You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置HTTPS后Google Ingress Controller的WebSocket连接失败求助

Troubleshooting WebSocket Failures with Google Ingress Controller (ELB) Over HTTPS

Let's break down the issues in your HTTPS configuration that's causing WebSocket connections to fail, and walk through the fixes step by step.

Key Issues in Your Current HTTPS Setup

Looking at the gap between your working HTTP config and broken HTTPS config, three main problems stand out:

1. Proxy Protocol Was Unnecessarily Disabled

In your HTTP setup, you enabled Proxy Protocol via Service annotations and ConfigMap—this lets the ELB pass critical client request details (like source IP and protocol context) to the Nginx Ingress Controller. But in HTTPS mode, you turned this off. Without Proxy Protocol, Nginx can't properly interpret WebSocket handshake headers or recognize the original request was over HTTPS, which breaks the upgrade process.

2. Misaligned TargetPort for HTTPS Service

Your HTTPS Service maps port 443 to targetPort: http (Nginx's 80 port), while your HTTP setup mapped it to targetPort: https (Nginx's 443 port). Even though ELB terminates SSL and sends HTTP traffic to the backend, this misalignment causes Nginx to mishandle protocol-specific headers needed for WebSocket.

3. Missing WebSocket-Specific Nginx Configs

While Nginx Ingress supports WebSocket by default, you need explicit settings to handle long-lived connections and ensure critical headers are forwarded to your backend. Your current HTTPS ConfigMap lacks these essential parameters.

Fixed HTTPS Configuration

Updated Service YAML

kind: Service
apiVersion: v1
metadata:
  name: ingress-nginx
  namespace: ingress-nginx
  labels:
    app: ingress-nginx
  annotations:
    service.beta.kubernetes.io/aws-load-balancer-ssl-cert: "arn:aws:acm:us-east-1:2xxxxxxxxxxxxxxxxxxx56:certificate/3fxxxxxxxxxxxxxxxxxxxxxxxxxx80"
    service.beta.kubernetes.io/aws-load-balancer-backend-protocol: "http"
    service.beta.kubernetes.io/aws-load-balancer-ssl-ports: "https"
    # Re-enable Proxy Protocol to pass client request details to Nginx
    service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: '*'
    # Keep long idle timeout for WebSocket connections
    service.beta.kubernetes.io/aws-load-balancer-connection-idle-timeout: '3600'
spec:
  type: LoadBalancer
  selector:
    app: ingress-nginx
  ports:
    - name: http
      port: 80
      targetPort: http
    - name: https
      port: 443
      # Align with your HTTP setup's targetPort (matches Nginx's HTTPS listener)
      targetPort: https

Updated ConfigMap YAML

kind: ConfigMap
apiVersion: v1
metadata:
  name: nginx-configuration
  namespace: ingress-nginx
  labels:
    app: ingress-nginx
data:
  # Keep Proxy Protocol enabled to match Service annotation
  use-proxy-protocol: "true"
  # Extend timeouts to match ELB's 3600s for long-lived WebSocket connections
  proxy-read-timeout: "3600"
  proxy-send-timeout: "3600"
  # Explicitly forward WebSocket upgrade headers to your backend
  proxy-set-header: "Upgrade $http_upgrade"
  proxy-set-header: "Connection \"upgrade\""
  # Ensure Nginx recognizes the original HTTPS protocol from ELB
  use-forwarded-headers: "true"
  forwarded-for-header: "X-Forwarded-For"

Why These Fixes Work

  • Proxy Protocol: Ensures Nginx receives full context of the original client request (including that it was sent over HTTPS), which is essential for validating the WebSocket handshake.
  • TargetPort Alignment: Makes sure ELB's HTTPS traffic routes to the correct Nginx listener, preventing protocol mismatches that break header handling.
  • WebSocket-Specific Configs: Extended timeouts prevent idle WebSocket connections from being dropped, while the Upgrade and Connection headers ensure Nginx properly forwards the handshake request to your backend app.

Additional Checks

  • Verify your Ingress resource doesn't have rewrite rules or header filters that block the Upgrade or Connection headers.
  • After applying the configs, restart the Ingress Controller pods to ensure new settings take effect:
    kubectl rollout restart deployment ingress-nginx-controller -n ingress-nginx
    

内容的提问来源于stack exchange,提问作者Nikit Swaraj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 10:08:33