gpt4 book ai didi

kubernetes - 在kubernetes上运行的traefik AWS ELB上的真实IP

转载 作者:行者123 更新时间:2023-12-02 12:29:13 24 4
gpt4 key购买 nike

我已经在配置了traefik(v1.7)的EKS集群(v1.13)上部署了服务。我已将源IP列入白名单,并在ELB上也启用了Proxyprotocol。我无法获得客户的真实IP。这是我的配置方式。

traefik.toml

[entryPoints.https.whiteList]
sourceRange = ["10.100.0.0/16"]
useXForwardedFor = true
[entryPoints.https.proxyProtocol]
trustedIPs = ["10.100.0.0/16"]
[entryPoints.https.forwardedHeaders]
trustedIPs = ["10.100.0.0/16"]

入口对象:
apiVersion: extensions/v1beta1
kind: Ingress
metadata:
name: test-nginx
annotations:
kubernetes.io/ingress.class: "test-dev"
traefik.ingress.kubernetes.io/preserve-host: "true"
ingress.kubernetes.io/whitelist-x-forwarded-for: "true"
traefik.ingress.kubernetes.io/whitelist-source-range: "10.100.0.0/16"
spec:
rules:
- host: test-nginx.example.com
http:
paths:
- path: /
backend:
serviceName: nginx-headers
servicePort: 80

输出:
$ curl https://test-nginx.example.com/
Hostname: nginx-headers-5f544s5cc3-sl5c6
IP: 127.0.0.1
IP: 10.100.0.57
GET / HTTP/1.1
Host: test-nginx.example.com
User-Agent: curl/7.64.1
Accept: */*
Accept-Encoding: gzip
X-Forwarded-For: 54.31.147.124, 10.100.0.57
X-Forwarded-Host: test-nginx.example.com
X-Forwarded-Port: 443
X-Forwarded-Proto: https
X-Forwarded-Server: test-dev-traefik-7549d898bc-ttjf4
X-Real-Ip: 10.100.0.57

我在这里想念什么吗?任何帮助将不胜感激。

最佳答案

我知道这不是一个安全的解决方案,但至少您会看到Real IP并可以进行调试

[entryPoints.https.whiteList]
sourceRange = ["0.0.0.0/0"]
useXForwardedFor = true
[entryPoints.https.proxyProtocol]
trustedIPs = ["0.0.0.0/0"]
[entryPoints.https.forwardedHeaders]
trustedIPs = ["0.0.0.0/0]
和注释:
traefik.ingress.kubernetes.io/whitelist-source-range: "0.0.0.0/0"
它在Docker Swarm中对我有用

关于kubernetes - 在kubernetes上运行的traefik AWS ELB上的真实IP,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/60191981/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com