Kubernetes Ingress ve yönlendirme
Hizmetlere dış erişim sağlamak, gelişmiş yönlendirme ve TLS sonlandırmayı etkinleştirmek için Ingress kaynaklarını yapılandırın.
Kubernetes Ingress ve yönlendirme, CoddyKit'te ücretsiz bir Docker & Kubernetes for Developers dersidir. Bu, 4 dersinin 1. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, Docker & Kubernetes for Developers öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. Docker & Kubernetes for Developers kursu toplamda 4 dersten oluşur.
Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.
Get External Access with Ingress
So far, we've used Services like NodePort or LoadBalancer to expose our applications outside the Kubernetes cluster.
While effective, these have limitations for complex routing, host-based rules, or managing TLS certificates for multiple applications.
This is where Ingress comes in! It acts as an entry point for external traffic, offering more advanced routing capabilities.
Ingress vs. Services: Key Differences
Let's clarify the roles:
- Service: Provides stable networking for Pods within the cluster and can expose a single application externally (e.g.,
NodePort,LoadBalancer). - Ingress: Manages external access to multiple Services, offering features like URL routing, host-based routing, and SSL/TLS termination.
Think of Ingress as a smart traffic controller for your external requests.
The Brain: Ingress Controller
An Ingress resource itself doesn't do anything on its own. It's just a set of rules you define.
You need an Ingress Controller running in your cluster. This controller watches for Ingress resources and configures a proxy (like Nginx, HAProxy, or Traefik) to fulfill those rules.
Without an Ingress Controller, your Ingress rules are ignored!
Anatomy of an Ingress Rule
An Ingress resource uses YAML to define how traffic should be routed. Here's a basic structure:
It specifies rules based on hostnames and paths, directing traffic to a specific Kubernetes Service.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: my-app-ingress
spec:
rules:
- host: myapp.example.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: my-app-service
port:
number: 80Routing by Hostname
One powerful feature is host-based routing. You can direct traffic for different hostnames to different backend Services.
For example, blog.example.com goes to your blog service, and api.example.com goes to your API service.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: multi-host-ingress
spec:
rules:
- host: blog.example.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: blog-service
port:
number: 80
- host: api.example.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: api-service
port:
number: 80Routing by URL Path
You can also route traffic based on the URL path. This is useful for exposing different parts of a single application or microservices under one domain.
For instance, myapp.com/users might go to a user service, while myapp.com/products goes to a product service.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: path-ingress
spec:
rules:
- host: myapp.example.com
http:
paths:
- path: /users
pathType: Prefix
backend:
service:
name: user-service
port:
number: 80
- path: /products
pathType: Prefix
backend:
service:
name: product-service
port:
number: 80Handling Unmatched Requests
What if no host or path rule matches an incoming request?
You can define a default backend in your Ingress. This directs all unmatched traffic to a specific Service, often a simple "404 Not Found" page or a default landing page.
It's good practice to always include a default backend for robustness.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: default-backend-ingress
spec:
defaultBackend:
service:
name: default-404-service
port:
number: 80
rules:
- host: myapp.example.com
http:
paths:
- path: /api
pathType: Prefix
backend:
service:
name: api-service
port:
number: 80Secure Traffic with TLS
Security is crucial! Ingress can also handle TLS termination. This means the Ingress Controller decrypts incoming HTTPS traffic before forwarding it to your backend Services (which can then run on plain HTTP).
This offloads SSL/TLS certificate management from your application Pods to the Ingress Controller.
You'll need a Kubernetes Secret containing your TLS certificate and key.
Ingress with TLS Example
To enable TLS, you reference a Kubernetes Secret in your Ingress definition. This Secret must contain the TLS certificate and private key.
The Ingress Controller will then use this certificate for HTTPS connections to your domain.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: secure-app-ingress
spec:
tls:
- hosts:
- secureapp.example.com
secretName: secureapp-tls-secret # Refers to a Kubernetes Secret
rules:
- host: secureapp.example.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: secure-app-service
port:
number: 443 # Or 80, if backend is HTTPIngress Routing Check
Consider an Ingress resource with the following rule:
rules:
- host: myapp.example.com
http:
paths:
- path: /api
pathType: Prefix
backend:
service:
name: api-service
port:
number: 80
- path: /
pathType: Prefix
backend:
service:
name: frontend-service
port:
number: 80
Which service will a request to http://myapp.example.com/api/v1/users be routed to?
Ingress: Your Smart Traffic Cop
In this lesson, you've learned about Kubernetes Ingress, a powerful tool for managing external access to your cluster.
- Ingress provides advanced routing features like host and path-based rules.
- An Ingress Controller is essential to make Ingress rules work.
- You can easily secure your applications with TLS termination using Ingress and Kubernetes Secrets.
Ingress simplifies exposing complex applications and microservices to the outside world!
Sıkça Sorulan Sorular
“Kubernetes Ingress ve yönlendirme” dersi ücretsiz mi?
Evet — “Kubernetes Ingress ve yönlendirme” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve Docker & Kubernetes for Developers kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. Docker & Kubernetes for Developers kursu toplamda 4 dersten oluşur.
“Kubernetes Ingress ve yönlendirme” dersinde ne öğreneceğim?
Hizmetlere dış erişim sağlamak, gelişmiş yönlendirme ve TLS sonlandırmayı etkinleştirmek için Ingress kaynaklarını yapılandırın. Docker & Kubernetes for Developers ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.
Docker & Kubernetes for Developers öğrenmeye başlamak için deneyim gerekli mi?
Önceden deneyim gerekmez. CoddyKit'te Docker & Kubernetes for Developers, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 1. dersidir.
“Kubernetes Ingress ve yönlendirme” dersi ne kadar sürer?
Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.
Bu Docker & Kubernetes for Developers dersinde kod yazıp çalıştırabilir miyim?
Evet. Her Docker & Kubernetes for Developers dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.
Bu kursun tüm dersleri
- Kubernetes Ingress ve yönlendirme
- Ağ politikalarını uygulama
- K8s'te hizmet keşfi ve DNS
- TLS Sonlandırma ve Ingress'i HTTPS ile Güvenceye Alma