GKE ingress controller annotations for proxy body size, buffer size and sever snippets

Viewed 563

I am using nginx ingress class presently. I want to change this to gce type ingress class. I have used many annotations in ingress with nginx type, but I couldn't find the matching annotations for gce type. I have listed the annotations below which I have used with nginx type ingress:

nginx.ingress.kubernetes.io/affinity: cookie
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/large-client-header-buffers: "4 16k"
nginx.ingress.kubernetes.io/proxy-buffer-size: "128k"
nginx.ingress.kubernetes.io/proxy-body-size: "25m"
nginx.ingress.kubernetes.io/configuration-snippet: |
    more_clear_headers "Server"
    more_clear_headers "X-Powered-By";
    more_set_headers "Feature-Policy: accelerometer 'none'; camera 'none'; geolocation 'none'; gyroscope 'none'; magnetometer 'none'; microphone 'none'; payment 'none'; usb 'none'"
    more_set_headers "Referrer-Policy: no-referrer"
    more_set_headers "X-Content-Type-Options: nosniff"
    more_set_headers "X-Frame-Options: DENY"
    more_set_headers "X-Permitted-Cross-Domain-Policies: none"
    more_set_headers "X-Xss-Protection: 1; mode=block";
nginx.org/server-snippets: gzip on;

I couldn't find an exact replacement for these annotations in gce. Also gce type ingress class has limited annotations only as per the documentation. But somehow I have managed to use some annotations in a different way:

  1. affinity - using ingress 'session_affinity' backend configuration, I have achieved this. But still some properties are not applied when using this way. Refer this post and this.
  2. force-ssl-redirect - using ingress 'https_redirect' frontend configuration, I have achieved this.
  3. configuration-snippet - using ingress 'custom_request_headers' backend configuration, I have achieved this. But clearing the response header is not possible here, only we can set some headers.

I can't find a replacement for other annotations such as large-client-header-buffers, proxy-buffer-size, proxy-body-size, server-snippets in gce type ingress. Anyone faced or know about this case? Could you help me to come out of this?

Note: As we are planning to configure cloud armor, we are doing this change. Because, for HTTP(S) type load balancers only we can enable cloud armor, if we create load balancer using nginx type ingress class it will create TCP type load balancer by default.

Can anyone suggest us how to use these annotations with gce type ingress? Or is there any way to configure cloud armor with nginx type ingress?

1 Answers

As per Gari suggested: if there are no supported annotations in GCE to use it instead of Nginx, then there is no other possible solution, except waiting for the feature implementation that is submitted in Buganizer. However, it was submitted 2 years ago and there are ping messages from last month. Let's wait for any update in this thread.

Note that Cloud Armor is a feature for GKE that only the GCE ingress controller supports. We try to only support features that are portable between cloud providers and baremetal

Please also note that:

Currently, GCP does not support 3rd party ingresses like Nginx for Cloud Armor and won't be filtered for DDoS attacks.

Related