From 6897fb3b66510f0104ece3ce76c0bf0ed84382f6 Mon Sep 17 00:00:00 2001 From: wangbo Date: Wed, 29 Jul 2026 02:40:57 +0800 Subject: [PATCH] =?UTF-8?q?fix(deploy):=20=E4=BD=BF=E7=94=A8=E7=AB=99?= =?UTF-8?q?=E7=82=B9=E4=B8=93=E5=B1=9E=20NodePort?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit HostPort 被命名空间 PodSecurity baseline 拒绝,因此恢复无特权 Pod 配置,并为宁波、香港的 API/Web 增加只选择本站 Pod 的专属 NodePort Service。双 NGINX 和验收脚本按站点使用 31088/31089 与 31178/31179,避免主机本地访问共享 NodePort 时随机命中不可达的跨站 Pod。\n\n验证:kubectl kustomize、服务端 dry-run、bash -n、ShellCheck、无 hostPort/hostIP、git diff --check。 --- .../easyai-ai-gateway-cluster-release | 20 +++- deploy/kubernetes/production/application.yaml | 92 +++++++++++++++++-- deploy/nginx/ai.51easyai.com-cluster.conf | 4 +- scripts/cluster/migrate-production.sh | 9 +- scripts/cluster/run-cross-node-file-e2e.sh | 2 +- 5 files changed, 107 insertions(+), 20 deletions(-) diff --git a/deploy/kubernetes/easyai-ai-gateway-cluster-release b/deploy/kubernetes/easyai-ai-gateway-cluster-release index d6d398d..d262e6e 100755 --- a/deploy/kubernetes/easyai-ai-gateway-cluster-release +++ b/deploy/kubernetes/easyai-ai-gateway-cluster-release @@ -64,14 +64,24 @@ wait_for_url() { verify_site() { local site=$1 local address + local api_port + local web_port case $site in - hongkong) address=10.77.0.2 ;; - ningbo) address=10.77.0.1 ;; + hongkong) + address=10.77.0.2 + api_port=31089 + web_port=31179 + ;; + ningbo) + address=10.77.0.1 + api_port=31088 + web_port=31178 + ;; *) return 1 ;; esac - wait_for_url "$site API health" "http://$address:31088/api/v1/healthz" easyai-ai-gateway - wait_for_url "$site API readiness" "http://$address:31088/api/v1/readyz" '"ok":true' - wait_for_url "$site Web" "http://$address:31178/" 'EasyAI AI Gateway' + wait_for_url "$site API health" "http://$address:$api_port/api/v1/healthz" easyai-ai-gateway + wait_for_url "$site API readiness" "http://$address:$api_port/api/v1/readyz" '"ok":true' + wait_for_url "$site Web" "http://$address:$web_port/" 'EasyAI AI Gateway' } rollout_site() { diff --git a/deploy/kubernetes/production/application.yaml b/deploy/kubernetes/production/application.yaml index 2ef4968..6072027 100644 --- a/deploy/kubernetes/production/application.yaml +++ b/deploy/kubernetes/production/application.yaml @@ -59,8 +59,6 @@ spec: ports: - name: http containerPort: 8088 - hostIP: 10.77.0.1 - hostPort: 31088 readinessProbe: httpGet: path: /api/v1/readyz @@ -167,8 +165,6 @@ spec: ports: - name: http containerPort: 8088 - hostIP: 10.77.0.2 - hostPort: 31088 readinessProbe: httpGet: path: /api/v1/readyz @@ -261,8 +257,6 @@ spec: ports: - name: http containerPort: 80 - hostIP: 10.77.0.1 - hostPort: 31178 readinessProbe: httpGet: path: / @@ -352,8 +346,6 @@ spec: ports: - name: http containerPort: 80 - hostIP: 10.77.0.2 - hostPort: 31178 readinessProbe: httpGet: path: / @@ -434,6 +426,90 @@ spec: targetPort: http nodePort: 30178 --- +apiVersion: v1 +kind: Service +metadata: + name: api-ningbo-edge + labels: + app.kubernetes.io/name: easyai-api + app.kubernetes.io/component: api + app.kubernetes.io/part-of: easyai-ai-gateway + easyai.io/site: ningbo +spec: + type: NodePort + externalTrafficPolicy: Local + selector: + app.kubernetes.io/name: easyai-api + easyai.io/site: ningbo + ports: + - name: http + port: 8088 + targetPort: http + nodePort: 31088 +--- +apiVersion: v1 +kind: Service +metadata: + name: api-hongkong-edge + labels: + app.kubernetes.io/name: easyai-api + app.kubernetes.io/component: api + app.kubernetes.io/part-of: easyai-ai-gateway + easyai.io/site: hongkong +spec: + type: NodePort + externalTrafficPolicy: Local + selector: + app.kubernetes.io/name: easyai-api + easyai.io/site: hongkong + ports: + - name: http + port: 8088 + targetPort: http + nodePort: 31089 +--- +apiVersion: v1 +kind: Service +metadata: + name: web-ningbo-edge + labels: + app.kubernetes.io/name: easyai-web + app.kubernetes.io/component: web + app.kubernetes.io/part-of: easyai-ai-gateway + easyai.io/site: ningbo +spec: + type: NodePort + externalTrafficPolicy: Local + selector: + app.kubernetes.io/name: easyai-web + easyai.io/site: ningbo + ports: + - name: http + port: 80 + targetPort: http + nodePort: 31178 +--- +apiVersion: v1 +kind: Service +metadata: + name: web-hongkong-edge + labels: + app.kubernetes.io/name: easyai-web + app.kubernetes.io/component: web + app.kubernetes.io/part-of: easyai-ai-gateway + easyai.io/site: hongkong +spec: + type: NodePort + externalTrafficPolicy: Local + selector: + app.kubernetes.io/name: easyai-web + easyai.io/site: hongkong + ports: + - name: http + port: 80 + targetPort: http + nodePort: 31179 +--- apiVersion: policy/v1 kind: PodDisruptionBudget metadata: diff --git a/deploy/nginx/ai.51easyai.com-cluster.conf b/deploy/nginx/ai.51easyai.com-cluster.conf index b1d9bae..d3f31e1 100644 --- a/deploy/nginx/ai.51easyai.com-cluster.conf +++ b/deploy/nginx/ai.51easyai.com-cluster.conf @@ -2,14 +2,14 @@ upstream easyai_gateway_api { least_conn; keepalive 64; server 10.77.0.1:31088 max_fails=2 fail_timeout=5s; - server 10.77.0.2:31088 max_fails=2 fail_timeout=5s; + server 10.77.0.2:31089 max_fails=2 fail_timeout=5s; } upstream easyai_gateway_web { least_conn; keepalive 32; server 10.77.0.1:31178 max_fails=2 fail_timeout=5s; - server 10.77.0.2:31178 max_fails=2 fail_timeout=5s; + server 10.77.0.2:31179 max_fails=2 fail_timeout=5s; } server { diff --git a/scripts/cluster/migrate-production.sh b/scripts/cluster/migrate-production.sh index 2fb492f..75abab2 100755 --- a/scripts/cluster/migrate-production.sh +++ b/scripts/cluster/migrate-production.sh @@ -329,13 +329,14 @@ echo '[cutover] starting both application sites with River workers frozen' AI_GATEWAY_ACTIVATE_WORKERS=false \ "$script_dir/bootstrap-platform.sh" activate "$release_manifest" -for site_ip in 10.77.0.1 10.77.0.2; do +for site_endpoint in 10.77.0.1:31088:31178 10.77.0.2:31089:31179; do + IFS=: read -r site_ip api_port web_port <<<"$site_endpoint" cluster_ssh "$CLUSTER_NINGBO_HOST" \ - "curl -fsS --max-time 10 http://$site_ip:31088/api/v1/healthz >/dev/null" + "curl -fsS --max-time 10 http://$site_ip:$api_port/api/v1/healthz >/dev/null" cluster_ssh "$CLUSTER_NINGBO_HOST" \ - "curl -fsS --max-time 10 http://$site_ip:31088/api/v1/readyz | grep -q '\"ok\":true'" + "curl -fsS --max-time 10 http://$site_ip:$api_port/api/v1/readyz | grep -q '\"ok\":true'" cluster_ssh "$CLUSTER_NINGBO_HOST" \ - "curl -fsS --max-time 10 http://$site_ip:31178/ | grep -q 'EasyAI AI Gateway'" + "curl -fsS --max-time 10 http://$site_ip:$web_port/ | grep -q 'EasyAI AI Gateway'" done "$script_dir/install-nginx-edges.sh" activate diff --git a/scripts/cluster/run-cross-node-file-e2e.sh b/scripts/cluster/run-cross-node-file-e2e.sh index 313b4f8..bfd1fed 100755 --- a/scripts/cluster/run-cross-node-file-e2e.sh +++ b/scripts/cluster/run-cross-node-file-e2e.sh @@ -32,7 +32,7 @@ k3s kubectl set env deployment/easyai-api-ningbo -n easyai \ AI_GATEWAY_ASYNC_QUEUE_WORKER_ENABLED=false >/dev/null k3s kubectl rollout status deployment/easyai-api-ningbo -n easyai --timeout=300s curl -fsS http://10.77.0.1:31088/api/v1/readyz | grep -q '"ok":true' -curl -fsS http://10.77.0.2:31088/api/v1/readyz | grep -q '"ok":true' +curl -fsS http://10.77.0.2:31089/api/v1/readyz | grep -q '"ok":true' REMOTE credentials_file=$(mktemp "$cluster_root/.local-secrets/cluster/e2e.XXXXXX")