fix(deploy): 使用站点专属 NodePort
HostPort 被命名空间 PodSecurity baseline 拒绝,因此恢复无特权 Pod 配置,并为宁波、香港的 API/Web 增加只选择本站 Pod 的专属 NodePort Service。双 NGINX 和验收脚本按站点使用 31088/31089 与 31178/31179,避免主机本地访问共享 NodePort 时随机命中不可达的跨站 Pod。\n\n验证:kubectl kustomize、服务端 dry-run、bash -n、ShellCheck、无 hostPort/hostIP、git diff --check。
This commit is contained in:
@@ -2,14 +2,14 @@ upstream easyai_gateway_api {
|
||||
least_conn;
|
||||
keepalive 64;
|
||||
server 10.77.0.1:31088 max_fails=2 fail_timeout=5s;
|
||||
server 10.77.0.2:31088 max_fails=2 fail_timeout=5s;
|
||||
server 10.77.0.2:31089 max_fails=2 fail_timeout=5s;
|
||||
}
|
||||
|
||||
upstream easyai_gateway_web {
|
||||
least_conn;
|
||||
keepalive 32;
|
||||
server 10.77.0.1:31178 max_fails=2 fail_timeout=5s;
|
||||
server 10.77.0.2:31178 max_fails=2 fail_timeout=5s;
|
||||
server 10.77.0.2:31179 max_fails=2 fail_timeout=5s;
|
||||
}
|
||||
|
||||
server {
|
||||
|
||||
Reference in New Issue
Block a user