Google Kubernetes(GKE)特定网关流量路由与静态路由配置咨询
嘿,刚好之前在GKE环境里处理过类似的流量路由和出口IP固定的需求,给你详细拆解下解决方案,完全匹配你要连接IP白名单外部系统的场景~
一、通过特定网关路由流量(入向/内部流量)
这里分两种常用的网关场景,你可以根据自己的架构选择:
1. 使用GKE原生GCE Ingress网关
如果你的流量是HTTP/HTTPS的入向请求,GKE默认的GCE Ingress会绑定GCP的外部负载均衡作为网关。要指定特定的网关(比如绑定静态IP、自定义负载均衡参数),可以通过Ingress资源的annotations来配置:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: custom-ingress annotations: # 指定使用GCE Ingress类(GKE默认就是这个,也可以切换到nginx等其他类) kubernetes.io/ingress.class: "gce" # 绑定预先创建好的静态公网IP(需要先在GCP控制台/gcloud创建) kubernetes.io/ingress.global-static-ip-name: "my-static-ingress-ip" spec: rules: - host: your-app-domain.com http: paths: - path: /your-app-path pathType: Prefix backend: service: name: your-app-service port: number: 80
部署这个Ingress后,所有指向your-app-domain.com/your-app-path的流量都会通过绑定了静态IP的GCE Ingress网关路由到你的后端服务。
2. 使用Istio Ingress Gateway(服务网格场景)
如果你的集群用了Istio服务网格,想要通过特定的Istio网关路由流量,需要先定义Gateway资源,再用VirtualService绑定路由规则:
# 第一步:定义特定的Istio Ingress Gateway apiVersion: networking.istio.io/v1alpha3 kind: Gateway metadata: name: custom-istio-gateway spec: selector: istio: ingressgateway # 对应Istio Ingress Gateway Pod的标签 servers: - port: number: 80 name: http protocol: HTTP hosts: - your-app-domain.com # 第二步:配置VirtualService,将流量路由到后端服务 apiVersion: networking.istio.io/v1alpha3 kind: VirtualService metadata: name: app-route spec: hosts: - your-app-domain.com gateways: - custom-istio-gateway # 明确指定上面创建的网关 http: - match: - uri: prefix: /your-app-path route: - destination: host: your-app-service.default.svc.cluster.local port: number: 80
这样所有匹配规则的流量都会通过你指定的custom-istio-gateway进入集群并路由到目标服务。
二、配置静态路由让特定外部IP流量走指定静态IP网关(出向流量)
这部分是你核心需求的关键——让Pod访问特定外部IP时,用固定的静态公网IP作为出口,以便加入对方的IP白名单。这里推荐两种可靠的方案:
1. Cloud NAT + VPC静态路由方案(无服务网格场景)
这是GKE官方推荐的出口IP固定方案,适合没有用服务网格的集群:
步骤1:创建静态公网IP
先用gcloud命令或GCP控制台创建一个区域级静态IP:gcloud compute addresses create my-nat-static-ip --region=your-cluster-region步骤2:创建Cloud NAT网关
把刚才的静态IP绑定到Cloud NAT网关,关联GKE集群所在的VPC子网:# 先确保你有VPC路由器,如果没有先创建:gcloud compute routers create my-router --region=your-cluster-region --network=your-vpc-network gcloud compute routers nats create my-nat-gateway \ --router=my-router \ --region=your-cluster-region \ --nat-external-ip-pool=my-nat-static-ip \ --nat-custom-subnet-ip-ranges=your-gke-subnet-name步骤3:创建VPC静态路由
在GCP VPC中创建一条静态路由,让目标外部IP的流量指向这个NAT网关:gcloud compute routes create route-to-external-system \ --network=your-vpc-network \ --destination-range=192.168.1.100/32 \ # 替换成外部系统的IP/网段 --next-hop-router=my-router \ --next-hop-router-region=your-cluster-region
完成后,所有GKE Pod访问192.168.1.100的流量都会通过绑定了静态IP的Cloud NAT网关出去,对方的白名单只需要加入my-nat-static-ip即可。
2. Istio Egress Gateway方案(服务网格场景)
如果你的集群用了Istio,可以用Egress Gateway作为出口,绑定静态IP,然后配置路由让访问特定外部IP的流量走这个网关:
# 第一步:创建带静态IP的Istio Egress Gateway Service apiVersion: v1 kind: Service metadata: name: custom-egress-gateway namespace: istio-system annotations: # 绑定预先创建的静态公网IP service.beta.kubernetes.io/google-cloud-load-balancer-static-ip: "my-egress-static-ip" spec: type: LoadBalancer selector: istio: egressgateway ports: - port: 443 name: https targetPort: 443 # 第二步:定义Egress Gateway资源 apiVersion: networking.istio.io/v1alpha3 kind: Gateway metadata: name: external-system-egress-gateway namespace: istio-system spec: selector: istio: egressgateway servers: - port: number: 443 name: https protocol: HTTPS hosts: - external-system-ip # 或者外部系统的域名 tls: mode: SIMPLE credentialName: external-system-cert # 如果需要SSL证书,提前创建Secret # 第三步:配置VirtualService,让Pod流量走Egress Gateway apiVersion: networking.istio.io/v1alpha3 kind: VirtualService metadata: name: route-to-external-system spec: hosts: - external-system-ip # 目标外部IP/域名 gateways: - mesh # 集群内部Pod发起的流量 - istio-system/external-system-egress-gateway # 指定Egress网关 http: - match: - gateways: - mesh route: - destination: host: custom-egress-gateway.istio-system.svc.cluster.local port: number: 443 - match: - gateways: - istio-system/external-system-egress-gateway route: - destination: host: external-system-ip port: number: 443
这样集群内Pod访问目标外部IP时,流量会先转发到Egress Gateway,再通过其绑定的静态IP出口,完美适配白名单需求。
关键注意事项
- 所有静态公网IP必须和GKE集群在同一个GCP项目、同区域(区域IP)或全局(全局IP)。
- 配置完成后,建议用
curl从Pod内访问外部系统,再检查GCP的NAT或负载均衡日志,确认出口IP正确。 - 如果外部系统是域名,也可以用域名代替IP配置路由,更灵活。
内容的提问来源于stack exchange,提问作者bogumbiker

