HostPort 被命名空间 PodSecurity baseline 拒绝,因此恢复无特权 Pod 配置,并为宁波、香港的 API/Web 增加只选择本站 Pod 的专属 NodePort Service。双 NGINX 和验收脚本按站点使用 31088/31089 与 31178/31179,避免主机本地访问共享 NodePort 时随机命中不可达的跨站 Pod。\n\n验证:kubectl kustomize、服务端 dry-run、bash -n、ShellCheck、无 hostPort/hostIP、git diff --check。
107 lines
3.1 KiB
Plaintext
107 lines
3.1 KiB
Plaintext
upstream easyai_gateway_api {
|
|
least_conn;
|
|
keepalive 64;
|
|
server 10.77.0.1:31088 max_fails=2 fail_timeout=5s;
|
|
server 10.77.0.2:31089 max_fails=2 fail_timeout=5s;
|
|
}
|
|
|
|
upstream easyai_gateway_web {
|
|
least_conn;
|
|
keepalive 32;
|
|
server 10.77.0.1:31178 max_fails=2 fail_timeout=5s;
|
|
server 10.77.0.2:31179 max_fails=2 fail_timeout=5s;
|
|
}
|
|
|
|
server {
|
|
listen 80;
|
|
listen [::]:80;
|
|
server_name ai.51easyai.com;
|
|
return 301 https://$host$request_uri;
|
|
}
|
|
|
|
server {
|
|
listen 443 ssl http2;
|
|
listen [::]:443 ssl http2;
|
|
server_name ai.51easyai.com;
|
|
|
|
ssl_certificate /etc/nginx/tls/ai.51easyai.com/fullchain.pem;
|
|
ssl_certificate_key /etc/nginx/tls/ai.51easyai.com/privkey.pem;
|
|
ssl_session_cache shared:easyai_gateway_tls:10m;
|
|
ssl_session_timeout 1d;
|
|
ssl_protocols TLSv1.2 TLSv1.3;
|
|
|
|
client_max_body_size 200m;
|
|
client_body_timeout 300s;
|
|
|
|
include /etc/nginx/easyai-ai-gateway/legacy-static.inc;
|
|
|
|
location = /api/v1/metrics {
|
|
return 404;
|
|
}
|
|
|
|
location ^~ /api/v1/ {
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Forwarded-Proto https;
|
|
proxy_set_header Connection "";
|
|
proxy_connect_timeout 2s;
|
|
proxy_send_timeout 3600s;
|
|
proxy_read_timeout 3600s;
|
|
proxy_request_buffering off;
|
|
proxy_buffering off;
|
|
proxy_next_upstream error timeout http_502 http_503 http_504;
|
|
proxy_next_upstream_tries 2;
|
|
proxy_pass http://easyai_gateway_api;
|
|
}
|
|
|
|
location /gateway-api/ {
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Forwarded-Proto https;
|
|
proxy_set_header Connection "";
|
|
proxy_connect_timeout 2s;
|
|
proxy_send_timeout 3600s;
|
|
proxy_read_timeout 3600s;
|
|
proxy_request_buffering off;
|
|
proxy_buffering off;
|
|
proxy_next_upstream error timeout http_502 http_503 http_504;
|
|
proxy_next_upstream_tries 2;
|
|
proxy_pass http://easyai_gateway_api/;
|
|
}
|
|
|
|
location ^~ /static/ {
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Forwarded-Proto https;
|
|
proxy_set_header Connection "";
|
|
proxy_connect_timeout 2s;
|
|
proxy_send_timeout 300s;
|
|
proxy_read_timeout 300s;
|
|
proxy_buffering off;
|
|
proxy_next_upstream error timeout http_502 http_503 http_504;
|
|
proxy_next_upstream_tries 2;
|
|
proxy_pass http://easyai_gateway_api;
|
|
}
|
|
|
|
location / {
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Forwarded-Proto https;
|
|
proxy_set_header Connection "";
|
|
proxy_connect_timeout 2s;
|
|
proxy_send_timeout 300s;
|
|
proxy_read_timeout 300s;
|
|
proxy_next_upstream error timeout http_502 http_503 http_504;
|
|
proxy_next_upstream_tries 2;
|
|
proxy_pass http://easyai_gateway_web;
|
|
}
|
|
}
|