Updated on 2026-09-29 GMT+08:00

Configuring an HTTP/HTTPS Header for a LoadBalancer Ingress

HTTP headers are a list of strings sent and received by both the client and server on every HTTP request and response. This section describes HTTP headers supported by HTTP and HTTPS listeners.
  • HTTP/HTTPS headers rely on ELB. Before using HTTP/HTTPS headers in a Service, check whether HTTP/HTTPS headers are supported in the current region. For details, see HTTP/HTTPS Headers.
  • After HTTP or HTTPS is configured, if you delete the HTTP or HTTPS configuration on the CCE console or delete the target annotation from the YAML file, the configuration on the ELB will be retained.
Table 1 Headers

Header

Feature

Description

Supported Cluster Version

X-Forwarded-Port

Transfer Listener Port Number

If this option is enabled, ELB inserts the listener port number into the X-Forwarded-Port header of requests forwarded to backend servers.

v1.23.13-r0, v1.25.8-r0, v1.27.5-r0, v1.28.3-r0, or later

X-Forwarded-For-Port

Transfer Port Number in the Request

If this option is enabled, the client port number is transmitted to backend servers via the X-Forwarded-For-Port header.

X-Forwarded-Host

Rewrite X-Forwarded-Host

If this option is enabled, the Host field from the client request header is rewritten into the X-Forwarded-Host header and passed to backend servers.

X-Real-IP

Rewrite X-Real-IP

If this option is enabled, the client source IP address is rewritten into the X-Real-IP header and passed to backend servers.

v1.25.16-r30, v1.27.16-r30, v1.28.15-r20, v1.29.13-r0, v1.30.10-r0, v1.31.6-r0, v1.32.1-r0, or later

X-Forwarded-ELB-IP

Transfer Load Balancer EIP

If this option is enabled, ELB passes the load balancer's EIP to backend servers via the HTTP request header. This option is available only for dedicated load balancers with HTTP or HTTPS listeners.

v1.30.14-r100, v1.31.14-r60, v1.32.13-r30, v1.33.12-r10, v1.34.8-r10, v1.35.5-r10, v1.36.2-r0, or later

X-Forwarded-ELB-ID

Transfer Load Balancer ID

If this option is enabled, ELB passes the load balancer's ID to backend servers via the HTTP request header. This option is available only for dedicated load balancers with HTTP or HTTPS listeners.

X-Forwarded-Proto

Transfer Listener Protocol

If this option is enabled, ELB passes the load balancer's listener protocol to backend servers via the HTTP request header. This option is available only for dedicated load balancers with HTTP or HTTPS listeners.

X-Forwarded-TLS-Certificate-ID

Transfer Certificate ID

If this option is enabled, ELB passes the load balancer's certificate ID to backend servers via the HTTP request header. This option is available only for dedicated load balancers with HTTPS listeners.

X-Forwarded-TLS-Protocol

Transfer TLS Protocol

If this option is enabled, ELB passes the load balancer's TLS protocol to backend servers via the HTTP request header. This option is available only for dedicated load balancers with HTTPS listeners.

X-Forwarded-TLS-Cipher

Transfer Cipher Suite

If this option is enabled, ELB passes the load balancer's cipher suite to backend servers via the HTTP request header. This option is available only for dedicated load balancers with HTTPS listeners.

Prerequisites

Constraints

  • Ingresses support HTTP to HTTPS headers only when dedicated load balancers are used.
  • If multiple ingresses share the same external port on a load balancer, you are advised to use the same HTTP/HTTPS header for these ingresses. Otherwise, the configuration of the first created ingress will take precedence. For details, see Configuring Multiple Ingresses to Use the Same Load Balancer.

Configuring an HTTP/HTTPS Header

You can configure an HTTP/HTTPS header for an ingress using either the CCE console or kubectl.

  1. Log in to the CCE console and click the cluster name to access the cluster console.
  2. In the navigation pane, choose Services and Ingresses. Click the Ingresses tab and click Create Ingress in the upper right corner.
  3. Configure ingress parameters.

    This example explains only key parameters for configuring HTTP/HTTPS headers. You can configure other parameters as required. For details, see Creating a LoadBalancer Ingress on the Console.

    Table 2 Key parameters

    Parameter

    Description

    Example

    Name

    Enter an ingress name.

    ingress-test

    Load Balancer

    Select a load balancer to be associated with the ingress or automatically create a load balancer. In this example, only dedicated load balancers are supported.

    Dedicated

    Listener

    • Frontend Protocol: HTTP and HTTPS are available.
    • External Port: specifies the port of the load balancer listener.
    • Advanced Options
      • Transfer Listener Port Number: If this function is enabled, the listening port on the load balancer can be transferred to backend servers through the HTTP header of the packet.
      • Transfer Port Number in the Request: If this function is enabled, the source port on the client can be transferred to backend servers through the HTTP header of the packet.
      • Rewrite X-Forwarded-Host: If this function is enabled, X-Forwarded-Host will be rewritten using the Host field in the client request header and transferred to backend servers.
      • Rewrite X-Real-IP: If this function is enabled, the source IP address of the client will be rewritten into the X-Real-IP header and transmitted to the backend servers.
      • Transfer Load Balancer EIP: If this option is enabled, ELB passes the load balancer's EIP to backend servers via the HTTP request header. This option is available only for dedicated load balancers with HTTP or HTTPS listeners.
      • Transfer Load Balancer ID: If this option is enabled, ELB passes the load balancer's ID to backend servers via the HTTP request header. This option is available only for dedicated load balancers with HTTP or HTTPS listeners.
      • Transfer Listener Protocol: If this option is enabled, ELB passes the load balancer's listener protocol to backend servers via the HTTP request header. This option is available only for dedicated load balancers with HTTP or HTTPS listeners.
      • Transfer Certificate ID: If this option is enabled, ELB passes the load balancer's certificate ID to backend servers via the HTTP request header. This option is available only for dedicated load balancers with HTTPS listeners.
      • Transfer TLS Protocol: If this option is enabled, ELB passes the load balancer's TLS protocol to backend servers via the HTTP request header. This option is available only for dedicated load balancers with HTTPS listeners.
      • Transfer Cipher Suite: If this option is enabled, ELB passes the load balancer's cipher suite to backend servers via the HTTP request header. This option is available only for dedicated load balancers with HTTPS listeners.
    • Frontend Protocol: HTTP
    • External Port: 80
    • Advanced Options
      • Transfer Listener Port Number: Enable
      • Transfer Port Number in the Request: Enable
      • Rewrite X-Forwarded-Host: Enable
      • Transfer Load Balancer EIP: Enable
      • ● true: Enable
      • Transfer Listener Protocol: Enable
      • Transfer Certificate ID: Enable
      • Transfer TLS Protocol: Enable
      • Transfer Cipher Suite: Enable

    Forwarding Policy

    • Domain Name: Enter an actual domain name to be accessed. If it is left blank, the ingress can be accessed through an IP address. The domain name must be registered and filed. Once a domain name is used by a forwarding policy, only that domain name will be accepted for access.
    • Path Matching Rule: Choose Prefix match, Exact match, or RegEx match.
    • Path: comes from a backend application for external access. It must work in the backend application. Otherwise, forwarding will not take effect.
    • Destination Service: Select an existing Service. Only Services that meet the requirements are automatically displayed in the Service list. If no Service meets the requirements, create one by following the operations provided in Services Supported by Ingresses.
    • Destination Service Port: Select the access port of the destination Service.
    • Domain Name: You do not need to configure this parameter.
    • Path Matching Rule: Prefix match
    • Path: /
    • Destination Service: nginx
    • Destination Service Port: 80
    Figure 1 Configuring HTTP/HTTPS headers

  4. Click OK.
  1. Use kubectl to access the cluster. For details, see Accessing a Cluster Using kubectl.
  2. Create a YAML file named ingress-test.yaml. The file name can be customized.

    vi ingress-test.yaml
    An example YAML file of an ingress associated with an existing load balancer is as follows:
    apiVersion: networking.k8s.io/v1
    kind: Ingress 
    metadata: 
      name: ingress-test
      annotations: 
        kubernetes.io/elb.id: <your_elb_id>                 # Replace it with the ID of your existing load balancer.
        kubernetes.io/elb.class: performance                # Load balancer type
        kubernetes.io/elb.port: '80'
        kubernetes.io/elb.x-forwarded-port: 'true'         # Obtain the listener port number.
        kubernetes.io/elb.x-forwarded-for-port: 'true'     # Obtain the client port number for requests.
        kubernetes.io/elb.x-forwarded-host: 'true'         # Rewrite X-Forwarded-Host.
        kubernetes.io/elb.x-real-ip: 'true'                # Rewrite X-Real-IP.
        kubernetes.io/elb.x-forwarded-proto: 'true'              # Forward the load balancer's listener protocol to backend servers.
        kubernetes.io/elb.x-forwarded-elb-ip: 'true'             # Forward the load balancer's EIP to backend servers.
        kubernetes.io/elb.x-forwarded-elb-id: 'true'             # Forward the load balancer's ID to backend servers.
        kubernetes.io/elb.x-forwarded-tls-certificate-id: 'true' # Forward the load balancer's certificate ID to backend servers.
        kubernetes.io/elb.x-forwarded-tls-protocol: 'true'       # Forward the load balancer's TLS version to backend servers.
        kubernetes.io/elb.x-forwarded-tls-cipher: 'true'         # Forward the load balancer's cipher suite to backend servers.
        kubernetes.io/elb.tls-certificate-ids: 6cfb43c9de1a41a18478b868e3******       # HTTPS listener server certificate
    spec:
      rules: 
      - host: ''
        http: 
          paths: 
          - path: '/'
            backend: 
              service:
                name: <your_service_name>  # Replace it with your target Service name.
                port: 
                  number: 80             # Replace it with your target Service port.
            property:
              ingress.beta.kubernetes.io/url-match-mode: STARTS_WITH
            pathType: ImplementationSpecific
      ingressClassName: cce     
    Table 3 Key parameters

    Parameter

    Type

    Description

    kubernetes.io/elb.x-forwarded-port

    String

    A load balancer can obtain the port number of a listener using X-Forwarded-Port and transmit the port number to the packets of the backend server.

    • true: Enable the function of obtaining a listener port number.
    • false: Disable the function of obtaining a listener port number.

    kubernetes.io/elb.x-forwarded-for-port

    String

    A load balancer can obtain a client port number for requests using X-Forwarded-For-Port and transmit the port number to the packets of the backend server.

    • true: Enable the function of obtaining a client port number for requests.
    • false: Disable the function of obtaining a client port number for requests.

    kubernetes.io/elb.x-forwarded-host

    String

    • true: Enable the function of rewriting X-Forwarded-Host. Then, the X-Forwarded-Host header will be rewritten using the Host header of the client request and transmitted to backend servers.
    • false: Disable the function of rewriting X-Forwarded-Host. Then, the X-Forwarded-Host header of the client will be transmitted to backend servers.

    kubernetes.io/elb.x-real-ip

    String

    • true: Enable the function of rewriting X-Real-IP. The source IP address of the client will be written into the X-Real-IP header and transmitted to the backend servers.
    • false: Disable the function of rewriting X-Real-IP. The X-Real-IP header of the client will be transmitted to the backend servers.

    kubernetes.io/elb.x-forwarded-elb-ip

    String

    Enables the load balancer to pass the listener's EIP to backend servers via the x-forwarded-elb-ip header field in forwarded requests. Only HTTP and HTTPS are supported.

    ● true: Enable

    ● false (default): Disable

    kubernetes.io/elb.x-forwarded-elb-id

    String

    Enables the load balancer to pass its ELB ID to backend servers via the x-forwarded-elb-id header field in forwarded requests. Only HTTP and HTTPS are supported.

    ● true: Enable

    ● false (default): Disable

    kubernetes.io/elb.x-forwarded-proto

    String

    Enables the load balancer to pass the listener protocol to backend servers via the x-forwarded-proto header field in forwarded requests. Only HTTP and HTTPS are supported.

    ● true (default): Enable

    ● false: Disable

    kubernetes.io/elb.x-forwarded-tls-certificate-id

    String

    Enables the load balancer to pass the TLS certificate ID to backend servers via the x-forwarded-tls-certificate-id header field in forwarded requests. Only HTTPS is supported.

    ● true: Enable

    ● false (default): Disable

    kubernetes.io/elb.x-forwarded-tls-protocol

    String

    Enables the load balancer to pass the algorithm protocol to backend servers via the x-forwarded-tls-protocol header field in forwarded requests. Only HTTPS is supported.

    ● true (default): Enable

    ● false: Disable

    kubernetes.io/elb.x-forwarded-tls-cipher

    String

    Enables the load balancer to pass the TLS cipher suite to backend servers via the x-forwarded-tls-cipher header field in forwarded requests. Only HTTPS is supported.

    ● true: Enable

    ● false (default): Disable

  3. Create an ingress.

    kubectl create -f ingress-test.yaml

    If information similar to the following is displayed, the ingress has been created:

    ingress.networking.k8s.io/ingress-test created

  4. Check the created ingress.

    kubectl get ingress

    If information similar to the following is displayed, the ingress has been created:

    NAME          CLASS    HOSTS     ADDRESS          PORTS   AGE
    ingress-test  cce      *         121.**.**.**     80      10s