SkillAtlasSkill 详情

kubesphere-gateway

The container platform tailored for Kubernetes multi-cloud, datacenter, and edge management

审核状态:已审核Quality 72Security 70

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年8月1日

banner

The container platform tailored for Kubernetes multi-cloud, datacenter, and edge management

A+ good first issue follow on Twitter


What is KubeSphere

English | 中文

KubeSphere is a distributed operating system for cloud-native application management, using Kubernetes as its kernel. It provides a plug-and-play architecture, allowing third-party applications to be seamlessly integrated into its ecosystem. KubeSphere is also a multi-tenant container platform with full-stack automated IT operation and streamlined DevOps workflows. It provides developer-friendly wizard web UI, helping enterprises to build out a more robust and feature-rich platform, which includes most common functionalities needed for enterprise Kubernetes strategy, see Feature List for details.

The following screenshots give a close insight into KubeSphere. Please check What is KubeSphere for further information.

WorkbenchProject Resources
CI/CD PipelineApp Store

Demo environment

🎮 KubeSphere Lite provides you with free, stable, and out-of-the-box managed cluster service. After registration and login, you can easily create a K8s cluster with KubeSphere installed in only 5 seconds and experience feature-rich KubeSphere.

🖥 You can view the Demo Video to get started with KubeSphere.

Features

🧩 Extensible Architecture Designed for flexibility, supporting plugin-based extensions and seamless integrations. Easily customize and expand functionalities to meet evolving needs. Learn more.
🕸 Provisioning Kubernetes Cluster Support deploy Kubernetes on any infrastructure, support online and air-gapped installation. Learn more.
🔗 Kubernetes Multi-cluster Management Provide a centralized control plane to manage multiple Kubernetes clusters, and support the ability to propagate an app to multiple K8s clusters across different cloud providers.
🤖 Kubernetes DevOps Provide GitOps-based CD solutions and use Argo CD to provide the underlying support, collecting CD status information in real time. With the mainstream CI engine Jenkins integrated, DevOps has never been easier. Learn more.
🔎 Cloud Native Observability Multi-dimensional monitoring, events and auditing logs are supported; multi-tenant log query and collection, alerting and notification are built-in. Learn more.
🌐 Service Mesh (Istio-based) Provide fine-grained traffic management, observability and tracing for distributed microservice applications, provides visualization for traffic topology. Learn more.
💻 App Store Provide an App Store for Helm-based applications, and offer application lifecycle management on Kubernetes platform. Learn more.
💡 Edge Computing Platform KubeSphere integrates KubeEdge to enable users to deploy applications on the edge devices and view logs and monitoring metrics of them on the console. Learn more.
🗃 Support Multiple Storage and Networking Solutions
  • Support GlusterFS, CephRBD, NFS, LocalPV solutions, and provide CSI plugins to consume storage from multiple cloud providers.
  • Provide Load Balancer Implementation OpenELB for Kubernetes in bare-metal, edge, and virtualization.
  • Provides network policy and Pod IP pools management, support Calico, Flannel, Kube-OVN
  • ..
    🏢 Multi-Tenancy Isolated workspaces with role-based access control ensure secure resource sharing across multiple tenants. Supports fine-grained permissions and quota management. Learn more.
    🧠 GPU Workloads Scheduling and Monitoring Create GPU workloads on the GUI, schedule GPU resources, and manage GPU resource quotas by tenant.

    Architecture

    KubeSphere 4.x adopts a microkernel + extension components architecture (codename LuBan). The core part (KubeSphere Core) only includes the essential basic functions required for system operation, with independent functional modules split and provided in the form of extension components. Users can dynamically manage the extension components during system operation. With the extension capabilities, KubeSphere can support more application scenarios and meet the needs of different users.

    Architecture


    Latest release

    🎉 KubeSphere v4.1.2 was released! It brings enhancements and better user experience, see the Release Notes For 4.1.2 for the updates.

    Installation

    KubeSphere can run anywhere from on-premise datacenter to any cloud to edge. In addition, it can be deployed on any version-compatible Kubernetes cluster. KubeSphere consumes very few resources, and you can optionally install additional extensions after installation.

    Quick start

    Installing on K8s

    Run the following commands to install KubeSphere on an existing Kubernetes cluster:

    helm upgrade --install -n kubesphere-system --create-namespace ks-core https://charts.kubesphere.io/main/ks-core-1.1.3.tgz --debug --wait
    

    KubeSphere for hosted Kubernetes services

    KubeSphere is hosted on the following cloud providers, and you can try KubeSphere by one-click installation on their hosted Kubernetes services.

    You can also install KubeSphere on other hosted Kubernetes services within minutes, see the step-by-step guides to get started.

    👨‍💻 No internet access? Refer to the Air-gapped Installation.

    Guidance, discussion, contribution, and support

    You can reach the KubeSphere community and developers via the following channels:

    :hugs: Please submit any KubeSphere bugs, issues, and feature requests to KubeSphere GitHub Issue.

    :heart_decoration: The KubeSphere team also provides efficient official ticket support to respond in hours. For more information, click KubeSphere Online Support.

    Contribution

    Code of conduct

    Participation in the KubeSphere community is governed by the Code of Conduct.

    Security

    The security process for reporting vulnerabilities is described in SECURITY.md.

    Who are using KubeSphere

    The user case studies page includes the user list of the project. You can leave a comment to let us know your use case.




        

    KubeSphere is a member of CNCF and a Kubernetes Conformance Certified platform , which enriches the CNCF CLOUD NATIVE Landscape.

    Agent / MCP / Skill 创作

    中风险

    • 来源需自行核对维护者身份。
    • 包含脚本或命令调用,安装前请复核。
    • 可能需要外部 token、网络权限或第三方服务。
    • 未检测到高风险命令。
    • 扫描发现:2 条。

    Codex — Git Clone 安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 克隆仓库:git clone https://github.com/kubesphere/kubesphere.git
    3. 将 "skills/kubesphere-gateway" 文件夹复制到 Codex 的 skills 目录中。
    4. 重启 Codex 让新的 skill 生效。

    Codex — 手动复制安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 从源仓库下载 SKILL.md 及相关文件。
    3. 在 Codex 的 skills 目录中创建新文件夹。
    4. 将所有 skill 文件复制到新文件夹中。
    5. 重启 Codex 让新的 skill 生效。

    Claude Code — Git Clone 安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 克隆仓库:git clone https://github.com/kubesphere/kubesphere.git
    3. 将 "skills/kubesphere-gateway" 文件夹复制到 Claude Code 的 skills 目录中。
    4. 重启 Claude Code 让新的 skill 生效。

    Claude Code — 手动复制安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 从源仓库下载 SKILL.md 及相关文件。
    3. 在 Claude Code 的 skills 目录中创建新文件夹。
    4. 将所有 skill 文件复制到新文件夹中。
    5. 重启 Claude Code 让新的 skill 生效。

    Cursor — Git Clone 安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 克隆仓库:git clone https://github.com/kubesphere/kubesphere.git
    3. 将 "skills/kubesphere-gateway" 文件夹复制到 Cursor 的 skills 目录中。
    4. 重启 Cursor 让新的 skill 生效。

    Cursor — 手动复制安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 从源仓库下载 SKILL.md 及相关文件。
    3. 在 Cursor 的 skills 目录中创建新文件夹。
    4. 将所有 skill 文件复制到新文件夹中。
    5. 重启 Cursor 让新的 skill 生效。

    GitHub Copilot — Git Clone 安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 克隆仓库:git clone https://github.com/kubesphere/kubesphere.git
    3. 将 "skills/kubesphere-gateway" 文件夹复制到 GitHub Copilot 的 skills 目录中。
    4. 重启 GitHub Copilot 让新的 skill 生效。

    GitHub Copilot — 手动复制安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 从源仓库下载 SKILL.md 及相关文件。
    3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
    4. 将所有 skill 文件复制到新文件夹中。
    5. 重启 GitHub Copilot 让新的 skill 生效。

    Windsurf — Git Clone 安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 克隆仓库:git clone https://github.com/kubesphere/kubesphere.git
    3. 将 "skills/kubesphere-gateway" 文件夹复制到 Windsurf 的 skills 目录中。
    4. 重启 Windsurf 让新的 skill 生效。

    Windsurf — 手动复制安装

    1. 安装前请先查看来源仓库和风险报告。
    2. 从源仓库下载 SKILL.md 及相关文件。
    3. 在 Windsurf 的 skills 目录中创建新文件夹。
    4. 将所有 skill 文件复制到新文件夹中。
    5. 重启 Windsurf 让新的 skill 生效。
    查看 SKILL.md 原文
    name: kubesphere-gateway
    description: KubeSphere Gateway extension management Skill (ingress-nginx based, uses Kubernetes Ingress API + Gateway CRD gateway.kubesphere.io/v2alpha2). For the newer Kubernetes Gateway API (Traefik + GatewayProxy CRD), see the kubesphere-gateway-api skill instead. Covers installation, uninstallation, status checks, gateway status inspection, and troubleshooting (gateway stuck states, Helm failures, pod issues).

    KubeSphere Gateway

    Overview

    Provides external access management (ingress) for KubeSphere using ingress-nginx. Supports three-tier gateway management:

    | Tier | Scope | Name Pattern | Namespace | Label | |---|---|---|---| | Cluster | Entire cluster | kubesphere-router-cluster | kubesphere-controls-system | kubesphere.io/gateway-type=cluster | | Workspace | Single workspace | kubesphere-router-workspace-{workspace} | kubesphere-controls-system | kubesphere.io/gateway-type=workspace | | Project | Single project/namespace | kubesphere-router-{namespace} | kubesphere-controls-system | kubesphere.io/gateway-type=project |

    Each gateway is a standalone Helm release of ingress-nginx. The gateway-controller-manager manages the lifecycle (install/upgrade/uninstall) via Helm.

    Core CRDs

    • Gateway (gateway.kubesphere.io/v2alpha2) — represents a single ingress-nginx deployment. Key fields:

      • spec.appVersion — the Helm chart version (e.g. kubesphere-nginx-ingress-<version>)
      • spec.values — Helm values for ingress-nginx (controller config, service type, resources, etc.)
      • status.state — Creating, Updating, Running, Faulted, Stopped
      • status.conditions[].type=GatewayReady — True when fully operational
      • status.loadBalancer — LB ingress IPs/hostnames
      • status.service — Service type, ports, external IPs
    • UpgradePlan (gateway.kubesphere.io/v2alpha2) — batch gateway upgrade job. Key fields:

      • spec.gatewayReferences — list of {name, namespace} to upgrade
      • spec.targetAppVersion — target version
      • status.state — Pending, Running, Succeeded, Failed

    Monitoring Integration

    Gateway exposes NGINX metrics (requests, 4xx/5xx, latency P50/P90/P99) via Prometheus. Requires the whizard-monitoring extension (optional dependency).


    Before You Start

    Check if Gateway extension is already installed:

    kubectl get installplans.kubesphere.io gateway --ignore-not-found
    

    If found, upgrading is supported — just select a newer version in Step 1.


    Installation

    Step 1: Detect and Select Version

    ALL_VERSIONS=$(kubectl get extensionversions.kubesphere.io \
      -l kubesphere.io/extension-ref=gateway \
      -o jsonpath='{range .items[*]}{.spec.version}{"\n"}{end}' | sort -V)
    
    LATEST_STABLE=$(echo "$ALL_VERSIONS" | grep -v -E 'alpha|beta|rc' | tail -1)
    if [ -z "$LATEST_STABLE" ]; then
      LATEST_STABLE=$(echo "$ALL_VERSIONS" | tail -1)
    fi
    
    echo "Available versions:"
    echo "$ALL_VERSIONS"
    echo ""
    echo "Latest stable: $LATEST_STABLE"
    

    This sets ALL_VERSIONS and LATEST_STABLE. Use SELECTED_VERSION for the version chosen.

    Use the question tool:

    • $LATEST_STABLE (Recommended) — accept the auto-detected version
    • (custom) — type a specific version; validate it against the printed list

    Step 2: Detect and Select Clusters

    CLUSTER_DATA=$(kubectl get clusters.cluster.kubesphere.io \
      -o jsonpath='{range .items[*]}{.metadata.name}{"\t"}{.status.conditions[?(@.type=="Ready")].status}{"\n"}{end}')
    
    READY_CLUSTERS=$(echo "$CLUSTER_DATA" | awk -F'\t' '$2 == "True" {print $1}')
    CLUSTER_COUNT=$(echo "$READY_CLUSTERS" | wc -l)
    
    HOST_CLUSTER=$(kubectl get clusters.cluster.kubesphere.io \
      -l 'cluster-role.kubesphere.io/host' \
      -o jsonpath='{.items[0].metadata.name}' || echo "")
    
    echo "Ready clusters:"
    echo "$READY_CLUSTERS"
    echo ""
    echo "Cluster count: $CLUSTER_COUNT"
    echo "Host cluster: $HOST_CLUSTER"
    

    This sets READY_CLUSTERS, CLUSTER_COUNT, HOST_CLUSTER.

    • 1 cluster → skip selection, auto-use it. Set TARGET_CLUSTERS="$HOST_CLUSTER"
    • Multiple clusters → use question with multiple: true:
      • All clusters → TARGET_CLUSTERS="$READY_CLUSTERS"
      • Host cluster only → TARGET_CLUSTERS="$HOST_CLUSTER"
      • (custom) — validate each name against $READY_CLUSTERS

    Step 3: Generate and Apply InstallPlan

    ./scripts/generate-installplan.sh "$SELECTED_VERSION" "$TARGET_CLUSTERS"
    

    This generates the YAML to /tmp/gateway-installplan.yaml, runs --dry-run=server, then prints the apply command.

    For configurable extension values (ingress-nginx default settings, image registry, upgrade tool config, etc.), see references/extension-values.md.

    Apply it:

    kubectl apply -f /tmp/gateway-installplan.yaml
    

    Tell the user "Installing". Then ask if they want to check status. If yes:

    ./scripts/check-status.sh poll
    

    Status Checking

    PurposeCommand
    Single snapshot./scripts/check-status.sh quick
    Wait until complete (5min timeout)./scripts/check-status.sh poll

    Logic:

    • All Installed → ✓ success
    • Any Failed → ✗ prints full status
    • Timeout (300s) → ⚠ prints current status
    • In progress → prints every 10s

    Uninstallation

    ⚠ Always confirm with the user before proceeding.

    Uninstall from all clusters

    if ! kubectl get installplans.kubesphere.io gateway &>/dev/null; then
      echo "Gateway is not installed."
      exit 0
    fi
    

    Confirm with the user, then delete:

    kubectl delete installplans.kubesphere.io gateway --ignore-not-found
    

    Verify cleanup:

    ./scripts/verify-uninstall.sh
    

    Success criteria:

    1. InstallPlan is deleted
    2. No active pods remain in extension-gateway namespace

    Uninstall from specific clusters

    WARNING: Do NOT delete the InstallPlan. Only remove target clusters from the placement list.

    Confirm which clusters to remove, compute remaining clusters, then patch:

    kubectl patch installplans.kubesphere.io gateway --type='json' \
      -p='[{"op": "replace", "path": "/spec/clusterScheduling/placement/clusters", "value": ["<REMAINING_CLUSTER_1>", "<REMAINING_CLUSTER_2>"]}]'
    

    Success: patch returns OK + removed clusters no longer in .status.clusterSchedulingStatuses.


    Gateway Operations

    List Gateways

    Gateways are organized by tier (see Overview), with each tier identified by the label kubesphere.io/gateway-type. List them grouped by tier:

    echo "=== Cluster Gateway ==="
    kubectl get gateways.gateway.kubesphere.io -n kubesphere-controls-system \
      -l kubesphere.io/gateway-type=cluster
    
    echo -e "\n=== Workspace Gateways ==="
    kubectl get gateways.gateway.kubesphere.io -n kubesphere-controls-system \
      -l kubesphere.io/gateway-type=workspace
    
    echo -e "\n=== Project Gateways ==="
    kubectl get gateways.gateway.kubesphere.io -n kubesphere-controls-system \
      -l kubesphere.io/gateway-type=project
    

    Check Gateway Status

    Pick a gateway name from the List Gateways output and run:

    GW_NS="kubesphere-controls-system"
    GW_NAME="<gateway-name-from-list>"
    
    # app.kubernetes.io/instance uses the Helm release name if available, otherwise the Gateway name
    GW_INSTANCE=$(kubectl get gateways.gateway.kubesphere.io -n $GW_NS $GW_NAME -o jsonpath='{.status.helmRelease.name}' 2>/dev/null)
    if [ -z "$GW_INSTANCE" ]; then
      GW_INSTANCE="$GW_NAME"
    fi
    
    kubectl get gateways.gateway.kubesphere.io -n $GW_NS $GW_NAME -o wide
    kubectl describe gateways.gateway.kubesphere.io -n $GW_NS $GW_NAME
    kubectl get gateways.gateway.kubesphere.io -n $GW_NS $GW_NAME -o yaml
    kubectl get pods -n $GW_NS -l "app.kubernetes.io/instance=$GW_INSTANCE"
    

    Gateway states:

    StateMeaning
    CreatingFirst-time Helm install in progress
    UpdatingHelm upgrade in progress (spec changed)
    RunningFully operational (all replicas available)
    FaultedDeployment missing, stopped unexpectedly, or health probe timeout
    StoppedScaled to zero replicas intentionally

    Troubleshooting

    Set $GW_NAME according to the gateway tier being troubleshot (see naming rules in Overview):

    • Cluster → GW_NAME=kubesphere-router-cluster
    • Workspace → GW_NAME=kubesphere-router-workspace-${WORKSPACE}
    • Project → GW_NAME=kubesphere-router-${NAMESPACE}

    Common namespace: GW_NS=kubesphere-controls-system

    $GW_INSTANCE is auto-resolved from status.helmRelease.name (falls back to $GW_NAME). If not yet set, run:

    GW_INSTANCE=$(kubectl get gateways.gateway.kubesphere.io -n $GW_NS $GW_NAME -o jsonpath='{.status.helmRelease.name}' 2>/dev/null)
    if [ -z "$GW_INSTANCE" ]; then
      GW_INSTANCE="$GW_NAME"
    fi
    

    Gateway stuck in Creating or Updating state

    kubectl describe gateways.gateway.kubesphere.io -n $GW_NS $GW_NAME
    
    kubectl logs -n extension-gateway -l app=gateway-controller-manager --tail=200 | grep -iE "(error|helm|install|upgrade|reconcile)"
    
    kubectl get deployment -n $GW_NS -l "app.kubernetes.io/instance=$GW_INSTANCE,app.kubernetes.io/component=controller"
    
    kubectl get configmap -n $GW_NS $GW_NAME -o yaml
    

    Common causes: Chart ConfigMap missing/corrupted, Helm wrapper timeout, invalid spec.values.

    Gateway shows Faulted state

    kubectl get deployment -n $GW_NS $GW_NAME -o wide
    kubectl describe deployment -n $GW_NS $GW_NAME
    kubectl get pods -n $GW_NS -l "app.kubernetes.io/instance=$GW_INSTANCE" -o wide
    
    POD_NAME=$(kubectl get pods -n $GW_NS -l "app.kubernetes.io/instance=$GW_INSTANCE" -o jsonpath='{.items[0].metadata.name}')
    kubectl describe pod -n $GW_NS $POD_NAME
    kubectl logs -n $GW_NS $POD_NAME --tail=100
    

    Common causes: Image pull failure, resource constraints, port conflicts, missing ConfigMap/Secret.

    Gateway pod crash-looping / CrashLoopBackOff

    kubectl logs -n $GW_NS -l "app.kubernetes.io/instance=$GW_INSTANCE" --tail=100 --previous
    kubectl get events -n $GW_NS --sort-by='.lastTimestamp' | tail -20
    kubectl exec -n $GW_NS -l "app.kubernetes.io/instance=$GW_INSTANCE" -- cat /etc/nginx/nginx.conf 2>/dev/null | head -50
    kubectl get configmap -n $GW_NS -l "app.kubernetes.io/instance=$GW_INSTANCE" -o yaml
    

    Common causes: Misconfigured nginx config, port conflicts, resource limits (OOMKilled), missing dependencies (ConfigMap/Secret).

    Log search not working

    Gateway log search proxies to whizard-telemetry-apiserver:

    kubectl get configmap -n extension-gateway gateway-agent-backend-config -o yaml
    kubectl get pods -n extension-whizard-telemetry
    kubectl get svc -n extension-whizard-telemetry whizard-telemetry-apiserver
    kubectl logs -n extension-gateway -l app=gateway-apiserver --tail=100 | grep -iE "(log|search|whizard|proxy)"
    

    Common causes: Whizard-telemetry not installed or not running, misconfigured gateway-agent-backend-config, network policy blocking cross-namespace traffic.

    Gateway controller not reconciling

    kubectl get pods -n extension-gateway -l app=gateway-controller-manager
    kubectl logs -n extension-gateway -l app=gateway-controller-manager --tail=200
    kubectl get validatingwebhookconfiguration -l "app.kubernetes.io/managed-by=Helm,kubesphere.io/extension-ref=gateway"
    kubectl get deployment -n extension-gateway -l app=gateway-controller-manager -o yaml
    

    Common causes: Controller pod not running, webhook configuration blocking updates, Helm release state mismatch, RBAC permission issues.

    发现问题?提交给管理员复核

    评分:

    评论 (0)

    暂无评论,成为第一个评论者吧!