VirtualServer ๋ฐ VirtualServerRoute ๋ฆฌ์์ค
VirtualServer ๋ฐ VirtualServerRoute ๋ฆฌ์์ค๋ Ingress ๋ฆฌ์์ค์ ๋์์ผ๋ก ๊ถ์ฅ๋๋ Load Balancing ๊ตฌ์ฑ์ ๋๋ค.
๋ฆด๋ฆฌ์ค 1.5์ ๋์ ๋ VirtualServer ๋ฐ VirtualServerRoute ๋ฆฌ์์ค๋ ํธ๋ํฝ ๋ถํ ๋ฐ ๊ณ ๊ธ ์ฝํ ์ธ ๊ธฐ๋ฐ ๋ผ์ฐํ ๊ณผ ๊ฐ์ด Ingress ๋ฆฌ์์ค์์ ์ง์๋์ง ์๋ ์ฌ์ฉ ์ฌ๋ก๋ฅผ ์ง์ํฉ๋๋ค. ๋ฆฌ์์ค๋ ์ฌ์ฉ์ ์ ์ ๋ฆฌ์์ค๋ก ๊ตฌํ๋ฉ๋๋ค.
์ด ๋ฌธ์๋ ๋ฆฌ์์ค์ ๋ํ ์ฐธ์กฐ ๋ฌธ์์ ๋๋ค. ํน์ ์ฌ์ฉ ์ฌ๋ก์ ๋ฆฌ์์ค๋ฅผ ์ฌ์ฉํ๋ ์ถ๊ฐ ์์ ๋ฅผ ๋ณด๋ ค๋ฉด GitHub Repo์ examples/custom-resources ํด๋๋ก ์ด๋ํ์ธ์.
๋ชฉ์ฐจ
1. VirtualServer ์ฌ์
1-1. VirtualServer.TLS
1-2. VirtualServer.TLS.Redirect
1-3. VirtualServer.TLS.CertManager
1-4. VirtualServer.ExternalDNS
1-5. VirtualServer.ExternalDNS.ProviderSpecific
1-6. VirtualServer.Policy
1-7. VirtualServer.Route
2. VirtualServerRoute ์ฌ์
2-1. VirtualServerRoute.Subroute
3. VirtualServer ๋ฐ VirtualServerRoute์ ๊ณตํต ๋ถ๋ถ
3-1. Upstream
3-2. Upstream.Buffers
3-3. Upstream.TLS
3-4. Upstream.Queue
3-5. Upstream.Healthcheck
3-6. Upstream.SessionCookie
3-7. Header
3-8. Action
3-9. Action.Redirect
3-10. Action.Return
3-11. Action.Proxy
3-12. Action.Proxy.RequestHeaders
3-13. Action.Proxy.RequestHeaders.Set.Header
3-14. Action.Proxy.ResponseHeaders
3-15. AddHeader
3-16. Split
3-17. Match
3-18. Condition
3-19. ErrorPage
3-20. ErrorPage.Redirect
3-21. ErrorPage.Return
3-22. ErrorPage.Return.Header
4.VirtualServer ๋ฐ VirtualServerRoute ์ฌ์ฉ
4-1. Snippets ์ฌ์ฉ
4-2. ๊ฒ์ฆ
4-3. ๊ตฌ์กฐ ๊ฒ์ฆ
4-4. ํฌ๊ด์ ๊ฒ์ฆ
5.ConfigMap์ ํตํ ์ฌ์ฉ์ ์ ์
1. VirtualServer ์ฌ์
VirtualServer ๋ฆฌ์์ค๋ example.com๊ณผ ๊ฐ์ ๋๋ฉ์ธ ์ด๋ฆ์ ๋ํ Load Balancing ๊ตฌ์ฑ์ ์ ์ํฉ๋๋ค. ๋ค์์ ์ด๋ฌํ ๊ตฌ์ฑ์ ์์
๋๋ค.
apiVersion: k8s.nginx.org/v1
kind: VirtualServer
metadata:
name: cafe
spec:
host: cafe.example.com
tls:
secret: cafe-secret
upstreams:
- name: tea
service: tea-svc
port: 80
- name: coffee
service: coffee-svc
port: 80
routes:
- path: /tea
action:
pass: tea
- path: /coffee
action:
pass: coffee
- path: ~ ^/decaf/.*\\.jpg$
action:
pass: coffee
- path: = /green/tea
action:
pass: tea
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
host | ์๋ฒ์ ํธ์คํธ(๋๋ฉ์ธ ์ด๋ฆ)์
๋๋ค. my-app ๋๋ hello.example.com๊ณผ ๊ฐ์ด RFC 1123์ ์ ์๋ ์ ํจํ ํ์ ๋๋ฉ์ธ์ด์ด์ผ ํฉ๋๋ค. *.example.com๊ณผ ๊ฐ์ ์์ผ๋ ์นด๋ ๋๋ฉ์ธ์ ์ฌ์ฉํ๋ ๊ฒฝ์ฐ ๋๋ฉ์ธ์ ํฐ๋ฐ์ดํ๋ก ๋ฌถ์ด์ผ ํฉ๋๋ค. host ๊ฐ์ ๋ชจ๋ Ingress ๋ฐ VirtualServer ๋ฆฌ์์ค์์ ๊ณ ์ ํด์ผ ํฉ๋๋ค. ํธ์คํธ ๋ฐ Listener ์ถฉ๋ ์ฒ๋ฆฌ๋ ์ฐธ์กฐํ์ธ์. | string | Yes |
tls | TLS termination ๊ตฌ์ฑ. | tls | No |
externalDNS | VirtualServer์ externalDNS ๊ตฌ์ฑ์ ๋๋ค. | externalDNS | No |
dos | DosProtectedResource์ ๋ํ ์ฐธ์กฐ๋ก ์ค์ ํ๋ฉด VirtualServer์ DOS ๋ณดํธ๊ฐ ํ์ฑํ๋ฉ๋๋ค. | string | No |
policies | ์ ์ฑ ๋ชฉ๋ก์ ๋๋ค. | []policy | No |
upstreams | Upstream ๋ชฉ๋ก์ ๋๋ค. | []upstream | No |
routes | ๋ฃจํธ ๋ชฉ๋ก์ ๋๋ค. | []route | No |
ingressClassName | VirtualServer ๋ฆฌ์์ค๋ฅผ ์ฒ๋ฆฌํด์ผ ํ๋ Ingress Controller๋ฅผ ์ง์ ํฉ๋๋ค. | string | No |
http-snippets | http Context์์ ์ฌ์ฉ์ ์ ์ snippet์ ์ค์ ํฉ๋๋ค. | string | No |
server-snippets | server Context์์ ์ฌ์ฉ์ ์ ์ snippet์ ์ค์ ํฉ๋๋ค. server-snippets ConfigMap Key๋ฅผ ์ฌ์ ์ํฉ๋๋ค. | string | No |
1-1. VirtualServer.TLS
tls ํ๋๋ VirtualServer์ ๋ํ TLS ๊ตฌ์ฑ์ ์ ์ํฉ๋๋ค. ์:
secret: cafe-secret
redirect:
enable: true
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
secret | TLS ์ธ์ฆ์ ๋ฐ Key๊ฐ ์๋ Secret์ ์ด๋ฆ์
๋๋ค. Secret๋ VirtualServer์ ๋์ผํ Namespace์ ์ํด์ผ ํฉ๋๋ค. ๋ณด์ Secret์ kubernetes.io/tls ์ ํ์ด์ด์ผ ํ๋ฉฐ ์ฌ๊ธฐ์ ์ค๋ช
๋ ์ธ์ฆ์์ ๊ฐ์ธ Key๋ฅผ ํฌํจํ๋ tls.crt ๋ฐ tls.key๋ผ๋ Key๋ฅผ ํฌํจํด์ผ ํฉ๋๋ค. Secret์ด ์กด์ฌํ์ง ์๊ฑฐ๋ ์ ํจํ์ง ์์ ๊ฒฝ์ฐ NGINX๋ VirtualServer์ ํธ์คํธ์ ๋ํ TLS ์ฐ๊ฒฐ์ ์ค์ ํ๋ ค๋ ๋ชจ๋ ์๋๋ฅผ ์ค๋จํฉ๋๋ค. Secret๊ฐ ์ง์ ๋์ง ์์์ง๋ง wildcard TLS secret๊ฐ ๊ตฌ์ฑ๋ ๊ฒฝ์ฐ NGINX๋ TLS Termination์ ์์ผ๋ ์นด๋ Secret๋ฅผ ์ฌ์ฉํฉ๋๋ค. | string | No |
redirect | VirtualServer์ ๋ํ TLS์ ๋ฆฌ๋ค์ด๋ ์ ๊ตฌ์ฑ์ ๋๋ค. | tls.redirect | No |
cert-manager | VirtualServer์ ๋ํ TLS์ cert-manager ๊ตฌ์ฑ์ ๋๋ค. | tls.cert-manager | No |
1-2. VirtualServer.TLS.Redirect
Redirect ํ๋๋ VirtualServer์ ๋ํ TLS Redirect์ ๊ตฌ์ฑํฉ๋๋ค.
enable: true
code: 301
basedOn: scheme
| Field | ์ค | Type | Required |
|---|---|---|---|
enable | VirtualServer์ ๋ํ TLS ๋ฆฌ๋ค์ด๋ ์
์ ํ์ฑํํฉ๋๋ค. ๊ธฐ๋ณธ๊ฐ์ False์
๋๋ค. | boolean | No |
code | ๋ฆฌ๋ค์ด๋ ์
์ ์ํ ์ฝ๋์
๋๋ค. ํ์ฉ๋๋ ๊ฐ์ 301 , 302 , 307 , 308์
๋๋ค. ๊ธฐ๋ณธ๊ฐ์ 301์
๋๋ค. | int | No |
basedOn | NGINX๊ฐ ๋ฆฌ๋ค์ด๋ ์
์ ์ ์กํ๊ธฐ ์ํด ํ๊ฐํ ์์ฒญ์ ์์ฑ์
๋๋ค. ํ์ฉ๋๋ ๊ฐ์ scheme(์์ฒญ์ scheme) ๋๋ x-forwarded-proto(์์ฒญ์ X-Forwarded-Proto ํค๋)์
๋๋ค. ๊ธฐ๋ณธ๊ฐ์ scheme์
๋๋ค. | string | No |
1-3. VirtualServer.TLS.CertManager
cert-manager ํ๋๋ cert-manager(cert-manager.io)๋ฅผ ์ฌ์ฉํ์ฌ VirtualServer ๋ฆฌ์์ค์ ๋ํ x509 ์๋ ์ธ์ฆ์ ๊ด๋ฆฌ๋ฅผ ๊ตฌ์ฑํฉ๋๋ค. ๋ฐ๊ธ์ ๋ฐฐํฌ ๋ฐ ๊ตฌ์ฑ์ ๋ํ ์์ธํ ๋ด์ฉ์ cert-manager ๊ตฌ์ฑ ์ค๋ช ์๋ฅผ ์ฐธ์กฐํ์ธ์. ์:
cert-manager:
cluster-issuer: "my-issuer-name"
| Field | Description | Type | Required |
|---|---|---|---|
issuer | Issuer์ ์ด๋ฆ. Issuer๋ ์ธ์ฆ์์ ์๋ช
ํ ์ ์๋ ์ธ์ฆ ๊ธฐ๊ด์ ์ค๋ช
ํ๋ ์ธ์ฆ์ ๊ด๋ฆฌ์ ๋ฆฌ์์ค์
๋๋ค. Issuer๋ VirtualServer ๋ฆฌ์์ค์ ๋์ผํ Namespace์ ์์ด์ผ ํฉ๋๋ค. issuer ๋ฐ cluster-issuer ์ค ํ๋๊ฐ ํ์ํ์ง๋ง ์ํธ ๋ฐฐํ์ ์ด๋ฏ๋ก ํ๋๋ง ์ ์ํด์ผ ํฉ๋๋ค. | string | No |
cluster-issuer | ClusterIssuer์ ์ด๋ฆ. ClusterIssuer๋ ์ธ์ฆ์์ ์๋ช
ํ ์ ์๋ ์ธ์ฆ ๊ธฐ๊ด์ ์ค๋ช
ํ๋ ์ธ์ฆ์ ๊ด๋ฆฌ์ ๋ฆฌ์์ค์
๋๋ค. ClusterIssuer๋ Namespace๊ฐ ์๋ ๋ฆฌ์์ค์ด๋ฏ๋ก VirtualServer๊ฐ ์์ฃผํ๋ Namespace๋ ์ค์ํ์ง ์์ต๋๋ค. ๋ฐ cluster-issuer ์ค ํ๋๊ฐ ํ์ํ์ง๋ง ์ํธ ๋ฐฐํ์ ์ด๋ฏ๋ก ํ๋๋ง ์ ์ํด์ผ ํฉ๋๋ค. | string | No |
issuer-kind | ์ธ๋ถ Issuer ๋ฆฌ์์ค์ ์ข
๋ฅ(์: AWSPCAIssuer)์
๋๋ค. ์ด๋ ํธ๋ฆฌ ์ธ๋ถ Issuer์๊ฒ๋ง ํ์ํฉ๋๋ค. ๋ ์ ์๋ ๊ฒฝ์ฐ์๋ ์ ์ํ ์ ์์ต๋๋ค. | string | No |
issuer-group | ์ธ๋ถ Issuer Controller์ API ๊ทธ๋ฃน(์: awspca.cert-manager.io)์
๋๋ค. ์ด๋ ํธ๋ฆฌ ์ธ๋ถ Issuer์๊ฒ๋ง ํ์ํฉ๋๋ค. ๋ ์ ์๋ ๊ฒฝ์ฐ์๋ ์ ์ํ ์ ์์ต๋๋ค. | string | No |
common-name | ์ด ํ๋๋ฅผ ์ฌ์ฉํ๋ฉด ์์ฑํ ์ธ์ฆ์์ ๋ํ spec.commonName์ ๊ตฌ์ฑํ ์ ์์ต๋๋ค. ์ด ๊ตฌ์ฑ์ x509 ์ธ์ฆ์์ CN์ ์ถ๊ฐํฉ๋๋ค. | string | No |
duration | ์ด ํ๋์์๋ ์์ฑํ ์ธ์ฆ์์ ๋ํ spec.duration ํ๋๋ฅผ ๊ตฌ์ฑํ ์ ์์ต๋๋ค. Go time.Duration ๋ฌธ์์ด ํ์์ ์ฌ์ฉํ์ฌ ์ง์ ํด์ผ ํ๋ฉฐ d(์ผ) ์ ๋ฏธ์ฌ๋ฅผ ํ์ฉํ์ง ์์ต๋๋ค. ๋์ s, m ๋ฐ h ์ ๋ฏธ์ฌ๋ฅผ ์ฌ์ฉํ์ฌ ์ด๋ฌํ ๊ฐ์ ์ง์ ํด์ผ ํฉ๋๋ค. | string | No |
renew-before | ์ด Annotation์ ์ฌ์ฉํ๋ฉด ์์ฑํ ์ธ์ฆ์์ ๋ํ spec.renewBefore ํ๋๋ฅผ ๊ตฌ์ฑํ ์ ์์ต๋๋ค. Go time.Duration ๋ฌธ์์ด ํ์์ ์ฌ์ฉํ์ฌ ์ง์ ํด์ผ ํ๋ฉฐ d(์ผ) ์ ๋ฏธ์ฌ๋ฅผ ํ์ฉํ์ง ์์ต๋๋ค. ๋์ s, m ๋ฐ h ์ ๋ฏธ์ฌ๋ฅผ ์ฌ์ฉํ์ฌ ์ด๋ฌํ ๊ฐ์ ์ง์ ํด์ผ ํฉ๋๋ค. | string | No |
usages | ์ด ํ๋๋ฅผ ์ฌ์ฉํ๋ฉด ์์ฑํ ์ธ์ฆ์์ ๋ํ spec.usages ํ๋๋ฅผ ๊ตฌ์ฑํ ์ ์์ต๋๋ค. ์ผํ๋ก ๊ตฌ๋ถ๋ ๊ฐ(์: key agreement, digital signature, server auth)์ด ์๋ ๋ฌธ์์ด์ ์ ๋ฌํฉ๋๋ค. ์ง์๋๋ Key ์ฌ์ฉ์ ์ ์ฒด ๋ชฉ๋ก์ cert-manager api ๋ฌธ์์์ ์ฐพ์ ์ ์์ต๋๋ค. | string | No |
1-4. VirtualServer.ExternalDNS
externalDNS ํ๋๋ ExternalDNS๋ฅผ ์ฌ์ฉํ์ฌ VirtualServer ๋ฆฌ์์ค์ ๋ํด DNS ๋ ์ฝ๋๋ฅผ ๋์ ์ผ๋ก ์ ์ดํ๋๋ก ๊ตฌ์ฑํฉ๋๋ค. ExternalDNS ๋ฐ ๊ณต๊ธ์ ๋ฐฐํฌ ๋ฐ ๊ตฌ์ฑ์ ๋ํ ์์ธํ ๋ด์ฉ์ ExternalDNS ๊ตฌ์ฑ ์ค๋ช ์๋ฅผ ์ฐธ์กฐํ์ญ์์ค. ์์:
enable: true
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
enable | VirtualServer ๋ฆฌ์์ค์ ๋ํ ExternalDNS ํตํฉ์ ํ์ฑํํฉ๋๋ค. ๊ธฐ๋ณธ๊ฐ์ false์
๋๋ค. | string | No |
labels | ExternalDNS์์ ์ฌ์ฉํ Endpoint ๋ฆฌ์์ค์ ์ ์ฉํ Label์ ๊ตฌ์ฑํฉ๋๋ค. | map[string]string | No |
providerSpecific | ๊ฐ๋ณ DNS ๊ณต๊ธ์์ ํน์ ํ ๊ตฌ์ฑ์ ์ด๋ฆ๊ณผ ๊ฐ์ ๋ณด์ ํ๋ ๊ณต๊ธ์๋ณ ์์ฑ์ ๊ตฌ์ฑํฉ๋๋ค. | []ProviderSpecific | No |
recordTTL | DNS ๋ ์ฝ๋์ฉ TTL์ ๋๋ค. ์ ์๋์ง ์์ ๊ฒฝ์ฐ ๊ธฐ๋ณธ๊ฐ์ 0์ ๋๋ค. ์ ์ฒด๋ณ ๊ธฐ๋ณธ๊ฐ์ ExternalDNS TTL ๋ฌธ์๋ฅผ ์ฐธ์กฐํ์ธ์. | int64 | No |
recordType | ์์ฑํด์ผ ํ๋ ๋ ์ฝ๋ ์ ํ์ ๋๋ค. ์: “A”, “AAAA”, “CNAME”. ์ ์๋์ง ์์ ๊ฒฝ์ฐ ์ธ๋ถ Endpoint๋ฅผ ๊ธฐ๋ฐ์ผ๋ก ์๋์ผ๋ก ๊ณ์ฐ๋ฉ๋๋ค. | string | No |
1-5. VirtualServer.ExternalDNS.ProviderSpecific
externalDNS ๋ธ๋ก์ providerSpecific ํ๋๋ฅผ ์ฌ์ฉํ๋ฉด ๊ฐ๋ณ DNS ์ ๊ณต์์ ๊ณ ์ ํ ๊ตฌ์ฑ์ Key Value ์ ๋ชฉ๋ก์ธ ์ ๊ณต์ ํน์ ์์ฑ์ ์ง์ ํ ์ ์์ต๋๋ค. ์:
- name: my-name
value: my-value
- name: my-name2
value: my-value2
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
name | Key Value ์์ name์ ๋๋ค. | string | Yes |
value | Key Value ์์ value์ ๋๋ค. | string | Yes |
1-6. VirtualServer.Policy
policy ํ๋๋ ์ด๋ฆ๊ณผ ์ ํ์ Namespace๋ก ์ ์ฑ ๋ฆฌ์์ค๋ฅผ ์ฐธ์กฐํฉ๋๋ค. ์:
name: access-control
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
name | ์ ์ฑ
์ ์ด๋ฆ์
๋๋ค. ์ ์ฑ
์ด ์กด์ฌํ์ง ์๊ฑฐ๋ ์ ํจํ์ง ์์ ๊ฒฝ์ฐ NGINX๋ 500 ์ํ ์ฝ๋๊ฐ ํฌํจ๋ ์ค๋ฅ ์๋ต์ผ๋ก ์๋ตํฉ๋๋ค. | string | Yes |
namespace | ์ ์ฑ ์ Namespace์ ๋๋ค. ์ง์ ํ์ง ์์ผ๋ฉด VirtualServer ๋ฆฌ์์ค์ Namespace๊ฐ ์ฌ์ฉ๋ฉ๋๋ค. | string | No |
1-7. VirtualServer.Route
Route๋ ์์ฒญ์ Upstream์ ์ ๋ฌํ๋ ๊ฒ๊ณผ ๊ฐ์ ์์ ์ ํด๋ผ์ด์ธํธ ์์ฒญ์ ์ผ์น์ํค๋ ๊ท์น์ ์ ์ํฉ๋๋ค. ์:
path: /tea
action:
pass: tea
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
path | route์ ๊ฒฝ๋ก์
๋๋ค. NGINX๋ ์์ฒญ์ URI์ ์ผ์น์ํต๋๋ค. ๊ฐ๋ฅํ ๊ฐ์ ๋ค์๊ณผ ๊ฐ์ต๋๋ค. ์ ๋์ฌ( / , /path ), ์ ํํ ์ผ์น( =/exact/match ), ๋์๋ฌธ์๋ฅผ ๊ตฌ๋ถํ์ง ์๋ ์ ๊ท์(~*^/Bar.*\.jpg ) ๋๋ ๋์๋ฌธ์๋ฅผ ๊ตฌ๋ถํ๋ ์ ๊ท์(~^/foo.*\.jpg ). ์ ๋์ฌ(/๋ก ์์ํด์ผ ํจ) ๋๋ ์ ํํ ์ผ์น(=๋ก ์์ํด์ผ ํจ)์ ๊ฒฝ์ฐ ๊ฒฝ๋ก์ ๊ณต๋ฐฑ ๋ฌธ์({ , } ๋๋ ;)๊ฐ ํฌํจ๋์ด์๋ ์ ๋ฉ๋๋ค. ์ ๊ท์ ์ผ์น์ ๊ฒฝ์ฐ ๋ชจ๋ ํฐ๋ฐ์ดํ๋ " ์ด์ค์ผ์ดํ๋์ด์ผ ํ๋ฉฐ ์ผ์น๋ ์ด์ค์ผ์ดํ ์ฒ๋ฆฌ๋์ง ์์ ๋ฐฑ์ฌ๋์ \๋ก ๋๋ ์ ์์ต๋๋ค. ๊ฒฝ๋ก๋ VirtualServer์ ๋ชจ๋ ๊ฒฝ๋ก ๊ฒฝ๋ก ์ค์์ ๊ณ ์ ํด์ผ ํฉ๋๋ค. ์์ธํ ๋ด์ฉ์ location ์ง์๋ฌธ์ ํ์ธํ์ธ์. . | string | Yes |
policies | ์ ์ฑ
๋ชฉ๋ก์
๋๋ค. ์ ์ฑ
์ VirtualServer์ ์ ์ ์๋ ๋์ผํ ์ ํ์ ์ ์ฑ
์ ์ฌ์ ์ํฉ๋๋ค. ์์ธํ ๋ด์ฉ์ ์ ์ฑ
์ ์ฉ์ ์ฐธ์กฐํ์ธ์. | []policy | No |
action | ์์ฒญ์ ๋ํด ์ํํ ๊ธฐ๋ณธ ์์ ์ ๋๋ค. | action | No |
dos | DosProtectedResource์ ๋ํ ์ฐธ์กฐ๋ก ์ค์ ํ๋ฉด VirtualServer ๊ฒฝ๋ก์ DOS ๋ณดํธ๊ฐ ํ์ฑํ๋ฉ๋๋ค. | string | No |
splits | ํธ๋ํฝ ๋ถํ ์ ์ํ ๊ธฐ๋ณธ ๋ถํ ๊ตฌ์ฑ์ ๋๋ค. ์ต์ 2๊ฐ์ ๋ถํ ์ ํฌํจํด์ผ ํฉ๋๋ค. | []split | No |
matches | ๊ณ ๊ธ ์ฝํ
์ธ ๊ธฐ๋ฐ ๋ผ์ฐํ
์ ์ํ ์ผ์น ๊ท์น์
๋๋ค. ๊ธฐ๋ณธ actionย ๋๋ splits์ด ํ์ํฉ๋๋ค. ์ผ์นํ์ง ์๋ ์์ฒญ์ ๊ธฐ๋ณธ actionย ๋๋ splits๋ก ์ฒ๋ฆฌ๋ฉ๋๋ค. | matches | No |
route | ์ด ๊ฒฝ๋ก๋ฅผ ์ ์ํ๋ VirtualServerRoute ๋ฆฌ์์ค์ ์ด๋ฆ์
๋๋ค. VirtualServerRoute๊ฐ VirtualServer์ ๋ค๋ฅธ Namespace์ ์ํ๋ ๊ฒฝ์ฐ Namespace๋ฅผ ํฌํจํด์ผ ํฉ๋๋ค. ์: tea-namespace/tea. | string | No |
errorPages | ์ค๋ฅ ์ฝ๋์ ๋ํ ์ฌ์ฉ์ ์ ์ ์๋ต์ ๋๋ค. NGINX๋ Upstream ์๋ฒ์ ์ค๋ฅ ์๋ต์ด๋ NGINX์์ ์์ฑํ ๊ธฐ๋ณธ ์๋ต์ ๋ฐํํ๋ ๋์ ํด๋น ์๋ต์ ์ฌ์ฉํฉ๋๋ค. ์ฌ์ฉ์ ์ ์ ์๋ต์ ๋ฆฌ๋ค์ด๋ ์ ๋๋ ๋ฏธ๋ฆฌ ์ค๋น๋ ์๋ต์ผ ์ ์์ต๋๋ค. ์๋ฅผ ๋ค์ด Upstream ์๋ฒ๊ฐ 404 ์ํ ์ฝ๋๋ก ์๋ตํ ๊ฒฝ์ฐ ๋ค๋ฅธ URL๋ก ๋ฆฌ๋ค์ด๋ ์ ํฉ๋๋ค. | []errorPage | No |
location-snippets | location Context์์ ๋ง์ถค Snippet์ ์ค์ ํฉ๋๋ค. location-snippets ConfigMap Key๋ฅผ ์ฌ์ ์ํฉ๋๋ค. | string | No |
* โ ๊ฒฝ๋ก์๋ action, splits ๋๋ route ์ค ํ๋๋ฅผ ์ ํํ ํฌํจํด์ผ ํฉ๋๋ค.
2. VirtualServerRoute ์ฌ์
VirtualServerRoute ๋ฆฌ์์ค๋ VirtualServer์ ๋ํ ๊ฒฝ๋ก๋ฅผ ์ ์ํฉ๋๋ค. ํ๋ ๋๋ ์ฌ๋ฌ ํ์ ๊ฒฝ๋ก๋ก ๊ตฌ์ฑ๋ ์ ์์ต๋๋ค. VirtualServerRoute๋ Mergeable Ingress Type์ ๋์์ ๋๋ค.
์๋ ์์์ Namespace cafe-ns์ VirtualServer cafa๋ ๊ฒฝ๋ก /coffee๊ฐ ์๋ ๊ฒฝ๋ก๋ฅผ ์ ์ํ๋ฉฐ, ์ด๋ Namespace coffee-ns์ VirtualServerRoute coffee์์ ์ถ๊ฐ๋ก ์ ์๋ฉ๋๋ค.
VirtualServer:
apiVersion: k8s.nginx.org/v1
kind: VirtualServer
metadata:
name: cafe
namespace: cafe-ns
spec:
host: cafe.example.com
upstreams:
- name: tea
service: tea-svc
port: 80
routes:
- path: /tea
action:
pass: tea
- path: /coffee
route: coffee-ns/coffee
VirtualServerRoute:
apiVersion: k8s.nginx.org/v1
kind: VirtualServerRoute
metadata:
name: coffee
namespace: coffee-ns
spec:
host: cafe.example.com
upstreams:
- name: latte
service: latte-svc
port: 80
- name: espresso
service: espresso-svc
port: 80
subroutes:
- path: /coffee/latte
action:
pass: latte
- path: /coffee/espresso
action:
pass: espresso
๊ฐ ํ์ path์๋ VirtualServer์ ๊ฒฝ๋ก์ ์ ์๋ ๋์ผํ ์ ๋์ฌ(์ฌ๊ธฐ์๋ /coffee)๋ก ์์ํ๋ Route๊ฐ ์์ด์ผ ํฉ๋๋ค. ๋ํ VirtualServerRoute์ ๋ VirtualServer์ host์ ๋์ผํด์ผ ํฉ๋๋ค.host
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
host | ์๋ฒ์ ํธ์คํธ(๋๋ฉ์ธ ์ด๋ฆ)์
๋๋ค. my-app ๋๋ hello.example.com๊ณผ ๊ฐ์ด RFC 1123์ ์ ์๋ ์ ํจํ ํ์ ๋๋ฉ์ธ์ด์ด์ผ ํฉ๋๋ค. *.example.com๊ณผ ๊ฐ์ ์์ผ๋ ์นด๋ ๋๋ฉ์ธ์ ์ฌ์ฉํ๋ ๊ฒฝ์ฐ ๋๋ฉ์ธ์ ํฐ๋ฐ์ดํ๋ก ๋ฌถ์ด์ผ ํฉ๋๋ค. ์ด ๋ฆฌ์์ค๋ฅผ ์ฐธ์กฐํ๋ VirtualServer์ host์ ๋์ผํด์ผ ํฉ๋๋ค. | string | Yes |
upstreams | Upstreams ๋ชฉ๋ก์ ๋๋ค. | []upstream | No |
subroutes | ํ์ ๊ฒฝ๋ก ๋ชฉ๋ก์ ๋๋ค. | []subroute | No |
ingressClassName | VirtualServerRoute ๋ฆฌ์์ค๋ฅผ ์ฒ๋ฆฌํด์ผ ํ๋ Ingress Controller๋ฅผ ์ง์ ํฉ๋๋ค. ์ด ๋ฆฌ์์ค๋ฅผ ์ฐธ์กฐํ๋ VirtualServer์ ingressClassName๊ณผ ๋์ผํด์ผ ํฉ๋๋ค. | string_ | No |
2-1. VirtualServerRoute.Subroute
ํ์ ๊ฒฝ๋ก๋ ํด๋ผ์ด์ธํธ ์์ฒญ์ Upstream์ ์ ๋ฌํ๋ ๊ฒ๊ณผ ๊ฐ์ ์์ ์ ์ผ์น์ํค๋ ๊ท์น์ ์ ์ํฉ๋๋ค. ์:
path: /coffee
action:
pass: coffee
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
path | subroute์ path์
๋๋ค. NGINX๋ ์์ฒญ์ URI์ ์ผ์น์ํต๋๋ค. ๊ฐ๋ฅํ ๊ฐ์ ๋ค์๊ณผ ๊ฐ์ต๋๋ค. ์ ๋์ฌ( / , /path ), ์ ํํ ์ผ์น( =/exact/match ), ๋์๋ฌธ์๋ฅผ ๊ตฌ๋ถํ์ง ์๋ ์ ๊ท์( ย ~*^/Bar.*\.jp ) ๋๋ ๋์๋ฌธ์๋ฅผ ๊ตฌ๋ถํ๋ ์ ๊ท์(ย ~^/foo.*\.jpg ). ์ ๋์ฌ์ ๊ฒฝ์ฐ ๊ฒฝ๋ก๋ ์ด ๋ฆฌ์์ค๋ฅผ ์ฐธ์กฐํ๋ VirtualServer์ route path์ ๋์ผํ path๋ก ์์ํด์ผ ํฉ๋๋ค. ์ ํํ ์ผ์น ๋๋ ์ ๊ท์ ์ผ์น์ ๊ฒฝ์ฐ ๊ฒฝ๋ก๋ ์ด ๋ฆฌ์์ค๋ฅผ ์ฐธ์กฐํ๋ VirtualServer์ route path์ ๋์ผํด์ผ ํฉ๋๋ค. ์ ๋์ฌ ๋๋ ์ ํํ ์ผ์นํ๋ ๊ฒฝ์ฐ path์ ๊ณต๋ฐฑ ๋ฌธ์({ , } ๋๋ ;)๊ฐ ํฌํจ๋์ด์๋ ์ ๋ฉ๋๋ค. ์ ๊ท์ ์ผ์น์ ๊ฒฝ์ฐ ๋ชจ๋ ํฐ๋ฐ์ดํ " ๋ ์ด์ค์ผ์ดํ๋์ด์ผ ํ๋ฉฐ ์ผ์น๋ ์ด์ค์ผ์ดํ ์ฒ๋ฆฌ๋์ง ์์ ๋ฐฑ์ฌ๋์ \๋ก ๋๋ ์ ์์ต๋๋ค. path๋ VirtualServerRoute์ ๋ชจ๋ ํ์ path์์ ๊ณ ์ ํด์ผ ํฉ๋๋ค. | string | Yes |
policies | ์ ์ฑ
๋ชฉ๋ก์
๋๋ค. ์ ์ฑ
์ ์ด ๋ฆฌ์์ค๋ฅผ ์ฐธ์กฐํ๋ VirtualServer์ ๊ฒฝ๋ก์ ์ ์๋ ๋ชจ๋ ์ ์ฑ
์ ์ฌ์ ์ํฉ๋๋ค. ์ ์ฑ
์ ๋ํ VirtualServer์ spec์ ์ ์๋ ๋์ผํ ์ ํ์ ์ ์ฑ
์ ์ฌ์ ์ํฉ๋๋ค. ์์ธํ ๋ด์ฉ์ ์ ์ฑ
์ ์ฉ์ ์ฐธ์กฐํ์ธ์. | []policy | No |
action | ์์ฒญ์ ๋ํด ์ํํ ๊ธฐ๋ณธ ์์ ์ ๋๋ค. | action | No |
dos | DosProtectedResource์ ๋ํ ์ฐธ์กฐ๋ก ์ด๋ฅผ ์ค์ ํ๋ฉด VirtualServerRoute ํ์ ๊ฒฝ๋ก์ DOS ๋ณดํธ๊ฐ ํ์ฑํ๋ฉ๋๋ค. | string | No |
splits | ํธ๋ํฝ ๋ถํ ์ ์ํ ๊ธฐ๋ณธ ๋ถํ ๊ตฌ์ฑ์ ๋๋ค. ์ต์ 2๊ฐ์ ๋ถํ ์ ํฌํจํด์ผ ํฉ๋๋ค. | []split | No |
matches | ๊ณ ๊ธ ์ฝํ
์ธ ๊ธฐ๋ฐ ๋ผ์ฐํ
์ ์ํ ์ผ์น ๊ท์น์
๋๋ค. ๊ธฐ๋ณธ action ๋๋ splits์ด ํ์ํฉ๋๋ค. ์ผ์นํ์ง ์๋ ์์ฒญ์ ๊ธฐ๋ณธ action ๋๋ splits๋ก ์ฒ๋ฆฌ๋ฉ๋๋ค. | matches | No |
errorPages | ์ค๋ฅ ์ฝ๋์ ๋ํ ์ฌ์ฉ์ ์ ์ ์๋ต์ ๋๋ค. NGINX๋ Upstream ์๋ฒ์ ์ค๋ฅ ์๋ต์ด๋ NGINX์์ ์์ฑํ ๊ธฐ๋ณธ ์๋ต์ ๋ฐํํ๋ ๋์ ํด๋น ์๋ต์ ์ฌ์ฉํฉ๋๋ค. ์ฌ์ฉ์ ์ ์ ์๋ต์ ๋ฆฌ๋ค์ด๋ ์ ๋๋ ๋ฏธ๋ฆฌ ์ค๋น๋ ์๋ต์ผ ์ ์์ต๋๋ค. ์๋ฅผ ๋ค์ด Upstream ์๋ฒ๊ฐ 404 ์ํ ์ฝ๋๋ก ์๋ตํ ๊ฒฝ์ฐ ๋ค๋ฅธ URL๋ก ๋ฆฌ๋ค์ด๋ ์ ํฉ๋๋ค. | []errorPage | No |
location-snippets | ์์น Context์์ ๋ง์ถค Snippet์ ์ค์ ํฉ๋๋ค. VirtualServer(์ค์ ๋ ๊ฒฝ์ฐ)์ location-snippets ๋๋ location-snippets ConfigMap Key๋ฅผ ์ฌ์ ์ํฉ๋๋ค. | string | No |
* โ ํ์ ๊ฒฝ๋ก๋ action ๋๋ splits ์ค ํ๋๋ฅผ ํฌํจํด์ผ ํฉ๋๋ค.
3. VirtualServer ๋ฐ VirtualServerRoute์ ๊ณตํต ๋ถ๋ถ
3-1. Upstream
Upstream์ ๋ผ์ฐํ ๊ตฌ์ฑ์ ๋์์ ์ ์ํฉ๋๋ค. ์:
name: tea
service: tea-svc
subselector:
version: canary
port: 80
lb-method: round_robin
fail-timeout: 10s
max-fails: 1
max-conns: 32
keepalive: 32
connect-timeout: 30s
read-timeout: 30s
send-timeout: 30s
next-upstream: "error timeout non_idempotent"
next-upstream-timeout: 5s
next-upstream-tries: 10
client-max-body-size: 2m
tls:
enable: true
Note: WebSocket ํ๋กํ ์ฝ์ ์ถ๊ฐ ๊ตฌ์ฑ ์์ด ์ง์๋ฉ๋๋ค.
| Field | Description | Type | Required |
|---|---|---|---|
name | Upstream์ ์ด๋ฆ์
๋๋ค. RFC 1035์ ์ ์๋ ์ ํจํ DNS Label์ด์ด์ผ ํฉ๋๋ค. ์๋ฅผ ๋ค์ด hello ๋ฐ upstream-123์ ์ ํจํฉ๋๋ค. ์ด๋ฆ์ ๋ฆฌ์์ค์ ๋ชจ๋ Upstream์์ ๊ณ ์ ํด์ผ ํฉ๋๋ค. | string | Yes |
service | ์๋น์ค์ ์ด๋ฆ์
๋๋ค. ์๋น์ค๋ ๋ฆฌ์์ค์ ๋์ผํ Namespace์ ์ํด์ผ ํฉ๋๋ค. ์๋น์ค๊ฐ ์กด์ฌํ์ง ์๋ ๊ฒฝ์ฐ NGINX๋ ์๋น์ค์ Endpoint๊ฐ ์๋ค๊ณ ๊ฐ์ ํ๊ณ ์ด Upstream์ ๋ํ ์์ฒญ์ ๋ํด 502 ์๋ต์ ๋ฐํํฉ๋๋ค. NGINX Plus์ ๊ฒฝ์ฐ์๋ง ExternalName ์ ํ์ ์๋น์ค๋ ์ง์๋ฉ๋๋ค(์ ์ ์กฐ๊ฑด ํ์ธ). | string | Yes |
subselector | Label Key์ ๊ฐ์ ์ฌ์ฉํ์ฌ ์๋น์ค ๋ด์ Pod๋ฅผ ์ ํํฉ๋๋ค. ๊ธฐ๋ณธ์ ์ผ๋ก ์๋น์ค์ ๋ชจ๋ Pod๊ฐ ์ ํ๋ฉ๋๋ค. Note: ์ง์ ๋ Label์ ์์ฑ๋ ๋ Pod์ ์์ด์ผ ํฉ๋๋ค. Pod Label์ด ์ ๋ฐ์ดํธ๋๋ฉด Ingress Controller๋ Pod ์๊ฐ ๋ณ๊ฒฝ๋ ๋๊น์ง ํด๋น ๋ณ๊ฒฝ ์ฌํญ์ ํ์ธํ์ง ์์ต๋๋ค. | map[string]string | No |
use-cluster-ip | Pod์ IP ๋ฐ ํฌํธ๋ฅผ ์ฌ์ฉํ๋ ๊ธฐ๋ณธ ๋์ ๋์ ์๋น์ค์ ํด๋ฌ์คํฐ IP ๋ฐ ํฌํธ๋ฅผ ์ฌ์ฉํ๋๋ก ์ค์ ํฉ๋๋ค. ์ด ํ๋๊ฐ ํ์ฑํ๋๋ฉด Ingress Controller๊ฐ ์๋น์ค ํด๋ฌ์คํฐ IP์ ์ผ์นํ๋ ํ๋์ Upstream ์๋ฒ๋ก๋ง NGINX๋ฅผ ๊ตฌ์ฑํ๋ฏ๋ก ์ฌ๋ฌ Upstream ์๋ฒ์ ๊ด๋ จ๋ NGINX ๋์์ ๊ตฌ์ฑํ๋ ํ๋(์: lb-method ๋ฐ next-upstream)๋ ์ํฅ์ ๋ฏธ์น์ง ์์ต๋๋ค. | boolean | No |
port | ์๋น์ค์ ํฌํธ์
๋๋ค. ์๋น์ค๊ฐ ํด๋น ํฌํธ๋ฅผ ์ ์ํ์ง ์์ผ๋ฉด NGINX๋ ์๋น์ค์ Endpoint๊ฐ ์๋ค๊ณ ๊ฐ์ ํ๊ณ ์ด Upstream์ ๋ํ ์์ฒญ์ ๋ํด 502 ์๋ต์ ๋ฐํํฉ๋๋ค. ํฌํธ๋ 1..65535 ๋ฒ์์ ์ํด์ผ ํฉ๋๋ค. | uint16 | Yes |
lb-method | Load Balancing ๋งค์๋์
๋๋ค. ๋ผ์ด๋ ๋ก๋น ๋ฐฉ๋ฒ์ ์ฌ์ฉํ๋ ค๋ฉด round_robin์ ์ง์ ํ์ธ์. ๊ธฐ๋ณธ๊ฐ์ lb-method ConfigMap Key์ ์ง์ ๋ฉ๋๋ค. | string | No |
fail-timeout | ์๋ฒ๋ฅผ ์ฌ์ฉํ ์ ์๋ ๊ฒ์ผ๋ก ๊ฐ์ฃผํ๊ธฐ ์ํด Upstream ์๋ฒ์์ ํต์ ์ ์๋ํ๋๋ฐ ์ง์ ๋ ํ์๋งํผ ์คํจํ ์๊ฐ์
๋๋ค. sever ์ง์๋ฌธ์ fail_timeout ๋งค๊ฐ๋ณ์๋ฅผ ์ฐธ์กฐํ์ธ์. ๊ธฐ๋ณธ๊ฐ์ fail-timeout ConfigMap Key์ ์ค์ ๋์ด ์์ต๋๋ค. | string | No |
max-fails | ์๋ฒ๋ฅผ ์ฌ์ฉํ ์ ์๋ค๊ณ ๊ฐ์ฃผํ๊ธฐ ์ํด fail-timeout ์์ ์ค์ ํ ๊ธฐ๊ฐ ๋ด์ ๋ฐ์ํด์ผ ํ๋ Pustream ์๋ฒ์์ ํต์ ์๋ ์คํจ ํ์์
๋๋ค. server ์ง์๋ฌธ์ max_fails ๋งค๊ฐ๋ณ์๋ฅผ ์ฐธ์กฐํ์ธ์. ๊ธฐ๋ณธ๊ฐ์ max-fails ConfigMap Key์ ์ค์ ๋์ด ์์ต๋๋ค. | int | No |
max-conns | Upstream ์๋ฒ์ ๋ํ ์ต๋ ๋์ ํ์ฑ ์ฐ๊ฒฐ ์์
๋๋ค. server ์ง์๋ฌธ์ max_conns ๋งค๊ฐ๋ณ์๋ฅผ ์ฐธ์กฐํ์ธ์. ๊ธฐ๋ณธ์ ์ผ๋ก ์ ํ์ด ์์ต๋๋ค. Note: keepalive ์ฐ๊ฒฐ์ด ํ์ฑํ๋ ๊ฒฝ์ฐ Upstream ์๋ฒ์ ๋ํ ์ด ํ์ฑ ๋ฐ ์ ํด keepalive ์ฐ๊ฒฐ ์๊ฐ max_conns ๊ฐ์ ์ด๊ณผํ ์ ์์ต๋๋ค. | int | No |
keepalive | Upstream ์๋ฒ์ ์ฐ๊ฒฐํ๊ธฐ ์ํ ์บ์๋ฅผ ๊ตฌ์ฑํฉ๋๋ค. ์บ์ ๊ฐ์ 0์ผ๋ก ์ฌ์ฉํ์ง ์๋๋ก ์ค์ ํฉ๋๋ค. keepalive ์ง์๋ฌธ์ ์ฐธ์กฐํ์ธ์. ๊ธฐ๋ณธ๊ฐ์ Keepailive ConfigMap Key์ ์ค์ ๋์ด ์์ต๋๋ค. | int | No |
connect-timeout | Upstream ์๋ฒ์์ ์ฐ๊ฒฐ์ ์ค์ ํ๊ธฐ ์ํ ์ ํ ์๊ฐ์
๋๋ค. proxy_connect_timeout ์ง์๋ฌธ์ ์ฐธ์กฐํ์ธ์. ๊ธฐ๋ณธ๊ฐ์ proxy-connect-timeout ConfigMap Key์ ์ง์ ๋ฉ๋๋ค. | string | No |
read-timeout | Upstream ์๋ฒ์์ ์๋ต์ ์ฝ๊ธฐ ์ํ ์ ํ ์๊ฐ์
๋๋ค. proxy_read_timeout ์ง์๋ฌธ์ ์ฐธ์กฐํ์ธ์. ๊ธฐ๋ณธ๊ฐ์ proxy-read-timeout ConfigMap Key์ ์ง์ ๋ฉ๋๋ค. | string | No |
send-timeout | Upstream ์๋ฒ๋ก ์์ฒญ์ ์ ์กํ๊ธฐ ์ํ ์ ํ ์๊ฐ์
๋๋ค. proxy_send_timeout ์ง์๋ฌธ์ ์ฐธ์กฐํ์ธ์. ๊ธฐ๋ณธ๊ฐ์ proxy-send-timeout ConfigMap Key์ ์ง์ ๋ฉ๋๋ค. | string | No |
next-upstream | ์์ฒญ์ ๋ค์ Upstream ์๋ฒ๋ก ์ ๋ฌํ ๊ฒฝ์ฐ๋ฅผ ์ง์ ํฉ๋๋ค. proxy_next_upstream ์ง์๋ฌธ์ ์ฐธ์กฐํ์ธ์. ๊ธฐ๋ณธ๊ฐ์ error timeout์
๋๋ค. | string | No |
next-upstream-timeout | ์์ฒญ์ด ๋ค์ Upstream ์๋ฒ๋ก ์ ๋ฌ๋ ์ ์๋ ์๊ฐ์
๋๋ค. proxy_next_upstream_timeout ์ง์๋ฌธ์ ์ฐธ์กฐํ์ธ์. 0 ๊ฐ์ ์๊ฐ ์ ํ์ ๋๋๋ค. ๊ธฐ๋ณธ๊ฐ์ 0์
๋๋ค. | string | No |
next-upstream-tries | ์์ฒญ์ ๋ค์ Upstream ์๋ฒ๋ก ์ ๋ฌํ๊ธฐ ์ํ ๊ฐ๋ฅํ ์๋ ํ์์
๋๋ค. proxy_next_upstream_tries ์ง์๋ฌธ์ ์ฐธ์กฐํ์ธ์. 0 ๊ฐ์ ์ด ์ ํ์ ๋๋๋ค. ๊ธฐ๋ณธ๊ฐ์ 0์
๋๋ค. | int | No |
client-max-body-size | ํด๋ผ์ด์ธํธ ์์ฒญ ๋ณธ๋ฌธ์ ์ต๋ ํ์ฉ ํฌ๊ธฐ๋ฅผ ์ค์ ํฉ๋๋ค. client_max_body_size ์ง์๋ฌธ์ ์ฐธ์กฐํ์ธ์. ๊ธฐ๋ณธ๊ฐ์ client-max-body-size ConfigMap ํค์ ์ค์ ๋์ด ์์ต๋๋ค. | string | No |
tls | Upstream์ ๋ํ TLS ๊ตฌ์ฑ์ ๋๋ค. | tls | No |
healthCheck | Upstream์ ๋ํ Health Check ๊ตฌ์ฑ์ ๋๋ค. health_check ์ง์๋ฌธ์ ์ฐธ์กฐํ์ธ์. Note: ์ด ๊ธฐ๋ฅ์ NGINX Plus์์๋ง ์ง์๋ฉ๋๋ค. | healthcheck | No |
slow-start | Slow Start์ ์ฌ์ฉํ๋ฉด Upstream ์๋ฒ๊ฐ ๋ณต๊ตฌ๋๊ฑฐ๋ ์ฌ์ฉ ๊ฐ๋ฅํด์ง ํ ๋๋ ์๋ฒ๊ฐ ์ฌ์ฉ ๋ถ๊ฐ๋ฅํ ๊ฒ์ผ๋ก ๊ฐ์ฃผ๋ ์ผ์ ๊ธฐ๊ฐ ํ์ ์ฌ์ฉ ๊ฐ๋ฅํด์ง๋ฉด ๊ฐ์ค์น๋ฅผ 0์์ ๊ณต์นญ ๊ฐ์ผ๋ก ์ ์ง์ ์ผ๋ก ๋ณต๊ตฌํ ์ ์์ต๋๋ค. ๊ธฐ๋ณธ์ ์ผ๋ก Slow Start์ ๋นํ์ฑํ๋์ด ์์ต๋๋ค. server ์ง์๋ฌธ์ slow_start ๋งค๊ฐ๋ณ์๋ฅผ ์ฐธ์กฐํ์ธ์. Note: ์ด ๋งค๊ฐ๋ณ์๋ random, hash ๋๋ ip_hash ๋ถํ ๋ถ์ฐ ๋ฐฉ๋ฒ๊ณผ ํจ๊ป ์ฌ์ฉํ ์ ์์ผ๋ฉฐ ๋ฌด์๋ฉ๋๋ค. | string | No |
queue | Upstream์ ๋ํ ์ ๊ตฌ์ฑํฉ๋๋ค. ์์ฒญ์ ์ฒ๋ฆฌํ๋ ๋์ Upstream ์๋ฒ๋ฅผ ์ฆ์ ์ ํํ ์ ์๋ ๊ฒฝ์ฐ ํด๋ผ์ด์ธํธ ์์ฒญ์ด ์ ๋ฐฐ์น๋ฉ๋๋ค. ๊ธฐ๋ณธ์ ์ผ๋ก ์ ๊ตฌ์ฑ๋์ง ์์ต๋๋ค. Note: ์ด ๊ธฐ๋ฅ์ NGINX Plus์์๋ง ์ง์๋ฉ๋๋ค. | queue | No |
buffering | Upstream ์๋ฒ์ ์๋ต ๋ฒํผ๋ง์ ํ์ฑํํฉ๋๋ค. proxy_buffering ์ง์๋ฌธ์ ์ฐธ์กฐํ์ธ์. ๊ธฐ๋ณธ๊ฐ์ proxy_buffering ConfigMap ํค์ ์ค์ ๋์ด ์์ต๋๋ค. | boolean | No |
buffers | ๋จ์ผ ์ฐ๊ฒฐ์ ๋ํ Upstream ์๋ฒ์์ ์๋ต์ ์ฝ๋ ๋ฐ ์ฌ์ฉ๋๋ ๋ฒํผ๋ฅผ ๊ตฌ์ฑํฉ๋๋ค. | buffers | No |
buffer-size | Upstream ์๋ฒ์์ ๋ฐ์ ์๋ต์ ์ฒซ ๋ฒ์งธ ๋ถ๋ถ์ ์ฝ๋ ๋ฐ ์ฌ์ฉ๋๋ ๋ฒํผ ํฌ๊ธฐ๋ฅผ ์ค์ ํฉ๋๋ค. proxy_buffer_size ์ง์๋ฌธ์ ์ฐธ์กฐํ์ธ์. ๊ธฐ๋ณธ๊ฐ์ proxy-buffer-size ConfigMap ํค์ ์ค์ ๋ฉ๋๋ค. | string | No |
ntlm | NTLM ์ธ์ฆ์ผ๋ก Proxy ์์ฒญ์ ํ์ฉํฉ๋๋ค. ntlm ์ง์๋ฌธ์ ์ฐธ์กฐํ์ธ์. NTLM ์ธ์ฆ์ด ์๋ํ๋ ค๋ฉด keepalive ํ๋๋ฅผ ์ฌ์ฉํ์ฌ Upstream ์๋ฒ์ ๋ํ keepalive ์ฐ๊ฒฐ์ ํ์ฑํํด์ผ ํฉ๋๋ค. Note: ์ด ๊ธฐ๋ฅ์ NGINX Plus์์๋ง ์ง์๋ฉ๋๋ค. | boolean | No |
type | Upstream์ ์ ํ์
๋๋ค. ์ง์๋๋ ๊ฐ์ http ๋ฐ grpc์
๋๋ค. ๊ธฐ๋ณธ๊ฐ์ http์
๋๋ค. gRPC์ ๊ฒฝ์ฐ ConfigMap์์ HTTP/2๋ฅผ ์ฌ์ฉ ์ค์ ํ๊ณ VirtualServer์์ TLS ์ข
๋ฃ๋ฅผ ๊ตฌ์ฑํด์ผ ํฉ๋๋ค. | string | No |
3-2. Upstream.Buffers
buffers ํ๋๋ ๋จ์ผ ์ฐ๊ฒฐ์ ๋ํ Upstream ์๋ฒ์ ์๋ต์ ์ฝ๋ ๋ฐ ์ฌ์ฉ๋๋ Buffers๋ฅผ ๊ตฌ์ฑํฉ๋๋ค.
number: 4
size: 8K
์์ธํ ๋ด์ฉ์ proxy_buffers ์ง์นจ์ ์ฐธ์กฐํ์ญ์์ค.
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
number | ๋ฒํผ ์๋ฅผ ๊ตฌ์ฑํฉ๋๋ค. ๊ธฐ๋ณธ๊ฐ์ proxy-buffers ConfigMap Key์ ์ค์ ๋์ด ์์ต๋๋ค. | int | Yes |
size | ๋ฒํผ์ ํฌ๊ธฐ๋ฅผ ๊ตฌ์ฑํฉ๋๋ค. ๊ธฐ๋ณธ๊ฐ์ proxy-buffers ConfigMap Key์ ์ค์ ๋์ด ์์ต๋๋ค. | string | Yes |
3-3. Upstream.TLS
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
enable | Upstream ์๋ฒ์ ๋ํ ์์ฒญ์ ๋ํด HTTPS๋ฅผ ํ์ฑํํฉ๋๋ค. ๊ธฐ๋ณธ๊ฐ์ False ์ด๋ฉฐ HTTP๊ฐ ์ฌ์ฉ๋จ์ ์๋ฏธํฉ๋๋ค. Note: ๊ธฐ๋ณธ์ ์ผ๋ก NGINX๋ Upstream ์๋ฒ ์ธ์ฆ์๋ฅผ ํ์ธํ์ง ์์ต๋๋ค. ํ์ธ์ ํ์ฑํํ๋ ค๋ฉด EgressMTLS ์ ์ฑ
์ ๊ตฌ์ฑํ์ญ์์ค. | boolean | No |
3-4. Upstream.Queue
queue ํ๋๋ Queue์ ๊ตฌ์ฑํฉ๋๋ค. ์์ฒญ์ ์ฒ๋ฆฌํ๋ ๋์ Upstream ์๋ฒ๋ฅผ ์ฆ์ ์ ํํ ์ ์๋ ๊ฒฝ์ฐ ํด๋ผ์ด์ธํธ ์์ฒญ์ด Queue์ ๋ฐฐ์น๋ฉ๋๋ค.
size: 10
timeout: 60s
์์ธํ ๋ด์ฉ์ Queue ์ง์๋ฌธ์ ์ฐธ์กฐํ์ญ์์ค.
Note: ์ด ๊ธฐ๋ฅ์ NGINX Plus์์๋ง ์ง์๋ฉ๋๋ค.
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
size | ํ(Queue)์ ํฌ๊ธฐ์ ๋๋ค. | int | Yes |
timeout | ํ(Queue)์ ์ ํ์๊ฐ์
๋๋ค. ์ ํ ์๊ฐ๋ณด๋ค ๊ธด ๊ธฐ๊ฐ ๋์ ์์ฒญ์ ๋๊ธฐํ ์ ์์ต๋๋ค. ๊ธฐ๋ณธ๊ฐ์ 60์ด์
๋๋ค. | string | No |
3-5. Upstream.Healthcheck
Healthcheck๋ Active Health Check๋ฅผ ์ ์ํฉ๋๋ค. ์๋ ์์์๋ Upstream์ ๋ํ Health Check์ ํ์ฑํํ๊ณ Mandatory ๋ฐ Persistent์ ๊ฒฐํฉ๋ Slow-Start ๋งค๊ฐ๋ณ์๋ฅผ ํฌํจํ์ฌ ์ฌ์ฉ ๊ฐ๋ฅํ ๋ชจ๋ ๋งค๊ฐ๋ณ์๋ฅผ ๊ตฌ์ฑํฉ๋๋ค.
name: tea
service: tea-svc
port: 80
slow-start: 30s
healthCheck:
enable: true
path: /healthz
interval: 20s
jitter: 3s
fails: 5
passes: 5
port: 8080
tls:
enable: true
connect-timeout: 10s
read-timeout: 10s
send-timeout: 10s
headers:
- name: Host
value: my.service
statusMatch: "! 500"
mandatory: true
persistent: true
Note: ์ด ๊ธฐ๋ฅ์ NGINX Plus์์๋ง ์ง์๋ฉ๋๋ค.
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
enable | Upstream ์๋ฒ์ ๋ํ ์ํ ํ์ธ์ ํ์ฑํํฉ๋๋ค. ๊ธฐ๋ณธ๊ฐ์ false์
๋๋ค. | boolean | No |
path | Health Check ์์ฒญ์ ์ฌ์ฉ๋๋ ๊ฒฝ๋ก์
๋๋ค. ๊ธฐ๋ณธ๊ฐ์ /์
๋๋ค. ์ด๊ฒ์ gRPC ์ ํ Upstream์ ๋ํด ๊ตฌ์ฑํ ์ ์์ต๋๋ค. | string | No |
interval | ์ฐ์๋ ๋ Health Check ์ฌ์ด์ ๊ฐ๊ฒฉ์
๋๋ค. ๊ธฐ๋ณธ๊ฐ์ 5s์
๋๋ค. | string | No |
jitter | ๊ฐ Health Check๊ฐ ์์๋ก ์ง์ฐ๋๋ ์๊ฐ์ ๋๋ค. ๊ธฐ๋ณธ์ ์ผ๋ก ์ง์ฐ์ ์์ต๋๋ค. | string | No |
fails | ์ด ์๋ฒ๊ฐ ๋น์ ์์ผ๋ก ๊ฐ์ฃผ๋ ํ ํน์ Upstream ์๋ฒ์ Health Check์ ์ฐ์์ผ๋ก ์คํจํ ํ์์
๋๋ค. ๊ธฐ๋ณธ๊ฐ์ 1์
๋๋ค. | integer | No |
passes | ์๋ฒ๊ฐ ์ ์ ์ํ๋ก ๊ฐ์ฃผ๋ ๋๊น์ง ํน์ Upstream ์๋ฒ์ ๋ํด ์ฐ์์ ์ผ๋ก ํต๊ณผ๋ Health Check ์์
๋๋ค. ๊ธฐ๋ณธ๊ฐ์ 1์
๋๋ค. | integer | No |
port | Health Check ์์ฒญ์ ์ฌ์ฉ๋๋ ํฌํธ์ ๋๋ค. ๊ธฐ๋ณธ์ ์ผ๋ก server port๊ฐ ์ฌ์ฉ๋ฉ๋๋ค. ์ฐธ๊ณ : Upstream์ ํฌํธ์ ๋ฌ๋ฆฌ ์ด ํฌํธ๋ ์๋น์ค ํฌํธ๊ฐ ์๋๋ผ Pod์ ํฌํธ์ ๋๋ค. | integer | No |
tls | Health Check ์์ฒญ์ ์ฌ์ฉ๋๋ TLS ๊ตฌ์ฑ์
๋๋ค. ๊ธฐ๋ณธ์ ์ผ๋ก Upstream์ tls ํ๋๊ฐ ์ฌ์ฉ๋ฉ๋๋ค. | upstream.tls | No |
connect-timeout | Upstream ์๋ฒ์์ ์ฐ๊ฒฐ์ ์ค์ ํ๊ธฐ ์ํ ์ ํ ์๊ฐ์
๋๋ค. ๊ธฐ๋ณธ์ ์ผ๋ก Upstream์ connect-timeout์ด ์ฌ์ฉ๋ฉ๋๋ค. | string | No |
read-timeout | Upstream ์๋ฒ์์ ์๋ต์ ์ฝ๊ธฐ ์ํ ์ ํ ์๊ฐ์
๋๋ค. ๊ธฐ๋ณธ์ ์ผ๋ก Upstream์ read-timeout์ด ์ฌ์ฉ๋ฉ๋๋ค. | string | No |
send-timeout | Upstream ์๋ฒ๋ก ์์ฒญ์ ์ ์กํ๊ธฐ ์ํ ์ ํ ์๊ฐ์
๋๋ค. ๊ธฐ๋ณธ์ ์ผ๋ก Upstream์ send-timeout์ด ์ฌ์ฉ๋ฉ๋๋ค. | string | No |
headers | Health Check ์์ฒญ์ ์ฌ์ฉ๋๋ ์์ฒญ ํค๋์
๋๋ค. NGINX Plus๋ ํญ์ Health Check ์์ฒญ์ ์ํด , ์ฌ์ฉ์ User-Agent ๋ฐ Connection ํค๋๋ฅผ ์ค์ ํฉ๋๋ค. | []header | No |
statusMatch | Health Check์ ์์ ์๋ต ์ํ ์ฝ๋์
๋๋ค. ๊ธฐ๋ณธ์ ์ผ๋ก ์๋ต์๋ ์ํ ์ฝ๋ 2xx ๋๋ 3xx๊ฐ ์์ด์ผ ํฉ๋๋ค. ์: '200' , '! 500' , '301-303 307'. match ์ง์์ด ๋ฌธ์๋ฅผ ์ฐธ์กฐํ์ธ์. gRPC ์ ํ Upstream์๋ ์ง์๋์ง ์์ต๋๋ค. | string | No |
grpcStatus | Check method์ ๋ํ Upstream ์๋ฒ ์๋ต์ ์์ gRPC status code์
๋๋ค. gRPC ์๋น์ค๊ฐ gRPC Health Check ํ๋กํ ์ฝ์ ๊ตฌํํ์ง ์๋ ๊ฒฝ์ฐ์๋ง ์ด ํ๋๋ฅผ ๊ตฌ์ฑํ์ญ์์ค. ์๋ฅผ ๋ค์ด Upstream ์๋ฒ๊ฐ 12(UNIMPLEMENTED) ์ํ ์ฝ๋๋ก ์๋ตํ๋ ๊ฒฝ์ฐ 12๋ฅผ ๊ตฌ์ฑํฉ๋๋ค. gRPC ์ ํ Upstream์์๋ง ์ ํจํฉ๋๋ค. | int | No |
grpcService | Upstream ์๋ฒ์์ ๋ชจ๋ํฐ๋งํ gRPC ์๋น์ค์ ๋๋ค. gRPC ์ ํ Upstream์์๋ง ์ ํจํฉ๋๋ค. | string | No |
mandatory | NGINX Plus๊ฐ ํธ๋ํฝ์ ์ ์กํ๊ธฐ ์ ์ ์๋ก ์ถ๊ฐ๋ ๋ชจ๋ ์๋ฒ๊ฐ ๊ตฌ์ฑ๋ ๋ชจ๋ Health Check์ ํต๊ณผํด์ผ ํฉ๋๋ค. ์ด๋ฅผ ์ง์ ํ์ง ์๊ฑฐ๋ false๋ก ์ค์ ํ๋ฉด ์ฒ์์๋ ์๋ฒ๊ฐ ์ ์์ผ๋ก ๊ฐ์ฃผ๋ฉ๋๋ค. Slow-Start๊ณผ ๊ฒฐํฉํ๋ฉด ์ ์๋ฒ๊ฐ ๋ฐ์ดํฐ๋ฒ ์ด์ค์ ์ฐ๊ฒฐํ๊ณ ์ ์ฒด ํธ๋ํฝ ๊ณต์ ๋ฅผ ์ฒ๋ฆฌํ๋ผ๋ ์์ฒญ์ ๋ฐ๊ธฐ ์ ์ “Warm Up”ํ ์ ์๋ ๋ ๋ง์ ์๊ฐ์ ์ ๊ณตํฉ๋๋ค. | bool | No |
persistent | Reloadํ๊ธฐ ์ ์ ์๋ฒ๊ฐ ์ ์์ผ๋ก ๊ฐ์ฃผ๋ ๊ฒฝ์ฐ Reloadํ ํ ์๋ฒ์ ๋ํ ์ด๊ธฐ “Up” ์ํ๋ฅผ ์ค์ ํฉ๋๋ค. ์๊ตฌ์ ์ผ๋ก ์ฌ์ฉ์ ์ค์ ํ๋ ค๋ฉด ํ์ ๋งค๊ฐ๋ณ์๋ true๋ก ์ค์ ํด์ผ ํฉ๋๋ค. | bool | No |
3-6. Upstream.SessionCookie
SessionCookie ํ๋๋ ๋์ผํ ํด๋ผ์ด์ธํธ์ ์์ฒญ์ด ๋์ผํ Upstream ์๋ฒ๋ก ์ ๋ฌ๋ ์ ์๋๋ก ํ๋ ์ธ์ ์ง์์ฑ์ ๊ตฌ์ฑํฉ๋๋ค. ์ง์ ๋ Upstream ์๋ฒ์ ๋ํ ์ ๋ณด๋ NGINX Plus์์ ์์ฑ๋ ์ธ์ Cookie์ ์ ๋ฌ๋ฉ๋๋ค.
์๋ ์์์๋ Upstream์ ๋ํ ์ธ์ Cookie๋ฅผ ์ฌ์ฉํ์ฌ ์ธ์ ์ง์์ฑ์ ๊ตฌ์ฑํ๊ณ ์ฌ์ฉ ๊ฐ๋ฅํ ๋ชจ๋ ๋งค๊ฐ๋ณ์๋ฅผ ๊ตฌ์ฑํฉ๋๋ค.
name: tea
service: tea-svc
port: 80
sessionCookie:
enable: true
name: srv_id
path: /
expires: 1h
domain: .example.com
httpOnly: false
secure: true
์ถ๊ฐ ์ ๋ณด๋ sticky ์ง์๋ฌธ์ ์ฐธ์กฐํ์ญ์์ค. Session Cookie๋ sticky cookie ๋ฐฉ๋ฒ์ ํด๋นํฉ๋๋ค.
Note: ์ด ๊ธฐ๋ฅ์ NGINX Plus์์๋ง ์ง์๋ฉ๋๋ค.
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
enable | Upstream ์๋ฒ์ ๋ํ ์ธ์
Cookie๋ก ์ธ์
์ง์์ฑ์ ํ์ฑํํฉ๋๋ค. ๊ธฐ๋ณธ๊ฐ์ false์
๋๋ค. | boolean | No |
name | Cookie์ ์ด๋ฆ์ ๋๋ค. | string | Yes |
path | Cookie๊ฐ ์ค์ ๋ ๊ฒฝ๋ก์ ๋๋ค. | string | No |
expires | ๋ธ๋ผ์ฐ์ ๊ฐ Cookie๋ฅผ ๋ณด๊ดํด์ผ ํ๋ ์๊ฐ์
๋๋ค. Cookie๊ฐ 2037๋
12์ 31์ผ 23:55:55 GMT์ ๋ง๋ฃ๋๋๋ก ํ๋ ํน์ ๊ฐ max๋ก ์ค์ ํ ์ ์์ต๋๋ค. | string | No |
domain | Cookie๊ฐ ์ค์ ๋ ๋๋ฉ์ธ์ ๋๋ค. | string | No |
httpOnly | Cookie์ HttpOnly ํน์ฑ์ ์ถ๊ฐํฉ๋๋ค. | boolean | No |
secure | Cookie์ Secure ํน์ฑ์ ์ถ๊ฐํฉ๋๋ค. | boolean | No |
3-7. Header
header๋ HTTP Header๋ฅผ ์ ์ํฉ๋๋ค:
name: Host
value: example.com
| Field | Description | Type | Required |
|---|---|---|---|
name | ํค๋์ ์ด๋ฆ์ ๋๋ค. | string | Yes |
value | ํค๋์ ๊ฐ์ ๋๋ค. | string | No |
3-8. Action
action์ ์์ฒญ์ ๋ํด Action ์์ ์ ์ ์ํฉ๋๋ค.
์๋ ์์์ ํด๋ผ์ด์ธํธ ์์ฒญ์ Upstream coffe๋ก ์ ๋ฌ๋ฉ๋๋ค.
path: /coffee
action:
pass: coffee
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
pass | ์์ฒญ์ Upstream์ผ๋ก ์ ๋ฌํฉ๋๋ค. ํด๋น ์ด๋ฆ์ Upstream์ ๋ฆฌ์์ค์ ์ ์ํด์ผ ํฉ๋๋ค. | string | No |
redirect | ์์ฒญ์ ์ ๊ณต๋ URL๋ก ๋ฆฌ๋ค์ด๋ ์ ํฉ๋๋ค. | action.redirect | No |
return | ๋ฏธ๋ฆฌ ๊ตฌ์ฑ๋ ์๋ต์ ๋ฐํํฉ๋๋ค. | action.return | No |
proxy | ์์ฒญ/์๋ต์ ์์ ํ ์ ์๋ ๊ธฐ๋ฅ(์: URI ์ฌ์์ฑ ๋๋ ํค๋ ์์ )์ ์ฌ์ฉํ์ฌ ์์ฒญ์ Upstream์ผ๋ก ์ ๋ฌํฉ๋๋ค. | action.proxy | No |
* โ ์์ ์๋ pass, redirect, return ๋๋ proxy ์ค ํ๋๊ฐ ์ ํํ ํฌํจ๋์ด์ผ ํฉ๋๋ค.
3-9. Action.Redirect
redirect ์์ ์ ์์ฒญ์ ๋ํด ๋ฐํํ Redirect์ ์ ์ํฉ๋๋ค.
์๋ ์์์๋ ํด๋ผ์ด์ธํธ ์์ฒญ์ด http://www.nginx.com URL๋ก ์ ๋ฌ๋ฉ๋๋ค:
redirect:
url: http://www.nginx.com
code: 301
| Field | ์ค | Type | Required |
|---|---|---|---|
url | ์์ฒญ์ ๋ฆฌ๋ค์ด๋ ์
ํ URL์
๋๋ค. ์ง์๋๋ NGINX ๋ณ์: $scheme , $http_x_forwarded_proto , $request_uri , $host ๋ณ์๋ ์ค๊ดํธ๋ก ๋ฌถ์ด์ผ ํฉ๋๋ค. ์: ${host}${request_uri}. | string | Yes |
code | ๋ฆฌ๋ค์ด๋ ์
์ ์ํ ์ฝ๋์
๋๋ค. ํ์ฉ๋๋ ๊ฐ์ 301, 302, 307, 308์
๋๋ค. ๊ธฐ๋ณธ๊ฐ์ 301์
๋๋ค. | int | No |
3-10. Action.Return
return ์์ ์ ์์ฒญ์ ๋ํด ๋ฏธ๋ฆฌ ๊ตฌ์ฑ๋ ์๋ต์ ์ ์ํฉ๋๋ค.
์๋ ์์์ NGINX๋ ๋ชจ๋ ์์ฒญ์ ๋ํด ์ฌ์ ๊ตฌ์ฑ๋ ์๋ต์ผ๋ก ์๋ตํฉ๋๋ค:
return:
code: 200
type: text/plain
body: "Hello World\n"
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
code | ์๋ต์ ์ํ ์ฝ๋์
๋๋ค. ํ์ฉ๋๋ ๊ฐ์ 2XX, 4XX ๋๋ 5XX์
๋๋ค. ๊ธฐ๋ณธ๊ฐ์ 200์
๋๋ค. | int | No |
type | ์๋ต์ MIME ์ ํ์
๋๋ค. ๊ธฐ๋ณธ๊ฐ์ text/plain์
๋๋ค. | string | No |
body | ์๋ต์ ๋ณธ๋ฌธ์
๋๋ค. NGINX ๋ณ์*๋ฅผ ์ง์ํฉ๋๋ค. ๋ณ์๋ ์ค๊ดํธ๋ก ๋ฌถ์ด์ผ ํฉ๋๋ค. ์: ์์ฒญ์ ${request_uri}\n์
๋๋ค. | string | Yes |
* โ ์ง์๋๋ NGINX ๋ณ์: $request_uri, $request_method, $request_body, $http_, $args, $args, $arg_, $cookie_, $host, $request_time, $request_length, $nginx_vers, $pid, $remote_addr, $remote_port, $time_iso8601, $time_local, $readdr, $re, $readdr, $servers_connection, $connections_writing ๋ฐ $connections_delays.
3-11. Action.Proxy
proxy ์์ ์ ์์ฒญ/์๋ต์ ์์ ํ ์ ์๋ ๊ธฐ๋ฅ(์: URI Rewrite ๋๋ ํค๋ ์์ )์ ์ฌ์ฉํ์ฌ ์์ฒญ์ Upstream์ผ๋ก ์ ๋ฌํฉ๋๋ค.
์๋ ์์ ์์๋ ์์ฒญ URI๊ฐ /๋ก ๋ค์ ์์ฑ๋๊ณ ์์ฒญ ๋ฐ ์๋ต ํค๋๊ฐ ์์ ๋ฉ๋๋ค:
proxy:
upstream: coffee
requestHeaders:
pass: true
set:
- name: My-Header
value: Value
- name: Client-Cert
value: ${ssl_client_escaped_cert}
responseHeaders:
add:
- name: My-Header
value: Value
- name: IC-Nginx-Version
value: ${nginx_version}
always: true
hide:
- x-internal-version
ignore:
- Expires
- Set-Cookie
pass:
- Server
rewritePath: /
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
upstream | ์์ฒญ์ด Proxy๋ Upstream์ ์ด๋ฆ์ ๋๋ค. ํด๋น ์ด๋ฆ์ Upstream์ด ๋ฆฌ์์ค์ ์ ์๋์ด ์์ด์ผ ํฉ๋๋ค. | string | Yes |
requestHeaders | ์์ฒญ ํค๋ ์์ ์ฌํญ์ ๋๋ค. | action.Proxy.RequestHeaders | No |
responseHeaders | ์๋ต ํค๋ ์์ ์ฌํญ์ ๋๋ค. | action.Proxy.ResponseHeaders | No |
rewritePath | ์ฌ์์ฑ๋ URI์
๋๋ค. ๋ฃจํธ ๊ฒฝ๋ก๊ฐ ~๋ก ์์ํ๋ ์ ๊ท์์ธ ๊ฒฝ์ฐ, rewritePath์๋ $1-9์ ์บก์ฒ ๊ทธ๋ฃน์ด ํฌํจ๋ ์ ์์ต๋๋ค. ์๋ฅผ ๋ค์ด ์ฒซ ๋ฒ์งธ ๊ทธ๋ฃน์ $1 ๋ฑ์ด ์์ต๋๋ค. ์์ธํ ๋ด์ฉ์ ๋ค์ ์ฐ๊ธฐ ์์ ๋ฅผ ํ์ธํ์ญ์์ค. | string | No |
3-12. Action.Proxy.RequestHeaders
RequestHeaders ํ๋๋ Proxy Upstream ์๋ฒ์ ๋ํ ์์ฒญ ํค๋๋ฅผ ์์ ํฉ๋๋ค.
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
pass | ์๋ ์์ฒญ ํค๋๋ฅผ Proxy Upstream ์๋ฒ๋ก ์ ๋ฌํฉ๋๋ค. ์์ธํ ๋ด์ฉ์ proxy_pass_request_header ์ง์๋ฌธ์ ์ฐธ์กฐํ์ธ์. ๊ธฐ๋ณธ๊ฐ์ true์ ๋๋ค. | bool | No |
set | Proxy Upstream ์๋ฒ๋ก ์ ๋ฌ๋ ์์ฒญ ํค๋๋ฅผ ํ์ํ๊ธฐ ์ํด ํ๋๋ฅผ ์ฌ์ ์ํ๊ฑฐ๋ ์ถ๊ฐํ ์ ์์ต๋๋ค. ์์ธํ ๋ด์ฉ์ proxy_set_header ์ง์๋ฌธ๋ฅผ ์ฐธ์กฐํ์ธ์. | []header | No |
3-13. Action.Proxy.RequestHeaders.Set.Header
header๋ HTTP Header๋ฅผ ์ ์ํฉ๋๋ค:
name: My-Header
value: My-Value
Ingress Controller๊ฐ $host๋ก ์ค์ ํ๋ Host ํค๋์ ๊ธฐ๋ณธ๊ฐ์ ์ฌ์ ์ํ ์ ์์ต๋๋ค.
name: Host
value: example.com
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
name | ํค๋์ ์ด๋ฆ์ ๋๋ค. | string | Yes |
value | ํค๋์ ๊ฐ์
๋๋ค. NGINX ๋ณ์*๋ฅผ ์ง์ํฉ๋๋ค. ๋ณ์๋ ์ค๊ดํธ๋ก ๋ฌถ์ด์ผ ํฉ๋๋ค. ์: ${scheme}. | string | No |
* โ ์ง์๋๋ NGINX ๋ณ์: $request_uri, $request_method, $request_body, $http_, $args, $args, $arg_, $cookie_, $host, $request_time, $request_length, $nginx_vers, $pid, $remote_addr, $remote_port, $time_iso8601, $time_local, $readdr, $re, $readdr, $servers_connection, $connections_writing, $connections_dn, $ssl_dn, $ssl_client_cert, $ssl_client_dn, $ssl_client_dn_fingerprint, $ssl_client_writing, $ssl_client_dn, $ssl_client_dn_dn, $ssl_client_dn_dn_dn, $ssl_client_dn, $ssl_dn_client_dn_client_dn, $ssl_dn_dn, $ss, $ssl_curves, $ssl_early_data, $ssl_protocol, $ssl_server_name, $ssl_session_id, $ssl_session_reuse, $jwt_claim_(NGINX Plus ์ ์ฉ) ๋ฐ $jwt_header_(NGINX Plus ์ ์ฉ).
3-14. Action.Proxy.ResponseHeaders
ResponseHeaders ํ๋๋ ํด๋ผ์ด์ธํธ์ ๋ํ ์๋ต์ ํค๋๋ฅผ ์์ ํฉ๋๋ค.
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
hide | Proxy Upstream ์๋ฒ์์ ํด๋ผ์ด์ธํธ์ ๋ํ ์๋ต์ผ๋ก ์ ๋ฌ๋์ง ์๋* ํค๋์ ๋๋ค. ์์ธํ ๋ด์ฉ์ proxy_hide_header ์ง์๋ฌธ์ ์ฐธ์กฐํ์ธ์. | []string | No |
pass | Proxy Upstream ์๋ฒ์์ ํด๋ผ์ด์ธํธ๋ก ์จ๊ฒจ์ง ํค๋ ํ๋*๋ฅผ ์ ๋ฌํ ์ ์์ต๋๋ค. ์์ธํ ๋ด์ฉ์ proxy_pass_header ์ง์๋ฌธ์ ์ฐธ์กฐํ์ธ์. | []string | No |
ignore | Proxy Uptream ์๋ฒ์์ ํด๋ผ์ด์ธํธ๋ก์ ํน์ ํค๋** ์ฒ๋ฆฌ๋ฅผ ๋นํ์ฑํํฉ๋๋ค. ์์ธํ ๋ด์ฉ์ proxy_ignore_headers ์ง์๋ฌธ์ ์ฐธ์กฐํ์ธ์. | []string | No |
add | ํด๋ผ์ด์ธํธ์ ๋ํ ์๋ต์ ํค๋๋ฅผ ์ถ๊ฐํฉ๋๋ค. | []addHeader | No |
* โ ๊ธฐ๋ณธ ์จ๊น ํค๋: Date, Server, X-Pad ๋ฐ X-Accel-โฆ ๋ฑ.
** โ ๋ฌด์ํ ์ ์๋ ํ๋๋ X-Acel-Redirect, X-Acel-Expires, X-Acel-Limit-Rate, X-Acel-Buffering, X-Acel-Charset, Expires, Cache-Control, Set-Cookie ๋ฐ Vari์
๋๋ค.
3-15. AddHeader
addHeader๋ ์ ํ์ always ํ๋๊ฐ ์๋ HTTP ํค๋๋ฅผ ์ ์ํฉ๋๋ค.
name: My-Header
value: My-Value
always: true
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
name | ํค๋์ ์ด๋ฆ์ ๋๋ค. | string | Yes |
value | ํค๋์ ๊ฐ์
๋๋ค. NGINX ๋ณ์*๋ฅผ ์ง์ํฉ๋๋ค. ๋ณ์๋ ์ค๊ดํธ๋ก ๋ฌถ์ด์ผ ํฉ๋๋ค. ์: ${scheme}. | string | No |
always | true๋ก ์ค์ ํ๋ฉด ์๋ต ์ํ ์ฝ๋**์ ๊ด๊ณ์์ด ํค๋๋ฅผ ์ถ๊ฐํฉ๋๋ค. ๊ธฐ๋ณธ๊ฐ์ false์ ๋๋ค. ์์ธํ ๋ด์ฉ์ add_header ์ง์์ด๋ฅผ ์ฐธ์กฐํ์ญ์์ค. | bool | No |
* โ ์ง์๋๋ NGINX ๋ณ์: $request_uri, $request_method, $request_body, $http_, $args, $args, $arg_, $cookie_, $host, $request_time, $request_length, $nginx_vers, $pid, $remote_addr, $remote_port, $time_iso8601, $time_local, $readdr, $re, $readdr, $servers_connection, $connections_writing, $connections_dn, $ssl_dn, $ssl_client_cert, $ssl_client_dn, $ssl_client_dn_fingerprint, $ssl_client_writing, $ssl_client_dn, $ssl_client_dn_dn, $ssl_client_dn_dn_dn, $ssl_client_dn, $ssl_dn_client_dn_client_dn, $ssl_dn_dn, $ss, $ssl_curves, $ssl_early_data, $ssl_protocol, $ssl_server_name, $ssl_session_id, $ssl_session_reuse, $jwt_claim_(NGINX Plus ์ ์ฉ) ๋ฐ $jwt_header_(NGINX Plus ์ ์ฉ).
** โ always๊ฐ false์ด๋ฉด ์๋ต ์ํ ์ฝ๋๊ฐ 200, 201, 204, 206, 301, 302, 303, 304, 307 ๋๋ 308์ธ ๊ฒฝ์ฐ์๋ง ์๋ต ํค๋๊ฐ ์ถ๊ฐ๋ฉ๋๋ค.
3-16. Split
split์ Split ๊ตฌ์ฑ์ ์ผ๋ถ๋ก ์์ ์ ๋ํ ๊ฐ์ค์น๋ฅผ ์ ์ํฉ๋๋ค.
์๋ ์์์ NGINX๋ ์์ฒญ์ 80%๋ฅผ Upstream coffee-v1์ ์ ๋ฌํ๊ณ ๋๋จธ์ง 20%๋ฅผ coffee-v2์ ์ ๋ฌํฉ๋๋ค.
splits:
- weight: 80
action:
pass: coffee-v1
- weight: 20
action:
pass: coffee-v2
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
weight | ์์
์ ๋ฌด๊ฒ์
๋๋ค. 1..99 ๋ฒ์์ ์ํด์ผ ํฉ๋๋ค. ๋ชจ๋ ๋ถํ ๊ฐ์ค์น์ ํฉ์ 100์ด์ด์ผ ํฉ๋๋ค. | int | Yes |
action | ์์ฒญ์ ๋ํด ์ํํ ์์ ์ ๋๋ค. | action | Yes |
3-17. Match
match๋ ์กฐ๊ฑด๊ณผ ์์ ๋๋ Split ๊ฐ์ ์ผ์น๋ฅผ ์ ์ํฉ๋๋ค.
์๋ ์์์ NGINX๋ Cookie user์ ๊ฐ์ ๋ฐ๋ผ /coffee ๊ฒฝ๋ก๊ฐ ์๋ ์์ฒญ์ ๋ค๋ฅธ Upstream์ผ๋ก ๋ผ์ฐํ
ํฉ๋๋ค.
user=johnย ->ย coffee-future
user=bobย ->ย coffee-deprecated
Cookie๊ฐ ์ค์ ๋์ง ์์๊ฑฐ๋ john ๋๋ bob๊ณผ ๊ฐ์ง ์์ ๊ฒฝ์ฐ NGINX๋ coffee-stable๋ก ๋ผ์ฐํ
ํฉ๋๋ค.
path: /coffee
matches:
- conditions:
- cookie: user
value: john
action:
pass: coffee-future
- conditions:
- cookie: user
value: bob
action:
pass: coffee-deprecated
action:
pass: coffee-stable
๋ค์ ์์์ NGINX๋ ์์ฒญ์ HTTP ๋ฉ์๋๋ฅผ ๋ํ๋ด๋ ๊ธฐ๋ณธ ์ ๊ณต $request_method ๋ณ์์ ๊ฐ์ ๊ธฐ๋ฐ์ผ๋ก ์์ฒญ์ ๋ผ์ฐํ
ํฉ๋๋ค.
๋ชจ๋ POST ์์ฒญ ->ย coffee-post
๋ชจ๋ non-POST ์ ->ย coffee
path: /coffee
matches:
- conditions:
- variable: $request_method
value: POST
action:
pass: coffee-post
action:
pass: coffee
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
conditions | ์กฐ๊ฑด ๋ชฉ๋ก์ ๋๋ค. ์กฐ๊ฑด์ 1๊ฐ ์ด์ ํฌํจํด์ผ ํฉ๋๋ค. | []condition | Yes |
action | ์์ฒญ์ ๋ํด ์ํํ ์์ ์ ๋๋ค. | action | No |
splits | ํธ๋ํฝ ๋ถํ ์ ์ํ ๋ถํ ๊ตฌ์ฑ์ ๋๋ค. ์ต์ 2๊ฐ์ ๋ถํ ์ ํฌํจํด์ผ ํฉ๋๋ค. | []split | No |
* โ Match์๋ action ๋๋ splits ์ค ์ ํํ ํ๋๊ฐ ํฌํจ๋์ด์ผ ํฉ๋๋ค.
3-18. Condition
condition์ ์ผ์น Condition์ ์กฐ๊ฑด์ ์ ์ํฉ๋๋ค.
| Field | ์ค | Type | Required |
|---|---|---|---|
header | ํค๋์ ์ด๋ฆ์
๋๋ค. ์์ซ์ ๋๋ -๋ก ๊ตฌ์ฑ๋์ด์ผ ํฉ๋๋ค. | string | No |
cookie | Cookie์ ์ด๋ฆ์
๋๋ค. ์์ซ์ ๋ฌธ์ ๋๋ _๋ก ๊ตฌ์ฑ๋์ด์ผ ํฉ๋๋ค. | string | No |
argument | Argument์ ์ด๋ฆ์
๋๋ค. ์์ซ์ ๋ฌธ์ ๋๋ _๋ก ๊ตฌ์ฑ๋์ด์ผ ํฉ๋๋ค. | string | No |
variable | NGINX ๋ณ์์ ์ด๋ฆ์
๋๋ค. $๋ก ์์ํด์ผ ํฉ๋๋ค. ํ ์๋์์ ์ง์๋๋ ๋ณ์ ๋ชฉ๋ก์ ์ฐธ์กฐํ์ญ์์ค. | string | No |
value | ์กฐ๊ฑด๊ณผ ์ผ์นํ๋ ๊ฐ์ ๋๋ค. ๊ฐ์ ์ ์ํ๋ ๋ฐฉ๋ฒ์ ํ ์๋์ ๋์ ์์ต๋๋ค. | string | Yes |
* โ ์กฐ๊ฑด์ header, cookie, argument ๋๋ variable ์ค ํ๋๋ฅผ ์ ํํ๊ฒ ํฌํจํด์ผ ํฉ๋๋ค.
์ง์๋๋ NGINX ๋ณ์: $args, $http2, $https, $remote_addr, $remote_port, $query_string, $request, $request_body, $request_uri, $request_method, $scheme. ์ฌ๊ธฐ์์ ๊ฐ ๋ณ์์ ๋ํ ์ค๋ช
์๋ฅผ ํ์ธํ์ญ์์ค.
์ด ๊ฐ์ ๋ ๊ฐ์ง ์ ํ์ Matching๋ฅผ ์ง์ํฉ๋๋ค:
- ๋์๋ฌธ์๋ฅผ ๊ตฌ๋ถํ์ง ์๋ ๋ฌธ์์ด ๋น๊ต. ์:
johnโ ๋ฌธ์์ด(์:john,John,JOHN)์ ๋ํด ๋์๋ฌธ์๋ฅผ ๊ตฌ๋ถํ์ง ์๋ ์ผ์น.!johnโbob,anything,' '(๋น ๋ฌธ์์ด)๊ณผ ๊ฐ์ ๋ฌธ์์ด์ ๋ํด john์ ๋ํ ๋์๋ฌธ์ ๊ตฌ๋ถ ์ผ์น๋ฅผ ๋ถ์ ํฉ๋๋ค.
- ์ ๊ท์๊ณผ ์ผ์นํฉ๋๋ค. NGINX๋ PCRE(Perl ํ๋ก๊ทธ๋๋ฐ ์ธ์ด)์์ ์ฌ์ฉํ๋ ๊ฒ๊ณผ ํธํ๋๋ ์ ๊ท์์ ์ง์ํฉ๋๋ค. ์๋ฅผ ๋ค์ด:
~^yesโyes๋ก ์์ํ๋ ๋ชจ๋ ๋ฌธ์์ด๊ณผ ์ผ์นํ๋ ๋์๋ฌธ์๋ฅผ ๊ตฌ๋ถํ๋ ์ ๊ท์์ ๋๋ค. ์๋ฅผ ๋ค์ดyes,yes123์ ๋๋ค.!~^yesโYES,Yes123,noyes์ ๊ฐ์ ๋ฌธ์์ด์ ๋ํด ์ฑ๊ณตํ๋ ์ด์ ์ ๊ท์์ ๋ถ์ . (๋ถ์ ๋ฉ์ปค๋์ฆ์ PCRE ๊ตฌ๋ฌธ์ ์ผ๋ถ๊ฐ ์๋๋๋ค.).~*no$โno๋ก ๋๋๋ ๋ชจ๋ ๋ฌธ์์ด๊ณผ ์ผ์นํ๋ ๋์๋ฌธ์๋ฅผ ๊ตฌ๋ถํ์ง ์๋ ์ ๊ท์์ ๋๋ค. ์:no,123no,123NO.
Note: ๊ฐ์๋ ์ด์ค์ผ์ดํ ์ฒ๋ฆฌ๋์ง ์์ ํฐ๋ฐ์ดํ(")๊ฐ ํฌํจ๋์ด์๋ ์ ๋๋ฉฐ ์ด์ค์ผ์ดํ ์ฒ๋ฆฌ๋์ง ์์ ๋ฐฑ์ฌ๋์(\)๋ก ๋๋์ง ์์์ผ ํฉ๋๋ค. ์๋ฅผ ๋ค์ด ๋ค์์ ์ ํจํ์ง ์์ ๊ฐ์
๋๋ค. some"value, somevalue\.
3-19. ErrorPage
errorPage๋ Upstream ์๋ฒ๊ฐ ์ค๋ฅ ์ํ ์ฝ๋๋ก ์๋ต(๋๋ NGINX๊ฐ ์์ฑ)ํ๋ ๊ฒฝ์ฐ ๊ฒฝ๋ก์ ๋ํ ์ฌ์ฉ์ ์ ์ ์๋ต์ ์ ์ํฉ๋๋ค. ์ฌ์ฉ์ ์ ์ ์๋ต์ ๋ฆฌ๋ค์ด๋ ์ ๋๋ ๋ฏธ๋ฆฌ ์ค๋น๋ ์๋ต์ผ ์ ์์ต๋๋ค. ์์ธํ ๋ด์ฉ์ error_page ์ง์๋ฌธ์ ์ฐธ์กฐํ์ญ์์ค.
path: /coffee
errorPages:
- codes: [502, 503]
redirect:
code: 301
url: https://nginx.org
- codes: [404]
return:
code: 200
body: "Original resource not found, but success!"
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
codes | ์ค๋ฅ ์ํ ์ฝ๋ ๋ชฉ๋ก์ ๋๋ค. | []int | Yes |
redirect | ์ง์ ๋ ์ํ ์ฝ๋์ ๋ํ ๋ฆฌ๋ค์ด๋ ์ ์์ ์ ๋๋ค. | errorPage.Redirect | No |
return | ์ง์ ๋ ์ํ ์ฝ๋์ ๋ํ ๋ฏธ๋ฆฌ ์ค๋น๋ ์๋ต ์์ ์ ๋๋ค. | errorPage.Return | No |
* โ errorPage๋ ๋ค์ ์ค ํ๋๋ฅผ ์ ํํ ํฌํจํด์ผ ํฉ๋๋ค: return ๋๋ redirect.
3-20. ErrorPage.Redirect
redirect์ errorPage์ ๋ํ Redirect์ ์ ์ํฉ๋๋ค.
์๋ ์์์ NGINX๋ Upstream ์๋ฒ์ ์๋ต์ 404 ์ํ ์ฝ๋๊ฐ ์์ ๋ ๋ฆฌ๋ค์ด๋ ์ ์ผ๋ก ์๋ตํฉ๋๋ค.
codes: [404]
redirect:
code: 301
url: ${scheme}://cafe.example.com/error.html
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
code | ๋ฆฌ๋๋ ์
์ ์ํ ์ฝ๋์
๋๋ค. ํ์ฉ๋๋ ๊ฐ์ 301, 302, 307, 308์
๋๋ค. ๊ธฐ๋ณธ๊ฐ์ 301์
๋๋ค. | int | No |
url | ์์ฒญ์ ๋ฆฌ๋ค์ด๋ ์
ํ URL์
๋๋ค. ์ง์๋๋ NGINX ๋ณ์: $scheme ๋ฐ $http_x_forwarded_proto ๋ณ์๋ ์ค๊ดํธ๋ก ๋ฌถ์ด์ผ ํฉ๋๋ค. ์: ${scheme}. | string | Yes |
3-21. ErrorPage.Return
๋ฐํ์ errorPage์ ๋ํ ๋ฏธ๋ฆฌ ์ค๋น๋ ์๋ต์ ์ ์ํฉ๋๋ค.
์๋ ์์์ NGINX๋ Upstream ์๋ฒ์ ์๋ต์ 401 ๋๋ 403 ์ํ ์ฝ๋๊ฐ ์์ ๋ ์ค๋น๋ ์๋ต์ผ๋ก ์๋ตํฉ๋๋ค.
codes: [401, 403]
return:
code: 200
type: application/json
body: |
{\"msg\": \"You don't have permission to do this\"}
headers:
- name: x-debug-original-statuses
value: ${upstream_status}
| Field | ์ค | Type | Required |
|---|---|---|---|
code | ์๋ต์ ์ํ ์ฝ๋์ ๋๋ค. ๊ธฐ๋ณธ๊ฐ์ ์๋ ์๋ต์ ์ํ ์ฝ๋์ ๋๋ค. | int | No |
type | ์๋ต์ MIME ์ ํ์ ๋๋ค. ๊ธฐ๋ณธ๊ฐ์ text/html์ ๋๋ค. | string | No |
body | ์๋ต์ ๋ณธ๋ฌธ์
๋๋ค. ์ง์๋๋ NGINX ๋ณ์: $upstream_status . ๋ณ์๋ ์ค๊ดํธ๋ก ๋ฌถ์ด์ผ ํฉ๋๋ค. ์: ${upstream_status}. | string | Yes |
headers | ์๋ต์ ์ฌ์ฉ์ ์ ์ ํค๋์ ๋๋ค. | errorPage.Return.Header | No |
3-22. ErrorPage.Return.Header
ํค๋๋ errorPage์์ ๊ฒ์๋ ์๋ต์ ๋ํ HTTP ํค๋๋ฅผ ์ ์ํฉ๋๋ค:
name: x-debug-original-statuses
value: ${upstream_status}
| Field | ์ค๋ช | Type | Required |
|---|---|---|---|
name | ํค๋์ ์ด๋ฆ์ ๋๋ค. | string | Yes |
value | ํค๋์ ๊ฐ์
๋๋ค. ์ง์๋๋ NGINX ๋ณ์: $upstream_status . ๋ณ์๋ ์ค๊ดํธ๋ก ๋ฌถ์ด์ผ ํฉ๋๋ค. ์: ${upstream_status}. | string | No |
4. VirtualServer ๋ฐ VirtualServerRoute ์ฌ์ฉ
์ผ๋ฐ์ ์ธ kubectl ๋ช
๋ น์ ์ฌ์ฉํ์ฌ Ingress ๋ฆฌ์์ค์ ์ ์ฌํ VirtualServer ๋ฐ VirtualServerRoute ๋ฆฌ์์ค๋ก ์ฌ์ฉํ ์ ์์ต๋๋ค.
์๋ฅผ ๋ค์ด ๋ค์ ๋ช
๋ น์ cafe-virtual-server.yaml์ ์ด๋ฆ์ด cafe์ธ VirtualServer ๋ฆฌ์์ค๋ฅผ ์์ฑํฉ๋๋ค.
$ kubectl apply -f cafe-virtual-server.yaml
virtualserver.k8s.nginx.org "cafe" created
๋ค์์ ์คํํ์ฌ ๋ฆฌ์์ค๋ฅผ ๊ฐ์ ธ์ฌ ์ ์์ต๋๋ค:
$ kubectl get virtualserver cafe
NAME STATE HOST IP PORTS AGE
cafe Valid cafe.example.com 12.13.23.123 [80,443] 3m
kubectl get ๋ฐ ์ ์ฌํ ๋ช
๋ น์์ virtualserver ๋์ vs๋ผ๋ ์งง์ ์ด๋ฆ์ ์ฌ์ฉํ ์๋ ์์ต๋๋ค.
VirtualServerRoute ๋ฆฌ์์ค ์์
์ ์ ์ฌํฉ๋๋ค. kubectl ๋ช
๋ น์์ virtualserverroute ๋๋ ๋จ์ถ ์ด๋ฆ vsr์ ์ฌ์ฉํฉ๋๋ค.
4-1. Snippets ์ฌ์ฉ
Snippets์ ์ฌ์ฉํ๋ฉด Raw NGINX ๊ตฌ์ฑ์ ๋ค๋ฅธ NGINX ๊ตฌ์ฑ Context์ ์ฝ์ ํ ์ ์์ต๋๋ค. ์๋ ์์์๋ Snippets์ ์ฌ์ฉํ์ฌ VirtualServer์์ ์ฌ๋ฌ NGINX ๊ธฐ๋ฅ์ ๊ตฌ์ฑํฉ๋๋ค.
apiVersion: k8s.nginx.org/v1
kind: VirtualServer
metadata:
name: cafe
namespace: cafe
spec:
http-snippets: |
limit_req_zone $binary_remote_addr zone=mylimit:10m rate=1r/s;
proxy_cache_path /tmp keys_zone=one:10m;
host: cafe.example.com
tls:
secret: cafe-secret
server-snippets: |
limit_req zone=mylimit burst=20;
upstreams:
- name: tea
service: tea-svc
port: 80
- name: coffee
service: coffee-svc
port: 80
routes:
- path: /tea
location-snippets: |
proxy_cache one;
proxy_cache_valid 200 10m;
action:
pass: tea
- path: /coffee
action:
pass: coffee
Snippets์ ์์ฑ๋ NGINX ๊ตฌ์ฑ์ ๋ํด ๋ ๋ง์ ์ ์ด๊ฐ ํ์ํ ๊ณ ๊ธ NGINX ์ฌ์ฉ์๊ฐ ์ฌ์ฉํ๊ธฐ ์ํ ๊ฒ์ ๋๋ค.
๊ทธ๋ฌ๋ ์๋์ ์ค๋ช
๋ ๋จ์ ๋๋ฌธ์ Snippets์ ๊ธฐ๋ณธ์ ์ผ๋ก ๋นํ์ฑํ๋์ด ์์ต๋๋ค. Snippets์ ์ฌ์ฉํ๋ ค๋ฉด enable-snippets Command-line๋ฅผ ์ค์ ํฉ๋๋ค.
Snippets ์ฌ์ฉ์ ๋จ์ :
- ๋ณต์ก์ฑ. Snippets์ ์ฌ์ฉํ๋ ค๋ฉด ๋ค์์ด ํ์ํฉ๋๋ค:
- NGINX ๊ตฌ์ฑ ๊ธฐ๋ณธ ์์๋ฅผ ์ดํดํ๊ณ ์ฌ๋ฐ๋ฅธ NGINX ๊ตฌ์ฑ์ ๊ตฌํํฉ๋๋ค.
- IC๊ฐ NGINX ๊ตฌ์ฑ์ ์์ฑํ์ฌ ๊ตฌ์ฑ์ ๋ค๋ฅธ ๊ธฐ๋ฅ์ Snippets์ด ๊ฐ์ญํ์ง ์๋๋ก ํ๋ ๋ฐฉ๋ฒ์ ์ดํดํฉ๋๋ค.
- ๊ฒฌ๊ณ ์ฑ ๊ฐ์. ์๋ชป๋ Snippets์ NGINX ๊ตฌ์ฑ์ ๋ฌดํจํํ์ฌ Reload์ ์คํจํ๊ฒ ํฉ๋๋ค. ์ด๋ ๊ฒ ํ๋ฉด Snippets์ด ์์ ๋ ๋๊น์ง ๋ค๋ฅธ VirtualServer ๋ฐ VirtualServerRoute ๋ฆฌ์์ค์ ๋ํ ์ ๋ฐ์ดํธ๋ฅผ ํฌํจํ์ฌ ์๋ก์ด ๊ตฌ์ฑ ์ ๋ฐ์ดํธ๊ฐ ๋ฐฉ์ง๋ฉ๋๋ค.
- ๋ณด์์ ์ํฅ์ ๋ฏธ์นฉ๋๋ค. Snippets์ NGINX ๊ตฌ์ฑ ๊ธฐ๋ณธ ์์์ ์ก์ธ์คํ ์ ์์ผ๋ฉฐ ์ด๋ฌํ ๊ธฐ๋ณธ ์์๋ Ingress Controller์์ ๊ฒ์ฆ๋์ง ์์ต๋๋ค. ์๋ฅผ ๋ค์ด, Snippets์ ์ ๋ ฅ ๋ฐ ๊ฐ์ ์๋ฒ ๋ฆฌ์์ค์ ๋ํ TLS Termination์ ์ฌ์ฉ๋๋ TLS ์ธ์ฆ์ ๋ฐ Key๋ฅผ ์ ๊ณตํ๋๋ก NGINX๋ฅผ ๊ตฌ์ฑํ ์ ์์ต๋๋ค.
Snippets์ ์ฌ์ฉํ ๋ ์ค๋ฅ๋ฅผ ๊ฐ์งํ ์ ์๋๋ก Ingress Controller๋ ๋ก๊ทธ๋ฟ ์๋๋ผ VirtualServer ๋ฐ VirtualServerRoute ๋ฆฌ์์ค์ ์ด๋ฒคํธ ๋ฐ ์ํ ํ๋์ ๊ตฌ์ฑ Reload ์ค๋ฅ๋ฅผ ๋ณด๊ณ ํฉ๋๋ค. ๋ํ ๋ค์์ Prometeus ๋ฉํธ๋ฆญ์ ์คํจํ Reload์ ๋ํ ํต๊ณ(controller_nginx_last_reload_status ๋ฐ controller_nginx_reload_errors_total)๋ฅผ ๋ณด์ฌ์ค๋๋ค.
Note: NGINX ๊ตฌ์ฑ์ ์๋ชป๋ Snippets์ด ํฌํจ๋ ๊ธฐ๊ฐ ๋์ NGINX๋ ์ ํจํ ์ต์ ๊ตฌ์ฑ์ผ๋ก ๊ณ์ ์๋ํฉ๋๋ค.
4-2. ๊ฒ์ฆ
VirtualServer ๋ฐ VirtualServerRoute ๋ฆฌ์์ค์ ๋ํด ๋ ๊ฐ์ง ์ ํ์ ์ ํจ์ฑ ๊ฒ์ฆ์ ์ฌ์ฉํ ์ ์์ต๋๋ค.
Kubectl๋ฐ Kubernetes API ์๋ฒ์ ์ํ ๊ตฌ์กฐ ๊ฒ์ฆ.- Ingress Controller์ ์ํ ํฌ๊ด์ ์ธ ๊ฒ์ฆ.
4-3. ๊ตฌ์กฐ ๊ฒ์ฆ
VirtualServer ๋ฐ VirtualServerRoute์ ๋ํ ์ฌ์ฉ์ ์ ์ ๋ฆฌ์์ค ์ ์์๋ ํด๋น ๋ฆฌ์์ค์ ๋ชจ๋ ํ๋ ์ ํ์ ์ค๋ช ํ๋ ๊ตฌ์กฐ์ OpenAPI ์คํค๋ง๊ฐ ํฌํจ๋ฉ๋๋ค.
๊ตฌ์กฐ์ ์คํค๋ง๋ฅผ ์๋ฐํ๋ ๋ฆฌ์์ค๋ฅผ ์์ฑ(๋๋ ์
๋ฐ์ดํธ)ํ๋ ค๊ณ ํ๋ฉด(์: Upstream์ ํฌํธ ํ๋์ ๋ฌธ์์ด ๊ฐ ์ฌ์ฉ) kubectl ๋ฐ Kubernetes API ์๋ฒ๋ ์ด๋ฌํ ๋ฆฌ์์ค๋ฅผ ๊ฑฐ๋ถํฉ๋๋ค.
kubectl ๊ฒ์ฆ์ ์:
$ kubectl apply -f cafe-virtual-server.yaml
error: error validating "cafe-virtual-server.yaml": error validating data: ValidationError(VirtualServer.spec.upstreams[0].port): invalid type for org.nginx.k8s.v1.VirtualServer.spec.upstreams.port: got "string", expected "integer"; if you choose to ignore these errors, turn validation off with --validate=false
Kubernetes API ์๋ฒ ๊ฒ์ฆ์ ์:
$ kubectl apply -f cafe-virtual-server.yaml --validate=false
The VirtualServer "cafe" is invalid: []: Invalid value: map[string]interface {}{ ... }: validation failure list:
spec.upstreams.port in body must be of type integer: "string"
๋ฆฌ์์ค๊ฐ ๊ฑฐ๋ถ๋์ง ์์ผ๋ฉด(๊ตฌ์กฐ ์คํค๋ง๋ฅผ ์๋ฐํ์ง ์์) Ingress Controller๊ฐ ๋ฆฌ์์ค๋ฅผ ์ถ๊ฐ๋ก ๊ฒ์ฆํฉ๋๋ค.
4-4. ํฌ๊ด์ ๊ฒ์ฆ
Ingress Controller๋ VirtualServer ๋ฐ VirtualServerRoute ๋ฆฌ์์ค์ ํ๋ ์ ํจ์ฑ์ ๊ฒ์ฌํฉ๋๋ค. ๋ฆฌ์์ค๊ฐ ์ ์ํ์ง ์์ ๊ฒฝ์ฐ Ingress Controller๊ฐ ๋ฆฌ์์ค๋ฅผ ๊ฑฐ๋ถํฉ๋๋ค. ๋ฆฌ์์ค๋ ํด๋ฌ์คํฐ์ ๊ณ์ ์กด์ฌํ์ง๋ง Ingress Controller๋ ์ด๋ฅผ ๋ฌด์ํฉ๋๋ค.
Ingress Controller๊ฐ VirtualServer์ ๋ํ ๊ตฌ์ฑ์ ์ฑ๊ณต์ ์ผ๋ก ์ ์ฉํ๋์ง ํ์ธํ ์ ์์ต๋๋ค. Example cafe VirtualServer์ ๊ฒฝ์ฐ ๋ค์์ ์คํํ ์ ์์ต๋๋ค.
$ kubectl describe vs cafe
. . .
Events:
Type Reason Age From Message
---- ------ ---- ---- -------
Normal AddedOrUpdated 16s nginx-ingress-controller Configuration for default/cafe was added or updated
๊ตฌ์ฑ์ด ์ฑ๊ณต์ ์ผ๋ก ์ ์ฉ๋์์์ ์๋ฆฌ๋ AddedOrUpdated ์ฌ์ ๊ฐ ์๋ Normal ์ด๋ฒคํธ๊ฐ ์ด๋ฒคํธ ์น์ ์ ์ด๋ป๊ฒ ํฌํจ๋์ด ์๋์ง ํ์ธํ์ญ์์ค.
์๋ชป๋ ๋ฆฌ์์ค๋ฅผ ์์ฑํ๋ฉด Ingress Controller๊ฐ ์ด๋ฅผ ๊ฑฐ๋ถํ๊ณ Rejected ์ด๋ฒคํธ๋ฅผ ๋ด๋ณด๋
๋๋ค. ์๋ฅผ ๋ค์ด, ๊ฐ์ ์ด๋ฆ์ tea๋ฅผ ๊ฐ์ง ๋ ๊ฐ์ Upstream์ด ์๋ VirtualServer cafe๋ฅผ ๋ง๋ค๋ฉด ๋ค์๊ณผ ๊ฐ์ ๊ฒฐ๊ณผ๋ฅผ ์ป๊ฒ ๋ฉ๋๋ค.
$ kubectl describe vs cafe
. . .
Events:
Type Reason Age From Message
---- ------ ---- ---- -------
Warning Rejected 12s nginx-ingress-controller VirtualServer default/cafe is invalid and was rejected: spec.upstreams[1].name: Duplicate value: "tea"
์ด๋ฒคํธ ์น์ ์ Rejected ์ฌ์ ๊ฐ ์๋ ๊ฒฝ๊ณ ์ด๋ฒคํธ๊ฐ ์ด๋ป๊ฒ ํฌํจ๋์ด ์๋์ง ํ์ธํ์ญ์์ค.
๋ํ ์ด ์ ๋ณด๋ VirtualServer ๋ฆฌ์์ค์ status ํ๋์์๋ ์ฌ์ฉํ ์ ์์ต๋๋ค. VirtualServer์ ์ํ ์น์
์ ์ ์ํ์ญ์์ค.
$ kubectl describe vs cafe
. . .
Status:
External Endpoints:
Ip: 12.13.23.123
Ports: [80,443]
Message: VirtualServer default/cafe is invalid and was rejected: spec.upstreams[1].name: Duplicate value: "tea"
Reason: Rejected
State: Invalid
Ingress Controller๋ ์ ์ฌํ ๋ฐฉ์์ผ๋ก VirtualServerRoute ๋ฆฌ์์ค์ ์ ํจ์ฑ์ ๊ฒ์ฌํฉ๋๋ค.
Note: ๊ธฐ์กด ๋ฆฌ์์ค๋ฅผ ์ ํจํ์ง ์๊ฒ ๋ง๋ค๋ฉด Ingress Controller๋ ์ด๋ฅผ ๊ฑฐ๋ถํ๊ณ NGINX์์ ํด๋น ๊ตฌ์ฑ์ ์ ๊ฑฐํฉ๋๋ค.
5. ConfigMap์ ํตํ ์ฌ์ฉ์ ์ ์
ConfigMap์ ์ฌ์ฉํ์ฌ VirtualServer ๋ฐ VirtualServerRoutes ๋ฆฌ์์ค์ ๋ํ NGINX ๊ตฌ์ฑ์ ์ฌ์ฉ์ ์ ์ํ ์ ์์ต๋๋ค. ๋ค์์ ์ ์ธํ๊ณ ๋๋ถ๋ถ์ ConfigMap Key๊ฐ ์ง์๋ฉ๋๋ค.
proxy-hide-headersproxy-pass-headershstshsts-max-agehsts-include-subdomainshsts-behind-proxyredirect-to-httpsssl-redirect