在GCE上配置HTTPS强制跳转及流量重定向的技术咨询
Hey there! Let’s walk through the best ways to enforce HTTPS and set up HTTP-to-HTTPS redirects in your GCE Kubernetes setup with kube-lego—both using the GCE Load Balancer and alternative, more flexible options.
方案一:通过GCE Ingress实现重定向
The GCE Kubernetes Ingress controller natively supports HTTP-to-HTTPS redirects, but we need to make sure we don’t break kube-lego’s ACME domain validation (which relies on unredirected HTTP access to a specific path). Here’s how to set it up:
Step 1: Update your Ingress resource
Add redirect annotations while exempting the ACME challenge path. Here’s a sample config:apiVersion: extensions/v1beta1 kind: Ingress metadata: name: your-app-ingress annotations: kubernetes.io/ingress.class: "gce" # Enable HTTP → HTTPS redirect ingress.gcp.kubernetes.io/force-ssl-redirect: "true" # Exempt ACME challenge path to keep kube-lego working ingress.gcp.kubernetes.io/ssl-redirect-exempt: "/.well-known/acme-challenge/*" # Your existing kube-lego annotation kubernetes.io/tls-acme: "true" spec: tls: - hosts: - your-domain.com secretName: your-tls-secret rules: - host: your-domain.com http: paths: - path: /* backend: serviceName: your-app-service servicePort: 80 # Route ACME challenge traffic to kube-lego - path: /.well-known/acme-challenge/* backend: serviceName: kube-lego servicePort: 8080The
force-ssl-redirectflag tells the GCE LB to send all HTTP (port 80) traffic to HTTPS (port 443), whilessl-redirect-exemptensures kube-lego can still reach the validation path via HTTP.Step 2: Test the setup
After applying the config withkubectl apply -f your-ingress.yaml, wait a few minutes for the GCE LB to update its rules. Test with:curl -I http://your-domain.comYou should get a 301 redirect to the HTTPS version. Then check the ACME path:
curl -I http://your-domain.com/.well-known/acme-challenge/test-pathThis should not redirect—confirming kube-lego can still do its job.
方案二:使用Nginx Ingress Controller(更灵活的替代)
If you need more granular control over redirects (like custom status codes or additional exempt paths), the Nginx Ingress Controller is a great alternative. It works seamlessly with kube-lego too:
Step 1: Deploy Nginx Ingress Controller
Deploy the controller tailored for GCE (use the official static deployment files for your Kubernetes version).Step 2: Configure your Ingress
Similar to the GCE setup, but with Nginx-specific annotations:apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: your-app-ingress annotations: kubernetes.io/ingress.class: "nginx" # Enable HTTP → HTTPS redirect nginx.ingress.kubernetes.io/force-ssl-redirect: "true" # Exempt ACME challenge path nginx.ingress.kubernetes.io/ssl-redirect-exempt: "/.well-known/acme-challenge/*" # Your existing kube-lego annotation kubernetes.io/tls-acme: "true" spec: tls: - hosts: - your-domain.com secretName: your-tls-secret rules: - host: your-domain.com http: paths: - path: /* pathType: Prefix backend: service: name: your-app-service port: number: 80 - path: /.well-known/acme-challenge/* pathType: Prefix backend: service: name: kube-lego port: number: 8080Nginx lets you tweak things like redirect status codes (default is 308 permanent redirect) or add regex-based exempt paths if needed.
Critical Notes to Remember
- Never redirect the ACME challenge path: Kube-lego uses HTTP-01 validation, which requires unblocked HTTP access to
/.well-known/acme-challenge/. Blocking this will break certificate issuance and renewal. - Wait for LB updates: Both GCE and Nginx Ingress take a few minutes to propagate rule changes—don’t panic if tests fail immediately after applying configs.
- Test certificate renewal: After setting up redirects, manually trigger a renewal test to ensure kube-lego can still validate your domain without issues.
内容的提问来源于stack exchange,提问作者Tino

