我可以返回多个Ingress类'使用一个入口控制器
希望这里有人能有所帮助。 我有一个用例,在该用例中,我正在公开具有内部和外部LB的NGINX入口控制器。内部LB用于位于K8之外的事物,但在同一网络中可以通过进入K8中的事物进行交谈,同时仍利用我们的NGINX配置。
挑战:
我希望能够限制我们仅向内部系统暴露的端点,以便无法通过外部LB访问它们(对于某人来说,使用正确的主机标头击中外部LB非常容易并且仍然访问其背后的应用程序)。
有人知道做这件事的任何方法吗?这不必完全站立nginx部署。 IE,希望能够定义一个入口类,该类别将与内部LB一起使用,而不是外部LB使用。
Hoping someone here can help.
I have a use case, where I am exposing an NGINX ingress controller with both internal and external LBs. The internal LB is used for things that sit outside of K8S, but within the same network to talk via ingress to things inside K8S, whilst still leveraging our NGINX configurations.
The challenge :
I want to be able to restrict endpoints which we are exposing only to internal systems, so that they can not be accessed via the external LBs (it would be pretty easy for someone to hit the external LB with the correct host headers otherwise and still access the applications behind them).
Does anyone know of any way to do this, which does not involve having to stand up a duplicate NGINX deployment entirely. IE, was hoping to be able to have an ingress class defined which would use exclusively the service with the internal LB rather than the external one.
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
data:image/s3,"s3://crabby-images/d5906/d59060df4059a6cc364216c4d63ceec29ef7fe66" alt="扫码二维码加入Web技术交流群"
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论