2

我正在通过 kubernetes 在 AWS 上运行 traefik。一切正常,除了我的 http=>https 重定向配置。

我有以下 .toml 文件

defaultEntryPoints = ["http", "https"]

[entryPoints]
  [entryPoints.http]
  address = ":80"
    [entryPoints.http.redirect]
      entryPoint = "https"

使用下面的 Kubernetes 部署 + 服务配置。

https 请求工作文件,但 http 请求返回:

> curl http://www.myserver.com
curl: (52) Empty reply from server

Kubernetes 配置文件:

kind: Deployment
apiVersion: extensions/v1beta1
metadata:
  name: traefik-proxy
  labels:
    app: traefik-proxy
    tier: proxy
spec:
  replicas: 1
  selector:
    matchLabels:
      app: traefik-proxy
      tier: proxy
  template:
    metadata:
      labels:
        app: traefik-proxy
        tier: proxy
    spec:
      terminationGracePeriodSeconds: 60

      # kubectl create configmap traefik-conf --from-file=./conf/k8s/traefik.toml
      volumes:
      - name: config
        configMap:
          name: traefik-conf

      containers:
      - image: traefik:v1.2.0-rc1-alpine
        name: traefik-proxy
        resources:
          limits:
            cpu: "200m"
            memory: "30Mi"
          requests:
            cpu: "100m"
            memory: "20Mi"
        volumeMounts:
        - mountPath: "/conf"
          name: config
        ports:
        - containerPort: 80
          hostPort: 80
          name: traefik-proxy
        - containerPort: 8080
          name: traefik-ui
        args:
        - --configFile=/conf/traefik.toml
        - --kubernetes
        - --web
---
apiVersion: v1
kind: Service
metadata:
  name: traefik-proxy
  annotations:
    # SSL certificate.
    # https://console.aws.amazon.com/acm (alienlabs.io)
    service.beta.kubernetes.io/aws-load-balancer-ssl-cert: "arn:aws:acm:us-east-1:861694698401:certificate/28204a9f-69ec-424d-8f56-ac085b7bdad8"
    service.beta.kubernetes.io/aws-load-balancer-backend-protocol: "http"
spec:
  type: LoadBalancer
  selector:
    app: traefik-proxy
    tier: proxy
  ports:
  - port: 80
    targetPort: 80
    name: http
  - port: 443
    targetPort: 80
    name: https
4

2 回答 2

1

我的traefik.toml配置与 Corey 的类似,但更简单一些。它适用于httpto的全面重定向https

defaultEntryPoints = ["http","https"]
[entryPoints]
  [entryPoints.http]
  address = ":80"
    [entryPoints.http.redirect]
      entryPoint = "https"
  [entryPoints.https]
  address = ":443"
于 2017-07-05T04:02:57.603 回答
0

您想稍微不同地说明您的入口点:

defaultEntryPoints = ["http","https"]
[entryPoints]
  [entryPoints.http]
  address = ":80"
    [entryPoints.http.redirect]
    regex = "^http://(.*)"
    replacement = "https://$1"
  [entryPoints.https]
  address = ":443"
于 2017-07-05T00:48:12.440 回答