You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为Kubernetes中Integration-protocol-api分配固定公网IP以满足白名单访问?

Hey there! I’ve dealt with this exact scenario before—whitelisted external services are such a pain when your Kubernetes pods keep cycling IPs. Let’s walk through the most reliable ways to get a fixed public IP for your Integration-protocol-api service:

1. Use a LoadBalancer Service with a Reserved Static Public IP

This is the go-to approach for managed Kubernetes clusters (AWS EKS, GCP GKE, Azure AKS). Most cloud providers let you reserve a static public IP upfront, then assign it directly to your LoadBalancer service.

Step-by-Step:

  1. First, reserve a static public IP in your cloud provider’s console (e.g., AWS Elastic IP, GCP Static IP Address, Azure Public IP). Make sure it’s in the same region as your Kubernetes cluster.
  2. Create or update your Service manifest to use this reserved IP:
apiVersion: v1
kind: Service
metadata:
  name: integration-protocol-api-lb
spec:
  type: LoadBalancer
  loadBalancerIP: "1.2.3.4" # Replace with your reserved static IP
  selector:
    app: integration-protocol-api # Match your pod's label
  ports:
    - protocol: TCP
      port: 80 # External port
      targetPort: 8080 # Port your app listens on inside the pod
  1. Apply the manifest with kubectl apply -f service.yaml
  2. Once the service is up, verify the external IP matches your reserved one with kubectl get service integration-protocol-api-lb
  3. Add this static IP to the Another-Integration-Protocol network’s whitelist.

This method is great because the cloud provider handles traffic routing, and the IP stays fixed even if pods restart or scale up/down.

2. NodePort Service + Static Public IPs on Worker Nodes

If you’re running a self-managed cluster or don’t want to use a LoadBalancer, you can assign static public IPs to your worker nodes and expose the service via NodePort.

How to set it up:

  1. Assign static public IPs to your Kubernetes worker nodes (this depends on your hosting environment—for bare metal, you might use static IPs from your ISP; for cloud, reserve static IPs for each node).
  2. Create a NodePort service:
apiVersion: v1
kind: Service
metadata:
  name: integration-protocol-api-nodeport
spec:
  type: NodePort
  selector:
    app: integration-protocol-api
  ports:
    - protocol: TCP
      port: 80
      targetPort: 8080
      nodePort: 30007 # Optional: specify a fixed NodePort (range 30000-32767)
  1. Open the NodePort in your cluster’s firewall/security groups so external traffic can reach it.
  2. Add your worker nodes’ static public IPs to the whitelist (if you have multiple nodes, you can add all of them or use a load balancer in front of the nodes for high availability).

Note: If a worker node goes down, traffic to that node will fail—so consider adding a layer of high availability (like keepalived for bare metal) if uptime is critical.

3. Ingress Controller with Static Public IP

If you already use an Ingress controller (like NGINX Ingress) in your cluster, you can assign a static public IP to the controller’s LoadBalancer service, then route traffic to your Integration-protocol-api via Ingress rules.

Setup:

  1. Reserve a static public IP in your cloud provider, then assign it to your Ingress controller’s LoadBalancer service (update the controller’s service manifest with loadBalancerIP: "your-static-ip").
  2. Create an Ingress resource pointing to your service:
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: integration-protocol-api-ingress
spec:
  ingressClassName: nginx # Match your Ingress controller's class
  rules:
  - http:
      paths:
      - path: /integration-api
        pathType: Prefix
        backend:
          service:
            name: integration-protocol-api-service # Your ClusterIP service
            port:
              number: 80
  1. Apply the Ingress manifest, then add the Ingress controller’s static IP to the whitelist.

This is ideal if you have multiple services to expose, as you can manage all routing through a single static IP.

Quick Tips:

  • Always verify the static IP stays assigned after restarting pods, services, or even the cluster.
  • For cloud-managed clusters, double-check that your reserved IP is compatible with the LoadBalancer type (some cloud providers have separate IP types for internal vs external).

内容的提问来源于stack exchange,提问作者Joom187

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:57:26