This is a HTTP reverse proxy for Kubernetes based on Nginx and confd.
To run this container, you need Kubernetes v0.15.0 or later and access to the etcd cluster on which Kubernetes operates.
docker run -e CONFD_ETCD_NODE=<etcd-address>:<etcd-port> -p 80:80 -p 443:443 noonien/kube-http-proxy
The reverse proxy is configured using Kubernetes annotations on services.
The configuration is stored as serialized JSON strings. Two annotations are supported:
http-proxy-servers:
[
{
"host": "some.example.com",
"names": ["some.other.example.com"],
"port": "8080",
"targetPort": "3000",
"default": true,
"targetPath": "proxy",
"pathOptions": ["proxy_pass_request_headers on"],
},
{
"host": "another.example.com",
"port": "8000",
"ssl": true,
"sslPort": "8443",
"path": "/somewhere/",
"webSocket": true
},
]
Field:
http-proxy-paths:
{
"some.example.com": [
{
"path": "/somewhere/",
"targetPort": "3000",
"webSocket": true
},
{
"path": "/somewhere/else/",
"targetPort": "3000",
"options": ["proxy_pass_request_headers on"],
}
],
"another.example.com": [
{
"path": "/api/",
"targetPort": "8080",
"targetPath": "proxy",
}
]
}
Fields:
Example service.yaml
apiVersion: v1beta3
kind: List
items:
- kind: Service
apiVersion: v1beta3
metadata:
name: test-proxy
annotations:
http-proxy-servers: '[{"host": "some.example.com"}]'
spec:
selector:
name: test-pod
ports:
- port: 80
targetPort: http
- kind: Service
apiVersion: v1beta3
metadata:
name: test-proxy-api
annotations:
http-proxy-paths: '{"some.example.com": [{"path": "/api/", "targetPort": 8080}]}'
spec:
selector:
name: test-pod-api
ports:
- port: 8080
targetPort: api
This container should be ran outside of kubernetes because due to kube-proxy, client IPs are obscured. Here's a service file that can be used to launch this container:
[Unit]
Description=Kubernetes HTTP Reverse Proxy
Documentation=https://github.com/noonien/kube-http-proxy
Requires=docker.service
Requires=etcd2.service
After=docker.service
After=etcd2.service
[Service]
EnvironmentFile=/etc/network-environment
ExecStartPre=-/usr/bin/docker rm -f kube-http-proxy
ExecStart=/usr/bin/docker run -e CONFD_ETCD_NODE=${DEFAULT_IPV4}:4001 -p 443:443 -p 80:80 --name kube-http-proxy noonien/kube-http-proxy
Restart=always
RestartSec=10
This example uses setup-network-environment to get the correct IP address of the etcd server.
Content type
Image
Digest
sha256:eaba30a92…
Size
131.4 MB
Last updated
over 10 years ago
docker pull noonien/kube-http-proxy