Google Kubernetes Engine中HTTP至HTTPS流量重定向问题咨询
Hey Daniel, let's fix that HTTP-to-HTTPS redirect for your GKE Ingress— I’ve dealt with this exact headache before, so here’s what worked for me:
First, let’s confirm you’re using GKE’s native Ingress controller (not a third-party one like NGINX) since the required annotations are totally different for each. For GKE’s managed Ingress, here’s the correct setup:
1. Update Your Ingress YAML with the Right Annotations
The key annotation to force redirects is kubernetes.io/ingress.force-ssl-redirect: "true", but you also need to make sure your SSL certificate is properly linked. Here’s a complete example:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: example-ingress annotations: # Force HTTP → HTTPS redirect kubernetes.io/ingress.force-ssl-redirect: "true" # Link your GCP-managed SSL certificate (replace with your cert name) networking.gke.io/managed-certificates: "example-com-cert" spec: rules: - host: example.com http: paths: - path: /* pathType: ImplementationSpecific backend: service: name: your-app-service port: number: 80
2. Critical Prerequisites to Check
- Valid SSL Certificate: Your Ingress must have a valid SSL certificate attached (either via GCP Managed Certificates or a pre-shared cert using
ingress.gcp.kubernetes.io/pre-shared-cert). Without this, the redirect won’t trigger. - Remove Conflicting Annotations: If you added
kubernetes.io/ingress.allow-http: "false"earlier, delete it— this setting blocks HTTP traffic entirely instead of redirecting it. - Service Port: Make sure your backend Service is listening on port 80 (GKE’s Ingress forwards decrypted HTTPS traffic to port 80 by default).
3. Apply and Verify the Config
Push your updated Ingress config:
kubectl apply -f ingress.yaml
Note: GCP takes 5-10 minutes to update the Load Balancer configuration, so don’t panic if it doesn’t work immediately. Once it’s done, test with curl:
curl -I http://example.com
You should see a 301 Moved Permanently response with a Location header pointing to https://example.com.
4. Troubleshooting If It’s Still Not Working
- Check Ingress status: Run
kubectl describe ingress example-ingressand look at the Events section— if there’s an error with your certificate or backend, it’ll show up here. - Verify DNS: Ensure your domain
example.comis correctly pointing to your Ingress’s external IP. - Double-check the controller: If you’re using NGINX Ingress instead of GKE’s native one, swap the annotation to
nginx.ingress.kubernetes.io/force-ssl-redirect: "true".
That should get all your traffic routing to HTTPS like you want!
内容的提问来源于stack exchange,提问作者Daniel Lee

