如何在Kubernetes中搭配AWS ELB使用Nginx Ingress(含SSL配置)
Hey there! Let's break down how to get your existing AWS ACM SSL certificate working seamlessly with AWS ELB and the Nginx Ingress Controller in Kubernetes, building off the service config you shared.
Step 1: Finalize Your Ingress Controller Service Configuration
First, let's complete and clarify your Service setup — it already has most of the critical ELB annotations, but we need to fill in the spec section to make it functional:
apiVersion: v1 kind: Service metadata: annotations: # Tells AWS ELB to use TCP to communicate with the Nginx Ingress Controller (since Nginx handles HTTP/HTTPS internally) service.beta.kubernetes.io/aws-load-balancer-backend-protocol: tcp # Sets ELB connection idle timeout to 1 hour (great for long-lived connections like WebSockets) service.beta.kubernetes.io/aws-load-balancer-connection-idle-timeout: "3600" # Enables Proxy Protocol so Nginx can capture the real client IP (super important for logging or access control) service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: '*' # Links your ACM certificate to the ELB — this is where your certificate ARN goes service.beta.kubernetes.io/aws-load-balancer-ssl-cert: arn:aws:acm:...fa5298fc # Instructs ELB to enable SSL on the HTTPS port (matches the port we'll define below) service.beta.kubernetes.io/aws-load-balancer-ssl-ports: https labels: k8s-addon: ingress-nginx.addons.k8s.io name: ingress-nginx spec: type: LoadBalancer # Tells Kubernetes to provision an AWS ELB for this service ports: - name: http port: 80 targetPort: 80 # Points to Nginx's HTTP port protocol: TCP - name: https port: 443 targetPort: 443 # Points to Nginx's HTTPS port protocol: TCP selector: # Make sure this matches the labels on your Nginx Ingress Controller pods app.kubernetes.io/name: ingress-nginx
Each annotation here serves a specific purpose: the SSL cert annotation ties your ACM certificate directly to the ELB, while the proxy protocol annotation ensures Nginx gets the real client IP instead of the ELB's IP.
Step 2: Configure Your Ingress Resource to Work with SSL Offloading
Since the ELB will handle SSL termination (aka SSL offloading), we need to tell Nginx about this so it can handle headers and redirects correctly. Here's a sample Ingress config:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: example-app-ingress annotations: # Redirect all HTTP traffic to HTTPS nginx.ingress.kubernetes.io/ssl-redirect: "true" nginx.ingress.kubernetes.io/force-ssl-redirect: "true" # Enable Proxy Protocol support to match the Service config (critical for real client IPs) nginx.ingress.kubernetes.io/enable-proxy-protocol: "true" # Optional: Enable HSTS for better security nginx.ingress.kubernetes.io/hsts: "true" nginx.ingress.kubernetes.io/hsts-max-age: "31536000" spec: ingressClassName: nginx # Use this if you have multiple ingress controllers; omit if nginx is default rules: - host: your-domain.com # Replace with your actual domain (the one on your ACM cert) http: paths: - path: / pathType: Prefix backend: service: name: your-app-service # Replace with your app's Service name port: number: 80 # No TLS section needed here! SSL is terminated at the ELB, so Nginx communicates with ELB over plain TCP
Note that we don't include a tls block in the Ingress because the SSL work is done at the ELB level. Nginx only sees plain HTTP traffic from the ELB, but it knows the original request was HTTPS thanks to the headers passed by the ELB.
Step 3: Verify Your Setup
Let's make sure everything is working as expected:
Check that the ELB is provisioned:
kubectl get service ingress-nginxLook for the
EXTERNAL-IPfield — this should be your ELB's public domain name.Confirm the ACM certificate is attached:
Head to the AWS Console, go to EC2 > Load Balancers, find your ELB, and check the Listeners tab. The HTTPS (443) listener should show your ACM certificate.Test the connection:
- Visit
https://your-domain.com— you should see your app, and the browser should show a valid SSL certificate. - Visit
http://your-domain.com— you should be automatically redirected to HTTPS.
- Visit
Important Things to Keep in Mind
- Proxy Protocol Consistency: You must enable Proxy Protocol in both the Service annotations and the Ingress annotations. If you skip either, Nginx will log the ELB's IP as the client IP instead of the real user's.
- Certificate Validation: Your ACM certificate must be fully validated (via DNS or HTTP) before the ELB can use it. If validation isn't complete, the ELB will throw an error.
- Security Groups: Ensure your ELB's security group allows inbound traffic on ports 80 and 443, and your Kubernetes nodes' security groups allow inbound traffic from the ELB on ports 80 and 443.
- Idle Timeout: The 3600-second timeout you set is great for long connections, but adjust it if your use case doesn't require it.
内容的提问来源于stack exchange,提问作者user2156115

