我在AWS EC2上使用kops
实用程序创建集群。现在,我正在尝试配置ingress-nginx控制器,以便它路由群集中的所有流量。我需要它处理HTTP,HTTPS和WebSocket连接。基于此guide,我做了所有必需的事情:
kubectl apply -f https://raw.githubusercontent.com/kubernetes/ingress-nginx/nginx-0.28.0/deploy/static/mandatory.yaml
kubectl apply -f https://raw.githubusercontent.com/kubernetes/ingress-nginx/nginx-0.28.0/deploy/static/provider/aws/service-l4.yaml
kubectl apply -f https://raw.githubusercontent.com/kubernetes/ingress-nginx/nginx-0.28.0/deploy/static/provider/aws/patch-configmap-l4.yaml
当我尝试使用ingress-nginx
获取kubectl -n ingress-nginx get all
命名空间中的所有项目时:
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
service/ingress-nginx LoadBalancer 100.71.94.9 a7d3fe1383e344c1d8cb2de671xxxxxx-810xxxxxx.eu-central-1.elb.amazonaws.com 80:32389/TCP,443:31803/TCP 16m
当我打开AWS控制台-> EC2实例->负载均衡器时,我可以看到已经创建了ELB,但是在“实例”选项卡下的每个节点上都有OutOfService
状态。所以我无法访问我的ELB URL:a7d3fe1383e344c1d8cb2de671xxxxxx-810xxxxxx.eu-central-1.elb.amazonaws.com
:
有关使用kubectl -n ingress-nginx describe service/ingress-nginx
的服务的更多详细信息
Name: ingress-nginx
Namespace: ingress-nginx
Labels: app.kubernetes.io/name=ingress-nginx
app.kubernetes.io/part-of=ingress-nginx
Annotations: kubectl.kubernetes.io/last-applied-configuration:
{"apiVersion":"v1","kind":"Service","metadata":{"annotations":{"service.beta.kubernetes.io/aws-load-balancer-connection-idle-timeout":"60"...
service.beta.kubernetes.io/aws-load-balancer-connection-idle-timeout: 60
service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: *
Selector: app.kubernetes.io/name=ingress-nginx,app.kubernetes.io/part-of=ingress-nginx
Type: LoadBalancer
IP: 100.71.94.9
LoadBalancer Ingress: a7d3fe1383e344c1d8cb2de671xxxxxx-810xxxxxx.eu-central-1.elb.amazonaws.com
Port: http 80/TCP
TargetPort: http/TCP
NodePort: http 32389/TCP
Endpoints: <none>
Port: https 443/TCP
TargetPort: https/TCP
NodePort: https 31803/TCP
Endpoints: <none>
Session Affinity: None
External Traffic Policy: Cluster
Events:
Type Reason Age From Message
---- ------ ---- ---- -------
Normal EnsuringLoadBalancer 15m service-controller Ensuring load balancer
Normal EnsuredLoadBalancer 15m service-controller Ensured load balancer
我错过了什么吗?
UPD#1
如果我在EKS集群中执行相同的操作,则一切正常,并且入口控制器出现在每个节点上。有什么想法吗?。
答案 0 :(得分:0)
您需要在已部署nginx的EC2实例(kubernetes辅助节点)上添加安全组,以允许为ELB创建的安全组使用端口80和443。
编辑:
service/ingress-nginx
服务的终结点部分没有nginx容器的IP。因此,当ELB发送运行状况检查请求但请求无法到达pod时,运行状况检查将失败,并且ELB将后端标记为服务中断。