Kubernetes Ingress 与路由
配置 Ingress 资源,为服务提供外部访问,并支持高级路由和 TLS 终止。
Kubernetes Ingress 与路由 是 CoddyKit 上的免费 Docker & Kubernetes for Developers 课时。 这是第 1 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Docker & Kubernetes for Developers 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Docker & Kubernetes for Developers 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
Get External Access with Ingress
So far, we've used Services like NodePort or LoadBalancer to expose our applications outside the Kubernetes cluster.
While effective, these have limitations for complex routing, host-based rules, or managing TLS certificates for multiple applications.
This is where Ingress comes in! It acts as an entry point for external traffic, offering more advanced routing capabilities.
Ingress vs. Services: Key Differences
Let's clarify the roles:
- Service: Provides stable networking for Pods within the cluster and can expose a single application externally (e.g.,
NodePort,LoadBalancer). - Ingress: Manages external access to multiple Services, offering features like URL routing, host-based routing, and SSL/TLS termination.
Think of Ingress as a smart traffic controller for your external requests.
The Brain: Ingress Controller
An Ingress resource itself doesn't do anything on its own. It's just a set of rules you define.
You need an Ingress Controller running in your cluster. This controller watches for Ingress resources and configures a proxy (like Nginx, HAProxy, or Traefik) to fulfill those rules.
Without an Ingress Controller, your Ingress rules are ignored!
Anatomy of an Ingress Rule
An Ingress resource uses YAML to define how traffic should be routed. Here's a basic structure:
It specifies rules based on hostnames and paths, directing traffic to a specific Kubernetes Service.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: my-app-ingress
spec:
rules:
- host: myapp.example.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: my-app-service
port:
number: 80Routing by Hostname
One powerful feature is host-based routing. You can direct traffic for different hostnames to different backend Services.
For example, blog.example.com goes to your blog service, and api.example.com goes to your API service.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: multi-host-ingress
spec:
rules:
- host: blog.example.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: blog-service
port:
number: 80
- host: api.example.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: api-service
port:
number: 80Routing by URL Path
You can also route traffic based on the URL path. This is useful for exposing different parts of a single application or microservices under one domain.
For instance, myapp.com/users might go to a user service, while myapp.com/products goes to a product service.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: path-ingress
spec:
rules:
- host: myapp.example.com
http:
paths:
- path: /users
pathType: Prefix
backend:
service:
name: user-service
port:
number: 80
- path: /products
pathType: Prefix
backend:
service:
name: product-service
port:
number: 80Handling Unmatched Requests
What if no host or path rule matches an incoming request?
You can define a default backend in your Ingress. This directs all unmatched traffic to a specific Service, often a simple "404 Not Found" page or a default landing page.
It's good practice to always include a default backend for robustness.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: default-backend-ingress
spec:
defaultBackend:
service:
name: default-404-service
port:
number: 80
rules:
- host: myapp.example.com
http:
paths:
- path: /api
pathType: Prefix
backend:
service:
name: api-service
port:
number: 80Secure Traffic with TLS
Security is crucial! Ingress can also handle TLS termination. This means the Ingress Controller decrypts incoming HTTPS traffic before forwarding it to your backend Services (which can then run on plain HTTP).
This offloads SSL/TLS certificate management from your application Pods to the Ingress Controller.
You'll need a Kubernetes Secret containing your TLS certificate and key.
Ingress with TLS Example
To enable TLS, you reference a Kubernetes Secret in your Ingress definition. This Secret must contain the TLS certificate and private key.
The Ingress Controller will then use this certificate for HTTPS connections to your domain.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: secure-app-ingress
spec:
tls:
- hosts:
- secureapp.example.com
secretName: secureapp-tls-secret # Refers to a Kubernetes Secret
rules:
- host: secureapp.example.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: secure-app-service
port:
number: 443 # Or 80, if backend is HTTPIngress Routing Check
Consider an Ingress resource with the following rule:
rules:
- host: myapp.example.com
http:
paths:
- path: /api
pathType: Prefix
backend:
service:
name: api-service
port:
number: 80
- path: /
pathType: Prefix
backend:
service:
name: frontend-service
port:
number: 80
Which service will a request to http://myapp.example.com/api/v1/users be routed to?
Ingress: Your Smart Traffic Cop
In this lesson, you've learned about Kubernetes Ingress, a powerful tool for managing external access to your cluster.
- Ingress provides advanced routing features like host and path-based rules.
- An Ingress Controller is essential to make Ingress rules work.
- You can easily secure your applications with TLS termination using Ingress and Kubernetes Secrets.
Ingress simplifies exposing complex applications and microservices to the outside world!
用 AI 导师学习 Docker & Kubernetes for Developers — 免费
在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。
- 课程
- 12
- 课程
- 48
常见问题解答
「Kubernetes Ingress 与路由」课时是免费的吗?
是的 — 「Kubernetes Ingress 与路由」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Docker & Kubernetes for Developers 课程的其余内容,请升级到 CoddyKit PRO。 Docker & Kubernetes for Developers 课程共包含 4 节课。
「Kubernetes Ingress 与路由」这节课中我会学到什么?
配置 Ingress 资源,为服务提供外部访问,并支持高级路由和 TLS 终止。 你通过在浏览器中直接运行的动手代码来练习 Docker & Kubernetes for Developers,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 Docker & Kubernetes for Developers 需要有经验吗?
无需任何先前经验。CoddyKit 上的 Docker & Kubernetes for Developers 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 1 节课,共 4 节。
「Kubernetes Ingress 与路由」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 Docker & Kubernetes for Developers 课中编写并运行代码吗?
能。每节 Docker & Kubernetes for Developers 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。
此课程中的所有课时
- Kubernetes Ingress 与路由
- 实施网络策略
- K8s 中的服务发现与 DNS
- TLS 终止与使用 HTTPS 保护 Ingress