外部訪問集羣內的服務,能夠經過NodePort或LoadBalancer(這一般由雲服務商提供),還能夠經過ingress訪問.html
Ingress包含兩個組件Ingress Controller和Ingress:nginx
Ingress:將Nginx的配置抽象成一個Ingress對象,每添加一個新的服務只需寫一個新的Ingress的yaml文件便可
Ingress Controller:將新加入的Ingress轉化成Nginx的配置文件並使之生效git
https://kubernetes.github.io/ingress-nginx/deploy/github
default-backend的做用是,若是外界訪問的域名不存在的話,則默認轉發到default-http-backend這個Service,其會直接返回404:web
[root@master ingress]# cat default-backend.yaml apiVersion: extensions/v1beta1 kind: Deployment metadata: name: default labels: k8s-app: default-http-backend namespace: default spec: replicas: 1 template: metadata: labels: k8s-app: default-http-backend spec: terminationGracePeriodSeconds: 60 containers: - name: default-http-backend # Any image is permissable as long as: # 1. It serves a 404 page at / # 2. It serves 200 on a /healthz endpoint image: anjia0532/defaultbackend:1.0 livenessProbe: httpGet: path: /healthz port: 8080 scheme: HTTP initialDelaySeconds: 30 timeoutSeconds: 5 ports: - containerPort: 8080 resources: limits: cpu: 10m memory: 20Mi requests: cpu: 10m memory: 20Mi --- apiVersion: v1 kind: Service metadata: name: default-http-backend namespace: default labels: k8s-app: default-http-backend spec: ports: - port: 80 targetPort: 8080 selector: k8s-app: default-http-backend [root@master ingress]#kubectl create -f default-backend.yaml
[root@master ingress]# cat nginx-ingress-controller.yaml apiVersion: v1 kind: ReplicationController metadata: name: nginx-ingress-lb labels: name: nginx-ingress-lb namespace: default spec: replicas: 1 template: metadata: labels: name: nginx-ingress-lb annotations: prometheus.io/port: '10254' prometheus.io/scrape: 'true' spec: terminationGracePeriodSeconds: 60 hostNetwork: true containers: - image: anjia0532/nginx-ingress-controller:0.9.0-beta.7 name: nginx-ingress-lb readinessProbe: httpGet: path: /healthz port: 10254 scheme: HTTP livenessProbe: httpGet: path: /healthz port: 10254 scheme: HTTP initialDelaySeconds: 10 timeoutSeconds: 1 ports: - containerPort: 80 hostPort: 80 - containerPort: 443 hostPort: 443 env: - name: POD_NAME valueFrom: fieldRef: fieldPath: metadata.name - name: POD_NAMESPACE valueFrom: fieldRef: fieldPath: metadata.namespace - name: KUBERNETES_MASTER value: http://192.168.2.17:8080 args: - /nginx-ingress-controller - --default-backend-service=$(POD_NAMESPACE)/default-http-backend - --apiserver-host=http://192.168.2.17:8080 [root@master ingress]#kubectl create -f nginx-ingress-controller.yaml
ps:
注意以上master地址,須要配置成正確的地址api
[root@master ingress]# cat test-nginx-ingress.yaml apiVersion: extensions/v1beta1 kind: Ingress metadata: name: test-nginx-ingress namespace: default spec: rules: - host: test.nginx.ingress http: paths: - path: / backend: serviceName: nginx-service servicePort: 80 [root@master ingress]#kubectl create -f test-nginx-ingress.yaml
rules中的host必須爲域名,不能爲IP,表示Ingress-controller的Pod所在主機域名,也就是Ingress-controller的IP對應的域名。
paths中的path則表示映射的路徑。如映射/表示若訪問test.nginx.ingress,則會將請求轉發至Kibana的service,端口爲5601。app
[root@master ingress]# kubectl get ingress -o wide NAME HOSTS ADDRESS PORTS AGE dashboard-weblogic-ingress test.nginx.ingress 192.168.2.26 80 2m
咱們經過如下命令將pod中nginx的配置文件輸出到當前目錄下看看curl
kubectl exec nginx-ingress-lb-6glds -it cat /etc/nginx/nginx.conf > nginx.conf
能夠看到是一個標準的nginx配置文件ide
#curl -H "Host:test.nginx.ingress" 192.168.2.26/a.html
若是正常,便可輸出結果url