为Ingress-GCE(GLBC)缺失的HTTP->HTTPS重定向实现解决方案
用自定义Apache后端实现GKE Inress-GCE的HTTP→HTTPS强制重定向
我明白你的困惑——Ingress-GCE(GLBC)确实没有内置的HTTP转HTTPS重定向功能,而你的应用本身又没部署Web服务器,想引入熟悉的Apache来做这个事儿完全没问题,咱们一步步来:
核心思路
本质是给Ingress加一个专门负责重定向的Apache后端Pod:让Ingress把所有HTTP(80端口)的流量转发到这个Apache,由它返回301/302重定向到HTTPS;而HTTPS(443端口)的流量直接转发到你的应用服务,完全不用动应用本身的代码或配置。
步骤1:创建Apache重定向服务
1.1 编写Apache重定向配置
先创建一个ConfigMap来存储Apache的重定向规则,这样不用自定义镜像,直接用官方的httpd镜像就行:
apiVersion: v1 kind: ConfigMap metadata: name: apache-redirect-config data: redirect.conf: | <VirtualHost *:80> # 替换成你的实际域名,多域名可添加ServerAlias ServerName your-domain.com ServerAlias www.your-domain.com # 永久重定向到HTTPS,临时重定向可把permanent改成temp Redirect permanent / https://your-domain.com/ </VirtualHost>
执行命令创建:
kubectl apply -f apache-redirect-config.yaml
1.2 部署Apache的Deployment和Service
接下来写Deployment的YAML,用官方httpd镜像,挂载刚才的ConfigMap到Apache的配置目录:
apiVersion: apps/v1 kind: Deployment metadata: name: apache-redirect spec: replicas: 1 selector: matchLabels: app: apache-redirect template: metadata: labels: app: apache-redirect spec: containers: - name: httpd image: httpd:2.4 ports: - containerPort: 80 volumeMounts: - name: config-volume mountPath: /usr/local/apache2/conf/extra/redirect.conf subPath: redirect.conf volumes: - name: config-volume configMap: name: apache-redirect-config --- apiVersion: v1 kind: Service metadata: name: apache-redirect-service spec: selector: app: apache-redirect ports: - protocol: TCP port: 80 targetPort: 80
执行命令部署:
kubectl apply -f apache-redirect-deployment.yaml
步骤2:配置Ingress资源
现在要修改(或创建)你的Ingress,把HTTP流量导向Apache服务,HTTPS流量导向你的应用服务:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: your-app-ingress annotations: # 指定使用GCE默认的GLBC控制器 kubernetes.io/ingress.class: "gce" # 可选:若用GKE托管证书,需先创建ManagedCertificate资源后添加此注解 # networking.gke.io/managed-certificates: "your-managed-cert" spec: tls: - hosts: - your-domain.com - www.your-domain.com secretName: your-tls-secret # 替换成你的TLS密钥Secret名称 rules: - host: your-domain.com http: paths: - path: / pathType: Prefix backend: service: name: apache-redirect-service port: number: 80 - path: / pathType: Prefix backend: service: name: your-app-service # 替换成你的应用服务名称 port: number: 80 # 替换成你的应用服务端口 - host: www.your-domain.com http: paths: - path: / pathType: Prefix backend: service: name: apache-redirect-service port: number: 80 - path: / pathType: Prefix backend: service: name: your-app-service port: number: 80
执行命令部署Ingress:
kubectl apply -f your-app-ingress.yaml
步骤3:验证效果
- 等待Ingress分配IP(用
kubectl get ingress查看状态) - 用curl测试HTTP访问,确认重定向生效:
curl -v http://your-domain.com
你会看到返回301 Moved Permanently,Location指向https://your-domain.com/
3. 测试HTTPS访问,确认能正常到达你的应用:
curl -v https://your-domain.com
一些注意事项
- 如果应用使用非80端口,记得在Ingress的backend里替换对应端口号
- 多域名场景只需在Apache配置中添加
ServerAlias,并同步更新Ingress的tls和rules字段 - 若用GKE托管证书,需提前创建
ManagedCertificate资源,再在Ingress注解中关联
内容的提问来源于stack exchange,提问作者zagrimsan
相关产品推荐
相关产品推荐

