Kubernetes中Ingress超时由Ingress Controller(如nginx-ingress-controller)实现,通过Annotations配置proxy-connect-timeout、proxy-send-timeout、proxy-read-timeout和proxy-buffering等参数控制连接、发送、读取及缓冲行为,注解优先级高于ConfigMap全局设置。

在 Kubernetes 中,Ingress 本身不直接处理超时逻辑,真正起作用的是背后的 Ingress Controller(如 nginx-ingress-controller)。超时行为由 Nginx 的 proxy 指令控制,而这些指令可通过 Annotations 注入到生成的 Nginx 配置中。
关键超时 Annotations 列表
以下注解需写在 Ingress 资源的 metadata.annotations 下,适用于 kubernetes/ingress-nginx v1.0+ 版本:
- nginx.ingress.kubernetes.io/proxy-connect-timeout:与后端 Service 建立连接的最长等待时间(单位:秒),默认 60。适合应对后端启动慢或网络延迟高场景。
- nginx.ingress.kubernetes.io/proxy-send-timeout:从 Ingress 向后端发送完整请求体的超时时间(单位:秒),默认 60。大文件上传、长耗时 POST 请求需调大。
- nginx.ingress.kubernetes.io/proxy-read-timeout:Ingress 等待后端响应的最长时间(单位:秒),默认 60。导出报表、批量计算等长响应业务必须延长此值。
-
nginx.ingress.kubernetes.io/proxy-buffering:是否启用 Nginx 缓冲(
"on"或"off")。设为"off"可避免缓冲导致的响应延迟感知失真,但会增加连接占用。
配置示例(YAML)
以下 Ingress 配置将读取超时设为 300 秒,连接和发送超时各为 120 秒:
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: my-app-ingress
annotations:
nginx.ingress.kubernetes.io/proxy-connect-timeout: "120"
nginx.ingress.kubernetes.io/proxy-send-timeout: "120"
nginx.ingress.kubernetes.io/proxy-read-timeout: "300"
spec:
ingressClassName: nginx
rules:
- host: app.example.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: my-app-service
port:
number: 80
注意事项与常见问题
这些注解只影响当前 Ingress 规则对应 location 块中的 upstream 行为,不改变全局 Nginx 设置。若需统一调整所有入口,应通过 ConfigMap 修改 nginx-configuration 中的 proxy-connect-timeout 等字段。
- 数值必须为纯数字字符串(如
"60"),不能带单位或空格; - 若同时设置了 ConfigMap 全局值和 Ingress 注解,注解优先级更高;
- 超时值过大会导致连接堆积,尤其在突发流量下易触发控制器 OOM 或连接拒绝;
- 对于 WebSocket 连接,需额外设置
nginx.ingress.kubernetes.io/websocket-services并确保proxy-read-timeout足够长(建议 ≥ 3600); - 使用
server-snippet或configuration-snippet可实现更底层控制,但需提前在 Ingress Controller 启动参数中开启--allow-snippet-annotations=true,且存在安全风险,生产环境慎用。
验证配置是否生效
进入 Ingress Controller Pod 查看实际生成的 Nginx 配置:
kubectl exec -n ingress-nginx deploy/ingress-nginx-controller -- cat /etc/nginx/nginx.conf | grep -A5 "location /" | grep timeout
输出中应包含类似 proxy_connect_timeout 120s; 的行。也可用 curl -v 观察响应头中的 X-Upstream-Status 和连接中断时机,辅助判断超时是否按预期触发。


















