メインコンテンツへスキップ

StorageGRIDをサードパーティのレイヤー7ロードバランサーのIPベースで動作するように設定する方法

Views:
97
Visibility:
Public
Votes:
0
Category:
storagegrid
Specialty:
sgrid
Last Updated:

環境

  • StorageGRID アプライアンス
  • StorageGRID 11.4以降
  • IP based

概要

  • この記事は、NGINX や HAProxy などの外部レイヤー 7 ロード バランサーを 1 つ以上使用し、S3 バケットまたはグループ ポリシーがIP ベース の場合、StorageGRID 11.4.0 以降に適用されます。StorageGRID は実際の送信者の IP アドレスを特定する必要があります。
  • 外部(サードパーティ)レイヤー7ロードバランサーを使用してストレージノードにリクエストをルーティングする場合、StorageGRIDは実際の送信者のIPアドレスを特定する必要があります。これは、ロードバランサーによってリクエストに挿入されるX-Forwarded-For(XFF)ヘッダーを確認することで行われます。
  • X-Forwarded-Forヘッダーは、ストレージノードに直接送信されるリクエストでは簡単に偽装できるため、StorageGRIDは各リクエストが信頼できるレイヤー7ロードバランサーによってルーティングされていることを確認する必要があります。StorageGRIDがリクエストの送信元を信頼できない場合、X-Forwarded-Forヘッダーは無視されます。
  • StorageGRID 11.4以降では、信頼できる外部レイヤー7ロードバランサーのリストを設定できる新しいグリッド管理APIが追加されました。この新しいAPIは非公開であり、将来のStorageGRIDリリースで変更される可能性があります。

 

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.