【问题标题】:Kubernetes Host and Service Ingress Mapping using TCP使用 TCP 的 Kubernetes 主机和服务入口映射
【发布时间】:2021-10-27 07:25:16
【问题描述】:

在使用 Kubernetes 几个月后,我发现了一种很好的方法,可以使用单个现有域名并通过子域公开 cluster-ip,但也可以使用不同的子子域公开大多数微服务入口控制器。

我的入口示例代码:

kind: Ingress
apiVersion: networking.k8s.io/v1beta1
metadata:
  name: cluster-ingress-basic
  namespace: ingress-basic
  selfLink: >-
    /apis/networking.k8s.io/v1beta1/namespaces/ingress-basic/ingresses/cluster-ingress-basic
  uid: 5d14e959-db5f-413f-8263-858bacc62fa6
  resourceVersion: '42220492'
  generation: 29
  creationTimestamp: '2021-06-23T12:00:16Z'
  annotations:
    kubernetes.io/ingress.class: nginx
  managedFields:
    - manager: Mozilla
      operation: Update
      apiVersion: networking.k8s.io/v1beta1
      time: '2021-06-23T12:00:16Z'
      fieldsType: FieldsV1
      fieldsV1:
        'f:metadata':
          'f:annotations':
            .: {}
            'f:kubernetes.io/ingress.class': {}
        'f:spec':
          'f:rules': {}
    - manager: nginx-ingress-controller
      operation: Update
      apiVersion: networking.k8s.io/v1beta1
      time: '2021-06-23T12:00:45Z'
      fieldsType: FieldsV1
      fieldsV1:
        'f:status':
          'f:loadBalancer':
            'f:ingress': {}
spec:
  rules:
    - host: microname1.subdomain.domain.com
      http:
        paths:
          - pathType: ImplementationSpecific
            backend:
              serviceName: kylin-job-svc
              servicePort: 7070
    - host: microname2.subdomain.domain.com
      http:
        paths:
          - pathType: ImplementationSpecific
            backend:
              serviceName: superset
              servicePort: 80
    - {}
status:
  loadBalancer:
    ingress:
      - ip: xx.xx.xx.xx

使用此配置:

  1. microname1.subdomain.domain.com 指向 Apache Kylin
  2. microname2.subdomain.domain.com 指向 Apache Superset

这样,所有微服务都可以使用相同的 Cluster-Load-Balancer(IP) 公开,但子域不同。

我尝试对 SQL Server 执行相同的操作,但这不起作用,不知道为什么,但我觉得原因是 SQL Server 使用 TCP 而不是 HTTP 进行通信。

- host: microname3.subdomain.domain.com
  http:
    paths:
      - pathType: ImplementationSpecific
        backend:
          serviceName: mssql-linux
          servicePort: 1433

关于如何为 TCP 服务做同样的事情有什么想法吗?

【问题讨论】:

    标签: sql-server kubernetes service ingress-controller


    【解决方案1】:

    您的理解很好,默认情况下 NGINX Ingress Controller 仅支持 HTTP 和 HTTPS 流量配置(第 7 层),因此您的 SQL 服务器可能因此无法正常工作。

    您的 SQL 服务正在使用 TCP 连接运行,因此它是 does not take into consideration custom domains that you are trying to setup as they are using same IP address anyway。

    您的问题的解决方案不是为此服务使用自定义子域,而是设置exposing TCP service in NGINX Ingress Controller。例如,您可以将此 SQL 服务设置为在端口 1433 上的入口 IP 上可用:

    Ingress 控制器使用标志 --tcp-services-configmap 和 --udp-services-configmap 指向现有配置映射,其中键是要使用的外部端口,值指示使用以下格式公开的服务:<namespace/service name>:<service port>:[PROXY]:[PROXY]

    要设置它,您可以按照official NGINX Ingress documentation 中提供的步骤操作,但也有一些有关 StackOverflow 的更详细说明,例如 this one。

    【讨论】:

    • 感谢您的澄清,只是有一个问题,我刚刚添加了 tcp-services configmap,我正在尝试访问 loadbalancher-ip 但仍然无法访问。
    • 请添加一些关于您已经配置的信息,配置文件等,或者考虑创建一个新主题。
    • 我只创建了这里描述的配置文件kubernetes.github.io/ingress-nginx/user-guide/…,但我觉得我必须使用标志做更多的事情
    • 请查看我在回答中提到的更详细的说明;)
    • @Stavros Koureas 请让我知道你是否能够让它工作。
    猜你喜欢
    • 1970-01-01
    • 2019-04-10
    • 1970-01-01
    • 2019-03-26
    • 2021-05-31
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2017-07-22
    相关资源
    最近更新 更多