首页
学习
活动
专区
圈层
工具
发布
社区首页 >问答首页 >从上游读取响应头时,入口nginx上游没有发送有效的HTTP/1.0报头

从上游读取响应头时,入口nginx上游没有发送有效的HTTP/1.0报头
EN

Server Fault用户
提问于 2020-06-02 23:30:51
回答 1查看 8.1K关注 0票数 1

我正在尝试为我的命名空间中的服务设置一个nginx入口控制器。其中一个后端服务在端口80上接受HTTP流量,另一个在端口443上只接受HTTPS流量。请参阅这两项服务的说明。

代码语言:javascript
复制
$ kubectl describe svc service-1 -n monit
Name:              service-1
Namespace:         monit
Labels:            app=service-1
Annotations:       
Selector:          app=service-1
Type:              ClusterIP
IP:                10.104.185.173
Port:              https  443/TCP
TargetPort:        8443/TCP
Endpoints:         10.1.0.95:8443
Session Affinity:  None
Events:            

$ kubectl describe svc service-2 -n monit
Name:              service-2
Namespace:         monit
Labels:            app=service-2
Annotations:       
Selector:          app=service-2
Type:              ClusterIP
IP:                10.110.93.64
Port:              service  80/TCP
TargetPort:        3000/TCP
Endpoints:         10.1.0.87:3000
Session Affinity:  None
Events:            

这是我的入口配置

代码语言:javascript
复制
apiVersion: extensions/v1beta1
kind: Ingress
metadata:
  name: ingress-monit
spec:
  rules:
  - host: service-2.localhost
    http:
      paths:
      - path: /
        backend:
          serviceName: service-2
          servicePort: 80
  - host: service-1.localhost
    http:
      paths:
      - path: /
        backend:
          serviceName: service-1
          servicePort: 443

当我查看Nginx配置时,一切看起来都很好

代码语言:javascript
复制
$ kubectl describe ingress ingress-monit -n monit                  
Name:             ingress-monit
Namespace:        monit
Address:          localhost
Default backend:  default-http-backend:80 ()
Rules:
  Host                            Path  Backends
  ----                            ----  --------
  service-2.localhost               
                                  /   service-2:80 (10.1.0.87:3000)
  service-1.localhost  
                                  /   service-1:443 (10.1.0.95:8443)
Annotations:                      Events:
  Type                            Reason  Age   From                      Message
  ----                            ------  ----  ----                      -------
  Normal                          CREATE  31m   nginx-ingress-controller  Ingress monit/ingress-monit
  Normal                          UPDATE  30m   nginx-ingress-controller  Ingress monit/ingress-monit

现在的问题是,我可以使用http://service-2.localhost/正确地访问服务-2,但我不能访问服务-1。访问铬上的http://service-1.localhost/给我

代码语言:javascript
复制
This site can’t be reachedThe webpage at https://service-1.localhost/ might be temporarily down or it may have moved permanently to a new web address.
ERR_INVALID_RESPONSE

当我查看Nginx日志时,我看到:

代码语言:javascript
复制
$ kubectl logs -n monit ingress-nginx-controller-bbdc786b4-8crdm -f
-------------------------------------------------------------------------------
NGINX Ingress controller
  Release:       0.32.0
  Build:         git-446845114
  Repository:    https://github.com/kubernetes/ingress-nginx
  nginx version: nginx/1.17.10

-------------------------------------------------------------------------------
. . .
2020/06/02 22:56:47 [error] 2363#2363: *64928 upstream sent no valid HTTP/1.0 header while reading response header from upstream, client: 192.168.65.3, server: service-1.localhost, request: "GET / HTTP/1.1", upstream: "http://10.1.0.95:8443/", host: "service-1.localhost"
192.168.65.3 - - [02/Jun/2020:22:58:13 +0000] "GET / HTTP/1.1" 200 7817 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 594 0.005 [monit-service-2-80] [] 10.1.0.87:3000 30520 0.005 200 2baefff713047b14a81643650cb50c4c

该错误似乎与服务-1返回糟糕的响应upstream sent no valid HTTP/1.0 header while reading response header from upstream有关。问题是,如果我使用kubectl proxy,我可以正确地访问该服务!!

我怎么才能弄清楚真正的问题是什么?

EN

回答 1

Server Fault用户

回答已采纳

发布于 2020-06-03 04:14:22

您将需要通过SSL连接上游的侵入域上的nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"注释,因为默认情况下,入口控制器假定所有集群内的上行流都使用HTTP。

据我所知,您不能为每个rule:添加该注释,因此您必须为其创建第二个Ingress:

代码语言:javascript
复制
apiVersion: extensions/v1beta1
kind: Ingress
metadata:
  name: ingress-monit-service-1
  annotations:
    nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
spec:
  rules:
  - host: service-1.localhost
    http:
      paths:
      - path: /
        backend:
          serviceName: service-1
          servicePort: 443
票数 3
EN
页面原文内容由Server Fault提供。腾讯云小微IT领域专用引擎提供翻译支持
原文链接:

https://serverfault.com/questions/1019778

复制
相关文章

相似问题

领券
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档