You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Kubernetes中搭配AWS ELB使用Nginx Ingress(含SSL配置)

Using AWS ACM SSL Certificate with AWS ELB + Nginx Ingress in Kubernetes

Hey there! Let's break down how to get your existing AWS ACM SSL certificate working seamlessly with AWS ELB and the Nginx Ingress Controller in Kubernetes, building off the service config you shared.

Step 1: Finalize Your Ingress Controller Service Configuration

First, let's complete and clarify your Service setup — it already has most of the critical ELB annotations, but we need to fill in the spec section to make it functional:

apiVersion: v1
kind: Service
metadata:
  annotations:
    # Tells AWS ELB to use TCP to communicate with the Nginx Ingress Controller (since Nginx handles HTTP/HTTPS internally)
    service.beta.kubernetes.io/aws-load-balancer-backend-protocol: tcp
    # Sets ELB connection idle timeout to 1 hour (great for long-lived connections like WebSockets)
    service.beta.kubernetes.io/aws-load-balancer-connection-idle-timeout: "3600"
    # Enables Proxy Protocol so Nginx can capture the real client IP (super important for logging or access control)
    service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: '*'
    # Links your ACM certificate to the ELB — this is where your certificate ARN goes
    service.beta.kubernetes.io/aws-load-balancer-ssl-cert: arn:aws:acm:...fa5298fc
    # Instructs ELB to enable SSL on the HTTPS port (matches the port we'll define below)
    service.beta.kubernetes.io/aws-load-balancer-ssl-ports: https
  labels:
    k8s-addon: ingress-nginx.addons.k8s.io
  name: ingress-nginx
spec:
  type: LoadBalancer  # Tells Kubernetes to provision an AWS ELB for this service
  ports:
    - name: http
      port: 80
      targetPort: 80  # Points to Nginx's HTTP port
      protocol: TCP
    - name: https
      port: 443
      targetPort: 443  # Points to Nginx's HTTPS port
      protocol: TCP
  selector:
    # Make sure this matches the labels on your Nginx Ingress Controller pods
    app.kubernetes.io/name: ingress-nginx

Each annotation here serves a specific purpose: the SSL cert annotation ties your ACM certificate directly to the ELB, while the proxy protocol annotation ensures Nginx gets the real client IP instead of the ELB's IP.

Step 2: Configure Your Ingress Resource to Work with SSL Offloading

Since the ELB will handle SSL termination (aka SSL offloading), we need to tell Nginx about this so it can handle headers and redirects correctly. Here's a sample Ingress config:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: example-app-ingress
  annotations:
    # Redirect all HTTP traffic to HTTPS
    nginx.ingress.kubernetes.io/ssl-redirect: "true"
    nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
    # Enable Proxy Protocol support to match the Service config (critical for real client IPs)
    nginx.ingress.kubernetes.io/enable-proxy-protocol: "true"
    # Optional: Enable HSTS for better security
    nginx.ingress.kubernetes.io/hsts: "true"
    nginx.ingress.kubernetes.io/hsts-max-age: "31536000"
spec:
  ingressClassName: nginx  # Use this if you have multiple ingress controllers; omit if nginx is default
  rules:
    - host: your-domain.com  # Replace with your actual domain (the one on your ACM cert)
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: your-app-service  # Replace with your app's Service name
                port:
                  number: 80
  # No TLS section needed here! SSL is terminated at the ELB, so Nginx communicates with ELB over plain TCP

Note that we don't include a tls block in the Ingress because the SSL work is done at the ELB level. Nginx only sees plain HTTP traffic from the ELB, but it knows the original request was HTTPS thanks to the headers passed by the ELB.

Step 3: Verify Your Setup

Let's make sure everything is working as expected:

  1. Check that the ELB is provisioned:

    kubectl get service ingress-nginx
    

    Look for the EXTERNAL-IP field — this should be your ELB's public domain name.

  2. Confirm the ACM certificate is attached:
    Head to the AWS Console, go to EC2 > Load Balancers, find your ELB, and check the Listeners tab. The HTTPS (443) listener should show your ACM certificate.

  3. Test the connection:

    • Visit https://your-domain.com — you should see your app, and the browser should show a valid SSL certificate.
    • Visit http://your-domain.com — you should be automatically redirected to HTTPS.

Important Things to Keep in Mind

  • Proxy Protocol Consistency: You must enable Proxy Protocol in both the Service annotations and the Ingress annotations. If you skip either, Nginx will log the ELB's IP as the client IP instead of the real user's.
  • Certificate Validation: Your ACM certificate must be fully validated (via DNS or HTTP) before the ELB can use it. If validation isn't complete, the ELB will throw an error.
  • Security Groups: Ensure your ELB's security group allows inbound traffic on ports 80 and 443, and your Kubernetes nodes' security groups allow inbound traffic from the ELB on ports 80 and 443.
  • Idle Timeout: The 3600-second timeout you set is great for long connections, but adjust it if your use case doesn't require it.

内容的提问来源于stack exchange,提问作者user2156115

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:32:41