0Pricing
Docker & Kubernetes for Developers · درس

Ingress والتوجيه في Kubernetes

هيّئوا موارد Ingress لتوفير وصول خارجي إلى الخدمات، مع إتاحة التوجيه المتقدم وإنهاء TLS.

Ingress والتوجيه في Kubernetes درس مجاني في Docker & Kubernetes for Developers على CoddyKit. هذا هو الدرس 1 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Docker & Kubernetes for Developers، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Docker & Kubernetes for Developers 4 دروس في المجموع.

بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.

Get External Access with Ingress

So far, we've used Services like NodePort or LoadBalancer to expose our applications outside the Kubernetes cluster.

While effective, these have limitations for complex routing, host-based rules, or managing TLS certificates for multiple applications.

This is where Ingress comes in! It acts as an entry point for external traffic, offering more advanced routing capabilities.

Ingress vs. Services: Key Differences

Let's clarify the roles:

  • Service: Provides stable networking for Pods within the cluster and can expose a single application externally (e.g., NodePort, LoadBalancer).
  • Ingress: Manages external access to multiple Services, offering features like URL routing, host-based routing, and SSL/TLS termination.

Think of Ingress as a smart traffic controller for your external requests.

The Brain: Ingress Controller

An Ingress resource itself doesn't do anything on its own. It's just a set of rules you define.

You need an Ingress Controller running in your cluster. This controller watches for Ingress resources and configures a proxy (like Nginx, HAProxy, or Traefik) to fulfill those rules.

Without an Ingress Controller, your Ingress rules are ignored!

Anatomy of an Ingress Rule

An Ingress resource uses YAML to define how traffic should be routed. Here's a basic structure:

It specifies rules based on hostnames and paths, directing traffic to a specific Kubernetes Service.

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: my-app-ingress
spec:
  rules:
  - host: myapp.example.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: my-app-service
            port:
              number: 80

Routing by Hostname

One powerful feature is host-based routing. You can direct traffic for different hostnames to different backend Services.

For example, blog.example.com goes to your blog service, and api.example.com goes to your API service.

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: multi-host-ingress
spec:
  rules:
  - host: blog.example.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: blog-service
            port:
              number: 80
  - host: api.example.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: api-service
            port:
              number: 80

Routing by URL Path

You can also route traffic based on the URL path. This is useful for exposing different parts of a single application or microservices under one domain.

For instance, myapp.com/users might go to a user service, while myapp.com/products goes to a product service.

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: path-ingress
spec:
  rules:
  - host: myapp.example.com
    http:
      paths:
      - path: /users
        pathType: Prefix
        backend:
          service:
            name: user-service
            port:
              number: 80
      - path: /products
        pathType: Prefix
        backend:
          service:
            name: product-service
            port:
              number: 80

Handling Unmatched Requests

What if no host or path rule matches an incoming request?

You can define a default backend in your Ingress. This directs all unmatched traffic to a specific Service, often a simple "404 Not Found" page or a default landing page.

It's good practice to always include a default backend for robustness.

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: default-backend-ingress
spec:
  defaultBackend:
    service:
      name: default-404-service
      port:
        number: 80
  rules:
  - host: myapp.example.com
    http:
      paths:
      - path: /api
        pathType: Prefix
        backend:
          service:
            name: api-service
            port:
              number: 80

Secure Traffic with TLS

Security is crucial! Ingress can also handle TLS termination. This means the Ingress Controller decrypts incoming HTTPS traffic before forwarding it to your backend Services (which can then run on plain HTTP).

This offloads SSL/TLS certificate management from your application Pods to the Ingress Controller.

You'll need a Kubernetes Secret containing your TLS certificate and key.

Ingress with TLS Example

To enable TLS, you reference a Kubernetes Secret in your Ingress definition. This Secret must contain the TLS certificate and private key.

The Ingress Controller will then use this certificate for HTTPS connections to your domain.

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: secure-app-ingress
spec:
  tls:
  - hosts:
    - secureapp.example.com
    secretName: secureapp-tls-secret # Refers to a Kubernetes Secret
  rules:
  - host: secureapp.example.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: secure-app-service
            port:
              number: 443 # Or 80, if backend is HTTP

Ingress Routing Check

Consider an Ingress resource with the following rule:

  rules:
  - host: myapp.example.com
    http:
      paths:
      - path: /api
        pathType: Prefix
        backend:
          service:
            name: api-service
            port:
              number: 80
      - path: /
        pathType: Prefix
        backend:
          service:
            name: frontend-service
            port:
              number: 80

Which service will a request to http://myapp.example.com/api/v1/users be routed to?

Ingress: Your Smart Traffic Cop

In this lesson, you've learned about Kubernetes Ingress, a powerful tool for managing external access to your cluster.

  • Ingress provides advanced routing features like host and path-based rules.
  • An Ingress Controller is essential to make Ingress rules work.
  • You can easily secure your applications with TLS termination using Ingress and Kubernetes Secrets.

Ingress simplifies exposing complex applications and microservices to the outside world!

الأسئلة الشائعة

هل درس «Ingress والتوجيه في Kubernetes» مجاني؟

نعم — نص درس «Ingress والتوجيه في Kubernetes» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Docker & Kubernetes for Developers، انتقل إلى CoddyKit PRO. تتضمن دورة Docker & Kubernetes for Developers 4 دروس في المجموع.

ماذا ستتعلم في «Ingress والتوجيه في Kubernetes»؟

هيّئوا موارد Ingress لتوفير وصول خارجي إلى الخدمات، مع إتاحة التوجيه المتقدم وإنهاء TLS. تتمرن على Docker & Kubernetes for Developers مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.

هل أحتاج إلى خبرة سابقة لأبدأ Docker & Kubernetes for Developers؟

لا تُشترط خبرة سابقة. Docker & Kubernetes for Developers على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 1 من أصل 4.

كم من الوقت يستغرق درس «Ingress والتوجيه في Kubernetes»؟

معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.

هل يمكنني كتابة وتشغيل أكواد في درس Docker & Kubernetes for Developers هذا؟

نعم. كل درس في Docker & Kubernetes for Developers يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.

جميع الدروس في هذه الدورة

  1. Ingress والتوجيه في Kubernetes
  2. تنفيذ سياسات الشبكة
  3. اكتشاف الخدمات وDNS في K8s
  4. إنهاء TLS وتأمين Ingress باستخدام HTTPS
← العودة إلى Docker & Kubernetes for Developers