You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在GCE上配置HTTPS强制跳转及流量重定向的技术咨询

Hey there! Let’s walk through the best ways to enforce HTTPS and set up HTTP-to-HTTPS redirects in your GCE Kubernetes setup with kube-lego—both using the GCE Load Balancer and alternative, more flexible options.

解决方案:GCE Kubernetes环境下强制HTTPS与HTTP重定向

方案一:通过GCE Ingress实现重定向

The GCE Kubernetes Ingress controller natively supports HTTP-to-HTTPS redirects, but we need to make sure we don’t break kube-lego’s ACME domain validation (which relies on unredirected HTTP access to a specific path). Here’s how to set it up:

  • Step 1: Update your Ingress resource
    Add redirect annotations while exempting the ACME challenge path. Here’s a sample config:

    apiVersion: extensions/v1beta1
    kind: Ingress
    metadata:
      name: your-app-ingress
      annotations:
        kubernetes.io/ingress.class: "gce"
        # Enable HTTP → HTTPS redirect
        ingress.gcp.kubernetes.io/force-ssl-redirect: "true"
        # Exempt ACME challenge path to keep kube-lego working
        ingress.gcp.kubernetes.io/ssl-redirect-exempt: "/.well-known/acme-challenge/*"
        # Your existing kube-lego annotation
        kubernetes.io/tls-acme: "true"
    spec:
      tls:
      - hosts:
        - your-domain.com
        secretName: your-tls-secret
      rules:
      - host: your-domain.com
        http:
          paths:
          - path: /*
            backend:
              serviceName: your-app-service
              servicePort: 80
          # Route ACME challenge traffic to kube-lego
          - path: /.well-known/acme-challenge/*
            backend:
              serviceName: kube-lego
              servicePort: 8080
    

    The force-ssl-redirect flag tells the GCE LB to send all HTTP (port 80) traffic to HTTPS (port 443), while ssl-redirect-exempt ensures kube-lego can still reach the validation path via HTTP.

  • Step 2: Test the setup
    After applying the config with kubectl apply -f your-ingress.yaml, wait a few minutes for the GCE LB to update its rules. Test with:

    curl -I http://your-domain.com
    

    You should get a 301 redirect to the HTTPS version. Then check the ACME path:

    curl -I http://your-domain.com/.well-known/acme-challenge/test-path
    

    This should not redirect—confirming kube-lego can still do its job.

方案二:使用Nginx Ingress Controller(更灵活的替代)

If you need more granular control over redirects (like custom status codes or additional exempt paths), the Nginx Ingress Controller is a great alternative. It works seamlessly with kube-lego too:

  • Step 1: Deploy Nginx Ingress Controller
    Deploy the controller tailored for GCE (use the official static deployment files for your Kubernetes version).

  • Step 2: Configure your Ingress
    Similar to the GCE setup, but with Nginx-specific annotations:

    apiVersion: networking.k8s.io/v1
    kind: Ingress
    metadata:
      name: your-app-ingress
      annotations:
        kubernetes.io/ingress.class: "nginx"
        # Enable HTTP → HTTPS redirect
        nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
        # Exempt ACME challenge path
        nginx.ingress.kubernetes.io/ssl-redirect-exempt: "/.well-known/acme-challenge/*"
        # Your existing kube-lego annotation
        kubernetes.io/tls-acme: "true"
    spec:
      tls:
      - hosts:
        - your-domain.com
        secretName: your-tls-secret
      rules:
      - host: your-domain.com
        http:
          paths:
          - path: /*
            pathType: Prefix
            backend:
              service:
                name: your-app-service
                port:
                  number: 80
          - path: /.well-known/acme-challenge/*
            pathType: Prefix
            backend:
              service:
                name: kube-lego
                port:
                  number: 8080
    

    Nginx lets you tweak things like redirect status codes (default is 308 permanent redirect) or add regex-based exempt paths if needed.

Critical Notes to Remember

  • Never redirect the ACME challenge path: Kube-lego uses HTTP-01 validation, which requires unblocked HTTP access to /.well-known/acme-challenge/. Blocking this will break certificate issuance and renewal.
  • Wait for LB updates: Both GCE and Nginx Ingress take a few minutes to propagate rule changes—don’t panic if tests fail immediately after applying configs.
  • Test certificate renewal: After setting up redirects, manually trigger a renewal test to ensure kube-lego can still validate your domain without issues.

内容的提问来源于stack exchange,提问作者Tino

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 03:58:46