ARTICLE DETAIL

资讯详情

深耕网站建设与运营推广的一线实战洞察。

K8s集群SpringCloudZuul网关部署管理实操

K8s集群SpringCloudZuul网关部署管理实操 K8s集群SpringCloudZuul网关部署管理实操技术栈Spring Cloud Zuul v1.x Kubernetes v1.32.13 Rocky Linux 8.6 Eureka/Nacos Java 17操作环境 / 对接原理 / 详细步骤 / 完整命令 / 配置文件 / 验证流程 / 排错方案K8s集群SpringCloudZuul网关部署管理实操操作环境Zuul 网关服务Spring Boot 2.7 Spring Cloud 2021K8s 集群 v1.32.13Rocky Linux 8.6注册中心 Nacos 2.x 或 Eureka后端微服务user-service/order-service/product-serviceJDK 17Maven 3.9镜像已推送到 HarborZuul 部署在 default 命名空间3副本kubectl v1.32.13应用日志输出到标准输出对接原理Zuul 是 Netflix 开源的 JVM 网关Spring Cloud 集成提供声明式路由和过滤器机制适合 Java 微服务体系。核心机制过滤器Filter是 Zuul 的核心分为 PRE路由前认证/限流/日志、ROUTING路由中请求转发、POST路由后响应修改/日志、ERROR错误处理四种类型通过 shouldFilter() 判断是否执行run() 实现逻辑。路由配置通过 zuul.routes 配置服务路由支持 serviceId服务发现自动路由和 url直接URL两种方式配合 Eureka/Nacos 实现服务发现和负载均衡Ribbon。Zuul 1.x 是阻塞式 IOServletZuul 2.x 是异步非阻塞NettySpring Cloud 主要集成 Zuul 1.x。熔断集成 Hystrix降级方法在 fallback 中实现。K8s 部署Zuul 无状态多副本Service LoadBalancer 暴露通过 ConfigMap 动态配置路由RefreshScope Spring Cloud Config。注意Spring Cloud 已推荐使用 Spring Cloud GatewayWebFlux 异步替代 Zuul但 Zuul 仍广泛用于存量系统。详细步骤1. Zuul网关部署到K8s# 1. 创建Spring Boot Zuul项目 # pom.xml依赖 cat pom.xml EOF dependency groupIdorg.springframework.cloud/groupId artifactIdspring-cloud-starter-netflix-zuul/artifactId /dependency dependency groupIdorg.springframework.cloud/groupId artifactIdspring-cloud-starter-netflix-eureka-client/artifactId /dependency EOF # 启动类 cat ZuulApplication.java EOF SpringBootApplication EnableZuulProxy EnableDiscoveryClient public class ZuulApplication { public static void main(String[] args) { SpringApplication.run(ZuulApplication.class, args); } } EOF # application.yml cat application.yml EOF server: port: 8080 spring: application: name: zuul-gateway cloud: nacos: discovery: server-addr: nacos.default.svc:8848 zuul: routes: user: path: /user/** serviceId: user-service order: path: /order/** serviceId: order-service sensitive-headers: add-host-header: true ribbon: ReadTimeout: 5000 ConnectTimeout: 2000 hystrix: command: default: execution: isolation: thread: timeoutInMilliseconds: 10000 EOF # 构建镜像 mvn clean package -DskipTests docker build -t harbor.example.com/default/zuul-gateway:v1 . docker push harbor.example.com/default/zuul-gateway:v1 # K8s部署 cat zuul-deploy.yaml EOF apiVersion: apps/v1 kind: Deployment metadata: name: zuul-gateway spec: replicas: 3 selector: matchLabels: app: zuul-gateway template: metadata: labels: app: zuul-gateway spec: containers: - name: zuul image: harbor.example.com/default/zuul-gateway:v1 ports: - containerPort: 8080 resources: requests: {cpu: 500m, memory: 1Gi} limits: {cpu: 2, memory: 2Gi} livenessProbe: httpGet: {path: /actuator/health, port: 8080} initialDelaySeconds: 60 readinessProbe: httpGet: {path: /actuator/health, port: 8080} --- apiVersion: v1 kind: Service metadata: name: zuul-gateway spec: type: LoadBalancer selector: app: zuul-gateway ports: - port: 80 targetPort: 8080 EOF kubectl apply -f zuul-deploy.yaml验证流程# 1. 验证Zuul启动 kubectl get pods -l appzuul-gateway # Running # 2. 验证健康检查 curl http://zuul-gateway/actuator/health # {status:UP} # 3. 验证路由 curl http://zuul-gateway/user/api/users # 返回用户服务响应 # 4. 验证过滤器 # 无token返回401有token返回200 # 5. 验证限流 for i in {1..110}; do curl -s -o /dev/null -w %{http_code}\n http://zuul/api; done | grep 429 # 6. 验证熔断 # 停止后端服务访问返回降级响应 # 7. 验证灰度 curl -H X-Canary: true http://zuul/user/version # 返回v2排错方案路由404检查zuul.routes配置path是否匹配serviceId是否在注册中心ignored-services是否排除了服务stripPrefix配置actuator/routes查看实际路由500内部错误查看Zuul日志后端服务异常过滤器run()抛出异常ERROR过滤器是否处理Hystrix超时Ribbon连接失败服务不可用502检查后端服务是否注册到Nacos/Eureka服务实例是否健康Ribbon是否获取到服务列表网络是否连通端口是否正确超时调整ribbon.ReadTimeout/ConnectTimeouthystrix.timeoutInMilliseconds后端响应慢需优化Zuul线程池大小增加副本过滤器不执行检查filterType是否正确shouldFilter()返回truefilterOrder顺序Component是否被Spring扫描是否有异常被吞掉熔断不恢复检查circuitBreaker.sleepWindowInMilliseconds后端是否恢复健康错误率是否降到阈值以下Hystrix dashboard查看状态动态配置不刷新检查RefreshScopeNacos Config是否配置bootstrap.yml优先级发布配置是否成功actuator/refresh手动刷新性能瓶颈Zuul 1.x阻塞IO增加副本数调大tomcat max-threadsJVM堆内存异步处理非核心逻辑考虑迁移到Spring Cloud Gateway
返回列表