如何为Kubernetes中Integration-protocol-api分配固定公网IP以满足白名单访问?
Hey there! I’ve dealt with this exact scenario before—whitelisted external services are such a pain when your Kubernetes pods keep cycling IPs. Let’s walk through the most reliable ways to get a fixed public IP for your Integration-protocol-api service:
This is the go-to approach for managed Kubernetes clusters (AWS EKS, GCP GKE, Azure AKS). Most cloud providers let you reserve a static public IP upfront, then assign it directly to your LoadBalancer service.
Step-by-Step:
- First, reserve a static public IP in your cloud provider’s console (e.g., AWS Elastic IP, GCP Static IP Address, Azure Public IP). Make sure it’s in the same region as your Kubernetes cluster.
- Create or update your Service manifest to use this reserved IP:
apiVersion: v1 kind: Service metadata: name: integration-protocol-api-lb spec: type: LoadBalancer loadBalancerIP: "1.2.3.4" # Replace with your reserved static IP selector: app: integration-protocol-api # Match your pod's label ports: - protocol: TCP port: 80 # External port targetPort: 8080 # Port your app listens on inside the pod
- Apply the manifest with
kubectl apply -f service.yaml - Once the service is up, verify the external IP matches your reserved one with
kubectl get service integration-protocol-api-lb - Add this static IP to the
Another-Integration-Protocolnetwork’s whitelist.
This method is great because the cloud provider handles traffic routing, and the IP stays fixed even if pods restart or scale up/down.
If you’re running a self-managed cluster or don’t want to use a LoadBalancer, you can assign static public IPs to your worker nodes and expose the service via NodePort.
How to set it up:
- Assign static public IPs to your Kubernetes worker nodes (this depends on your hosting environment—for bare metal, you might use static IPs from your ISP; for cloud, reserve static IPs for each node).
- Create a NodePort service:
apiVersion: v1 kind: Service metadata: name: integration-protocol-api-nodeport spec: type: NodePort selector: app: integration-protocol-api ports: - protocol: TCP port: 80 targetPort: 8080 nodePort: 30007 # Optional: specify a fixed NodePort (range 30000-32767)
- Open the NodePort in your cluster’s firewall/security groups so external traffic can reach it.
- Add your worker nodes’ static public IPs to the whitelist (if you have multiple nodes, you can add all of them or use a load balancer in front of the nodes for high availability).
Note: If a worker node goes down, traffic to that node will fail—so consider adding a layer of high availability (like keepalived for bare metal) if uptime is critical.
If you already use an Ingress controller (like NGINX Ingress) in your cluster, you can assign a static public IP to the controller’s LoadBalancer service, then route traffic to your Integration-protocol-api via Ingress rules.
Setup:
- Reserve a static public IP in your cloud provider, then assign it to your Ingress controller’s LoadBalancer service (update the controller’s service manifest with
loadBalancerIP: "your-static-ip"). - Create an Ingress resource pointing to your service:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: integration-protocol-api-ingress spec: ingressClassName: nginx # Match your Ingress controller's class rules: - http: paths: - path: /integration-api pathType: Prefix backend: service: name: integration-protocol-api-service # Your ClusterIP service port: number: 80
- Apply the Ingress manifest, then add the Ingress controller’s static IP to the whitelist.
This is ideal if you have multiple services to expose, as you can manage all routing through a single static IP.
Quick Tips:
- Always verify the static IP stays assigned after restarting pods, services, or even the cluster.
- For cloud-managed clusters, double-check that your reserved IP is compatible with the LoadBalancer type (some cloud providers have separate IP types for internal vs external).
内容的提问来源于stack exchange,提问作者Joom187

