You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为Ingress-GCE(GLBC)缺失的HTTP->HTTPS重定向实现解决方案

用自定义Apache后端实现GKE Inress-GCE的HTTP→HTTPS强制重定向

我明白你的困惑——Ingress-GCE(GLBC)确实没有内置的HTTP转HTTPS重定向功能,而你的应用本身又没部署Web服务器,想引入熟悉的Apache来做这个事儿完全没问题,咱们一步步来:

核心思路

本质是给Ingress加一个专门负责重定向的Apache后端Pod:让Ingress把所有HTTP(80端口)的流量转发到这个Apache,由它返回301/302重定向到HTTPS;而HTTPS(443端口)的流量直接转发到你的应用服务,完全不用动应用本身的代码或配置。


步骤1:创建Apache重定向服务

1.1 编写Apache重定向配置

先创建一个ConfigMap来存储Apache的重定向规则,这样不用自定义镜像,直接用官方的httpd镜像就行:

apiVersion: v1
kind: ConfigMap
metadata:
  name: apache-redirect-config
data:
  redirect.conf: |
    <VirtualHost *:80>
        # 替换成你的实际域名,多域名可添加ServerAlias
        ServerName your-domain.com
        ServerAlias www.your-domain.com

        # 永久重定向到HTTPS,临时重定向可把permanent改成temp
        Redirect permanent / https://your-domain.com/
    </VirtualHost>

执行命令创建:

kubectl apply -f apache-redirect-config.yaml

1.2 部署Apache的Deployment和Service

接下来写Deployment的YAML,用官方httpd镜像,挂载刚才的ConfigMap到Apache的配置目录:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: apache-redirect
spec:
  replicas: 1
  selector:
    matchLabels:
      app: apache-redirect
  template:
    metadata:
      labels:
        app: apache-redirect
    spec:
      containers:
      - name: httpd
        image: httpd:2.4
        ports:
        - containerPort: 80
        volumeMounts:
        - name: config-volume
          mountPath: /usr/local/apache2/conf/extra/redirect.conf
          subPath: redirect.conf
      volumes:
      - name: config-volume
        configMap:
          name: apache-redirect-config
---
apiVersion: v1
kind: Service
metadata:
  name: apache-redirect-service
spec:
  selector:
    app: apache-redirect
  ports:
  - protocol: TCP
    port: 80
    targetPort: 80

执行命令部署:

kubectl apply -f apache-redirect-deployment.yaml

步骤2:配置Ingress资源

现在要修改(或创建)你的Ingress,把HTTP流量导向Apache服务,HTTPS流量导向你的应用服务:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: your-app-ingress
  annotations:
    # 指定使用GCE默认的GLBC控制器
    kubernetes.io/ingress.class: "gce"
    # 可选:若用GKE托管证书,需先创建ManagedCertificate资源后添加此注解
    # networking.gke.io/managed-certificates: "your-managed-cert"
spec:
  tls:
  - hosts:
    - your-domain.com
    - www.your-domain.com
    secretName: your-tls-secret # 替换成你的TLS密钥Secret名称
  rules:
  - host: your-domain.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: apache-redirect-service
            port:
              number: 80
      - path: /
        pathType: Prefix
        backend:
          service:
            name: your-app-service # 替换成你的应用服务名称
            port:
              number: 80 # 替换成你的应用服务端口
  - host: www.your-domain.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: apache-redirect-service
            port:
              number: 80
      - path: /
        pathType: Prefix
        backend:
          service:
            name: your-app-service
            port:
              number: 80

执行命令部署Ingress:

kubectl apply -f your-app-ingress.yaml

步骤3:验证效果

  1. 等待Ingress分配IP(用kubectl get ingress查看状态)
  2. 用curl测试HTTP访问,确认重定向生效:
curl -v http://your-domain.com

你会看到返回301 Moved Permanently,Location指向https://your-domain.com/
3. 测试HTTPS访问,确认能正常到达你的应用:

curl -v https://your-domain.com

一些注意事项

  • 如果应用使用非80端口,记得在Ingress的backend里替换对应端口号
  • 多域名场景只需在Apache配置中添加ServerAlias,并同步更新Ingress的tls和rules字段
  • 若用GKE托管证书,需提前创建ManagedCertificate资源,再在Ingress注解中关联

内容的提问来源于stack exchange,提问作者zagrimsan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:04:03