Scale up as you grow — whether you're running one virtual machine or ten thousand.

From GPU-powered inference and Kubernetes to managed databases and storage, get everything you need to build, scale, and deploy intelligent applications.

This textbox defaults to using Markdown to format your answer.
You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!
These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.
Hi there,
Usually enabling PROXY Protocol is the way to get the real client IP, but APISIX needs to be configured properly to handle it.
You should be able to do that by:
First, enable PROXY Protocol on the LB. Add this annotation to your Kubernetes Service:
service.beta.kubernetes.io/do-loadbalancer-enable-proxy-protocol: "true"
service.beta.kubernetes.io/do-loadbalancer-tls-passthrough: "true"
This ensures the LB sends the original client IP.
Then configure APISIX to expect the PROXY Protocol. Update your APISIX config:
apisix:
proxy_protocol:
listen_http_port: 80
listen_https_port: 443
enable_tcp_pp: true
nginx_config:
http:
real_ip_header: proxy_protocol
Without this, APISIX won’t interpret the client IP correctly.
Also, set externalTrafficPolicy: Local.
This prevents Kubernetes from SNAT’ing the source IP:
spec:
externalTrafficPolicy: Local
As far as I can tell from the docs, APISIX requires dedicated ports for PROXY Protocol, so your existing listeners may need adjustments.
If PROXY Protocol isn’t working as expected, an alternative is to let the LB handle TLS termination and use X-Forwarded-For, but DigitalOcean LBs don’t support multiple TLS certificates, which could be a dealbreaker.
- Bobby