You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google Kubernetes(GKE)特定网关流量路由与静态路由配置咨询

在GKE中通过特定网关路由流量&配置静态出口路由的解决方案

嘿,刚好之前在GKE环境里处理过类似的流量路由和出口IP固定的需求,给你详细拆解下解决方案,完全匹配你要连接IP白名单外部系统的场景~

一、通过特定网关路由流量(入向/内部流量)

这里分两种常用的网关场景,你可以根据自己的架构选择:

1. 使用GKE原生GCE Ingress网关

如果你的流量是HTTP/HTTPS的入向请求,GKE默认的GCE Ingress会绑定GCP的外部负载均衡作为网关。要指定特定的网关(比如绑定静态IP、自定义负载均衡参数),可以通过Ingress资源的annotations来配置:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: custom-ingress
  annotations:
    # 指定使用GCE Ingress类(GKE默认就是这个,也可以切换到nginx等其他类)
    kubernetes.io/ingress.class: "gce"
    # 绑定预先创建好的静态公网IP(需要先在GCP控制台/gcloud创建)
    kubernetes.io/ingress.global-static-ip-name: "my-static-ingress-ip"
spec:
  rules:
  - host: your-app-domain.com
    http:
      paths:
      - path: /your-app-path
        pathType: Prefix
        backend:
          service:
            name: your-app-service
            port:
              number: 80

部署这个Ingress后,所有指向your-app-domain.com/your-app-path的流量都会通过绑定了静态IP的GCE Ingress网关路由到你的后端服务。

2. 使用Istio Ingress Gateway(服务网格场景)

如果你的集群用了Istio服务网格,想要通过特定的Istio网关路由流量,需要先定义Gateway资源,再用VirtualService绑定路由规则:

# 第一步:定义特定的Istio Ingress Gateway
apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name: custom-istio-gateway
spec:
  selector:
    istio: ingressgateway # 对应Istio Ingress Gateway Pod的标签
  servers:
  - port:
      number: 80
      name: http
      protocol: HTTP
    hosts:
    - your-app-domain.com

# 第二步:配置VirtualService,将流量路由到后端服务
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: app-route
spec:
  hosts:
  - your-app-domain.com
  gateways:
  - custom-istio-gateway # 明确指定上面创建的网关
  http:
  - match:
    - uri:
        prefix: /your-app-path
    route:
    - destination:
        host: your-app-service.default.svc.cluster.local
        port:
          number: 80

这样所有匹配规则的流量都会通过你指定的custom-istio-gateway进入集群并路由到目标服务。

二、配置静态路由让特定外部IP流量走指定静态IP网关(出向流量)

这部分是你核心需求的关键——让Pod访问特定外部IP时,用固定的静态公网IP作为出口,以便加入对方的IP白名单。这里推荐两种可靠的方案:

1. Cloud NAT + VPC静态路由方案(无服务网格场景)

这是GKE官方推荐的出口IP固定方案,适合没有用服务网格的集群:

  • 步骤1:创建静态公网IP
    先用gcloud命令或GCP控制台创建一个区域级静态IP:

    gcloud compute addresses create my-nat-static-ip --region=your-cluster-region
    
  • 步骤2:创建Cloud NAT网关
    把刚才的静态IP绑定到Cloud NAT网关,关联GKE集群所在的VPC子网:

    # 先确保你有VPC路由器,如果没有先创建:gcloud compute routers create my-router --region=your-cluster-region --network=your-vpc-network
    gcloud compute routers nats create my-nat-gateway \
      --router=my-router \
      --region=your-cluster-region \
      --nat-external-ip-pool=my-nat-static-ip \
      --nat-custom-subnet-ip-ranges=your-gke-subnet-name
    
  • 步骤3:创建VPC静态路由
    在GCP VPC中创建一条静态路由,让目标外部IP的流量指向这个NAT网关:

    gcloud compute routes create route-to-external-system \
      --network=your-vpc-network \
      --destination-range=192.168.1.100/32 \ # 替换成外部系统的IP/网段
      --next-hop-router=my-router \
      --next-hop-router-region=your-cluster-region
    

完成后,所有GKE Pod访问192.168.1.100的流量都会通过绑定了静态IP的Cloud NAT网关出去,对方的白名单只需要加入my-nat-static-ip即可。

2. Istio Egress Gateway方案(服务网格场景)

如果你的集群用了Istio,可以用Egress Gateway作为出口,绑定静态IP,然后配置路由让访问特定外部IP的流量走这个网关:

# 第一步:创建带静态IP的Istio Egress Gateway Service
apiVersion: v1
kind: Service
metadata:
  name: custom-egress-gateway
  namespace: istio-system
  annotations:
    # 绑定预先创建的静态公网IP
    service.beta.kubernetes.io/google-cloud-load-balancer-static-ip: "my-egress-static-ip"
spec:
  type: LoadBalancer
  selector:
    istio: egressgateway
  ports:
  - port: 443
    name: https
    targetPort: 443

# 第二步:定义Egress Gateway资源
apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name: external-system-egress-gateway
  namespace: istio-system
spec:
  selector:
    istio: egressgateway
  servers:
  - port:
      number: 443
      name: https
      protocol: HTTPS
    hosts:
    - external-system-ip # 或者外部系统的域名
    tls:
      mode: SIMPLE
      credentialName: external-system-cert # 如果需要SSL证书,提前创建Secret

# 第三步:配置VirtualService,让Pod流量走Egress Gateway
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: route-to-external-system
spec:
  hosts:
  - external-system-ip # 目标外部IP/域名
  gateways:
  - mesh # 集群内部Pod发起的流量
  - istio-system/external-system-egress-gateway # 指定Egress网关
  http:
  - match:
    - gateways:
      - mesh
    route:
    - destination:
        host: custom-egress-gateway.istio-system.svc.cluster.local
        port:
          number: 443
  - match:
    - gateways:
      - istio-system/external-system-egress-gateway
    route:
    - destination:
        host: external-system-ip
        port:
          number: 443

这样集群内Pod访问目标外部IP时,流量会先转发到Egress Gateway,再通过其绑定的静态IP出口,完美适配白名单需求。

关键注意事项

  • 所有静态公网IP必须和GKE集群在同一个GCP项目、同区域(区域IP)或全局(全局IP)。
  • 配置完成后,建议用curl从Pod内访问外部系统,再检查GCP的NAT或负载均衡日志,确认出口IP正确。
  • 如果外部系统是域名,也可以用域名代替IP配置路由,更灵活。

内容的提问来源于stack exchange,提问作者bogumbiker

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:57:44