K8S traffic ingress rewrite rule
The requirements are as follows:
Domain name service
Www.baidu.com/authorize saas-jcpt-saas-uc-authorize-core-tomcat-online
Analysis:
1. To get to ingress, so you can't remove authorize from the front.
two。 Rewrite needs to be configured on ingress
Configuration
Www.baidu.com and saas-jcpt-saas-uc-authorize-core-tomcat-online are in different namespaces, so you need to create a new ingress under saas-jcpt-tomcat-online, configured as follows:
ApiVersion: extensions/v1beta1kind: Ingressmetadata:name: public-fe-n-saas-uc-node-online-ingressnamespace: saas-jcpt-tomcat-onlineannotations:traefik.ingress.kubernetes.io/rewrite-target: / spec:rules:- host: www.baidu.comhttp:paths:- backend:serviceName: saas-jcpt-saas-uc-authorize-core-tomcat-onlineservicePort: 8080path: / authorizestatus:loadBalancer: {}
Pay attention to a small pit:
The following requirements are required:
Domain name service
Www.abc.com/aaa/ saas-jcpt-saas-uc-authorize-core-tomcat-online/bbb/
The way we are used to writing may be as follows:
ApiVersion: extensions/v1beta1kind: Ingressmetadata: name: public-fe-n-saas-uc-node-online-ingress namespace: saas-jcpt-tomcat-online annotations: traefik.ingress.kubernetes.io/rewrite-target: / bbb/spec: rules:-host: www.abc.com http: paths:-backend: serviceName: saas-jcpt-saas-uc-authorize-core-tomcat-online servicePort: 8080 path: / aaa/status: loadBalancer: {}
At this time, when we visit http://www.abc.com/aaa/xxx, we will find that the actual URL called on the container is: saas-jcpt-saas-uc-authorize-core-tomcat-online/bbbxxx, the middle / none.
The problem can be solved by removing the last of path and traefik.ingress.kubernetes.io/rewrite-target at the same time:
ApiVersion: extensions/v1beta1kind: Ingressmetadata: name: public-fe-n-saas-uc-node-online-ingress namespace: saas-jcpt-tomcat-online annotations: traefik.ingress.kubernetes.io/rewrite-target: / bbbspec: rules:-host: www.abc.com http: paths:-backend: serviceName: saas-jcpt-saas-uc-authorize-core-tomcat-online servicePort: 8080 path: / aaastatus: loadBalancer: {}