可通过内网类型的LoadBalancer Service实现,根据访问范围选对应方案即可:

  • 若仅集群内部应用需要访问TCP端口:直接使用默认的ClusterIP类型Service,无需额外配置,仅集群内可访问,安全性最高。
  • 若Azure VPC内非AKS资源也需要访问TCP端口:创建带内网注解的LoadBalancer类型Service,Azure会自动创建仅分配内网IP的四层负载均衡,公网不可访问。

内网LoadBalancer Service配置示例:

apiVersion: v1
kind: Service
metadata:
  name: service1-tcp
  annotations:
    service.beta.kubernetes.io/azure-load-balancer-internal: "true"
spec:
  type: LoadBalancer
  selector:
    app: service1
  ports:
    - protocol: TCP
      port: <你要暴露的TCP端口>
      targetPort: <Pod内监听的TCP端口>

补充说明

最后可根据需求调整VPC网络安全组规则,仅放行信任的内网网段访问对应端口,进一步提升安全性。

内容的提问来源于stack exchange,提问作者Michael

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.06 19:39:05