You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Kubernetes中创建私有命名空间/域名(FQDN):遗留VM迁移问题

适配遗留FQDN服务解析的Kubernetes解决方案

我刚好处理过类似的遗留VM迁移到K8s的场景,针对你这种依赖固定FQDN(如service1.customer.domain.com)且无法修改产品代码的需求,这里有几个实用的解决方案,你可以根据服务规模和维护需求灵活选择:

方法1:Pod HostAliases 模拟/etc/hosts映射(小规模服务场景)

如果你的服务数量不多,直接在Pod模板中配置hostAliases是最简单的方式,它会自动在Pod的/etc/hosts文件中添加指定的IP和FQDN映射,和你之前在VM里的操作逻辑完全一致。

示例Deployment配置:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: legacy-app-deployment
spec:
  replicas: 2
  template:
    metadata:
      labels:
        app: legacy-app
    spec:
      # 配置HostAliases,对应原VM的/etc/hosts映射
      hostAliases:
      - ip: "10.244.1.5"  # 替换为service1对应的K8s Service ClusterIP或PodIP
        hostnames:
        - "service1.customer.domain.com"
      - ip: "10.244.2.8"  # 替换为service2对应的K8s Service ClusterIP或PodIP
        hostnames:
        - "service2.customer.domain.com"
      containers:
      - name: legacy-app-container
        image: your-legacy-app-image:v1
        ports:
        - containerPort: 8080

优势:配置简单,无需修改集群DNS,适合少量服务的场景;缺点:如果Service IP变化(比如Service重建),需要手动更新HostAliases中的IP。

方法2:CoreDNS自定义Zone实现全局域名解析(大规模服务推荐)

如果你的服务数量较多,或者需要动态适配Service的IP变化,修改CoreDNS配置来添加自定义域名Zone是更优的方案,它能让集群内所有Pod自动解析指定的FQDN到对应的K8s Service,无需在每个Pod中单独配置。

操作步骤:

  1. 编辑Kube-system命名空间下的CoreDNS ConfigMap:
kubectl edit configmap coredns -n kube-system
  1. 在Corefile段落中添加自定义Zone配置,这里提供两种模式:
    • 模式A:硬编码IP映射(和原/etc/hosts逻辑一致):
      # 在现有Corefile内容后添加以下配置
      customer.domain.com:53 {
          errors
          cache 30
          hosts {
              10.244.1.5 service1.customer.domain.com
              10.244.2.8 service2.customer.domain.com
              fallthrough  # 如果找不到映射,转发到上游DNS
          }
          forward . /etc/resolv.conf
      }
      
    • 模式B:重写域名到K8s内部服务(动态适配Service IP,推荐):
      这种方式会把遗留FQDN重写为K8s内部的Service域名(如service1.default.svc.cluster.local),自动指向Service的ClusterIP,无需硬编码IP:
      # 在现有Corefile内容后添加以下配置
      customer.domain.com:53 {
          errors
          cache 30
          # 重写遗留FQDN到K8s内部服务域名
          rewrite name service1.customer.domain.com service1.default.svc.cluster.local
          rewrite name service2.customer.domain.com service2.default.svc.cluster.local
          # 复用Kubernetes DNS插件处理内部解析
          kubernetes cluster.local in-addr.arpa ip6.arpa {
              pods insecure
              fallthrough in-addr.arpa ip6.arpa
          }
          forward . /etc/resolv.conf
      }
      
  2. 重启CoreDNS Pod让配置生效:
kubectl rollout restart deployment coredns -n kube-system

优势:全局生效,支持动态Service IP更新,适合大规模服务场景;缺点:需要有集群CoreDNS的修改权限。

方法3:ExternalName Service 做域名别名(可选补充)

如果需要将遗留FQDN映射到K8s内部或外部的服务,可以创建ExternalName类型的Service,配合CoreDNS的配置使用:

示例ExternalName Service配置:

apiVersion: v1
kind: Service
metadata:
  name: service1-alias
  namespace: default
spec:
  type: ExternalName
  externalName: service1.default.svc.cluster.local  # K8s内部Service域名

之后你可以在CoreDNS中配置将service1.customer.domain.com指向这个service1-alias的ClusterIP,或者直接用方法2的重写模式更高效。


内容的提问来源于stack exchange,提问作者user1843591

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 09:08:03