配置HTTPS后Google Ingress Controller的WebSocket连接失败求助
Let's break down the issues in your HTTPS configuration that's causing WebSocket connections to fail, and walk through the fixes step by step.
Key Issues in Your Current HTTPS Setup
Looking at the gap between your working HTTP config and broken HTTPS config, three main problems stand out:
1. Proxy Protocol Was Unnecessarily Disabled
In your HTTP setup, you enabled Proxy Protocol via Service annotations and ConfigMap—this lets the ELB pass critical client request details (like source IP and protocol context) to the Nginx Ingress Controller. But in HTTPS mode, you turned this off. Without Proxy Protocol, Nginx can't properly interpret WebSocket handshake headers or recognize the original request was over HTTPS, which breaks the upgrade process.
2. Misaligned TargetPort for HTTPS Service
Your HTTPS Service maps port 443 to targetPort: http (Nginx's 80 port), while your HTTP setup mapped it to targetPort: https (Nginx's 443 port). Even though ELB terminates SSL and sends HTTP traffic to the backend, this misalignment causes Nginx to mishandle protocol-specific headers needed for WebSocket.
3. Missing WebSocket-Specific Nginx Configs
While Nginx Ingress supports WebSocket by default, you need explicit settings to handle long-lived connections and ensure critical headers are forwarded to your backend. Your current HTTPS ConfigMap lacks these essential parameters.
Fixed HTTPS Configuration
Updated Service YAML
kind: Service apiVersion: v1 metadata: name: ingress-nginx namespace: ingress-nginx labels: app: ingress-nginx annotations: service.beta.kubernetes.io/aws-load-balancer-ssl-cert: "arn:aws:acm:us-east-1:2xxxxxxxxxxxxxxxxxxx56:certificate/3fxxxxxxxxxxxxxxxxxxxxxxxxxx80" service.beta.kubernetes.io/aws-load-balancer-backend-protocol: "http" service.beta.kubernetes.io/aws-load-balancer-ssl-ports: "https" # Re-enable Proxy Protocol to pass client request details to Nginx service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: '*' # Keep long idle timeout for WebSocket connections service.beta.kubernetes.io/aws-load-balancer-connection-idle-timeout: '3600' spec: type: LoadBalancer selector: app: ingress-nginx ports: - name: http port: 80 targetPort: http - name: https port: 443 # Align with your HTTP setup's targetPort (matches Nginx's HTTPS listener) targetPort: https
Updated ConfigMap YAML
kind: ConfigMap apiVersion: v1 metadata: name: nginx-configuration namespace: ingress-nginx labels: app: ingress-nginx data: # Keep Proxy Protocol enabled to match Service annotation use-proxy-protocol: "true" # Extend timeouts to match ELB's 3600s for long-lived WebSocket connections proxy-read-timeout: "3600" proxy-send-timeout: "3600" # Explicitly forward WebSocket upgrade headers to your backend proxy-set-header: "Upgrade $http_upgrade" proxy-set-header: "Connection \"upgrade\"" # Ensure Nginx recognizes the original HTTPS protocol from ELB use-forwarded-headers: "true" forwarded-for-header: "X-Forwarded-For"
Why These Fixes Work
- Proxy Protocol: Ensures Nginx receives full context of the original client request (including that it was sent over HTTPS), which is essential for validating the WebSocket handshake.
- TargetPort Alignment: Makes sure ELB's HTTPS traffic routes to the correct Nginx listener, preventing protocol mismatches that break header handling.
- WebSocket-Specific Configs: Extended timeouts prevent idle WebSocket connections from being dropped, while the
UpgradeandConnectionheaders ensure Nginx properly forwards the handshake request to your backend app.
Additional Checks
- Verify your Ingress resource doesn't have rewrite rules or header filters that block the
UpgradeorConnectionheaders. - After applying the configs, restart the Ingress Controller pods to ensure new settings take effect:
kubectl rollout restart deployment ingress-nginx-controller -n ingress-nginx
内容的提问来源于stack exchange,提问作者Nikit Swaraj

