基于Istio为AKS上的应用配置流量路由遇阻求助
Istio Ingress 配置访问失败排查问题
环境与已完成配置
- 已通过ArgoCD在AKS上完成应用部署,应用运行正常
- 自行从零部署Istio,配置Ingress流量路由
Gateway 配置
执行命令:
kubectl get -n second-app-staging gw -o yaml
输出内容:
apiVersion: v1 items: - apiVersion: networking.istio.io/v1 kind: Gateway metadata: annotations: kubectl.kubernetes.io/last-applied-configuration: | {"apiVersion":"networking.istio.io/v1beta1","kind":"Gateway","metadata":{"annotations":{},"name":"second-app-gateway","namespace":"second-app-staging"},"spec":{"selector":{"istio":"ingressgateway"},"servers":[{"hosts":["*"],"port":{"name":"http","number":80,"protocol":"HTTP"}}]}} creationTimestamp: "2025-03-02T20:39:46Z" generation: 1 name: second-app-gateway namespace: second-app-staging resourceVersion: "1082933" uid: 1a0e457a-6514-4a16-bc50-020a8ce07baf spec: selector: istio: ingressgateway servers: - hosts: - '*' port: name: http number: 80 protocol: HTTP kind: List metadata: resourceVersion: ""
VirtualService 配置
执行命令:
kubectl get virtualservice -n second-app-staging -o yaml
输出内容:
apiVersion: v1 items: - apiVersion: networking.istio.io/v1 kind: VirtualService metadata: annotations: kubectl.kubernetes.io/last-applied-configuration: | {"apiVersion":"networking.istio.io/v1beta1","kind":"VirtualService","metadata":{"annotations":{},"name":"second-app-vs","namespace":"second-app-staging"},"spec":{"gateways":["second-app-gateway"],"hosts":["*"],"http":[{"match":[{"uri":{"prefix":"/"}}],"route":[{"destination":{"host":"staging-welcome-php","port":{"number":8080}}}]}]}} creationTimestamp: "2025-03-02T20:41:01Z" generation: 1 name: second-app-vs namespace: second-app-staging resourceVersion: "1083268" uid: 81d97334-79f4-4d81-98b2-d4c5f49dd1ca spec: gateways: - second-app-gateway hosts: - '*' http: - match: - uri: prefix: / route: - destination: host: staging-welcome-php port: number: 8080 kind: List metadata: resourceVersion: ""
应用Service状态
执行命令:
kubectl get svc -n second-app-staging staging-welcome-php
输出内容:
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE staging-welcome-php ClusterIP 10.0.132.229 <none> 8080/TCP 23h
Istio IngressGateway状态
执行命令:
kubectl get svc -n istio-system
输出内容:
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE istio-ingressgateway LoadBalancer 10.0.178.74 57.151.79.230 15021:31837/TCP,80:30589/TCP,443:31199/TCP 30m istiod ClusterIP 10.0.51.162 <none> 15010/TCP,15012/TCP,443/TCP,15014/TCP 30m
访问问题记录
- HTTP访问错误
访问http://57.151.79.230/时,出现以下错误:
upstream connect error or disconnect/reset before headers. retried and the latest reset reason: remote connection failure, transport failure reason: TLS_error:|268435581:SSL routines:OPENSSL_internal:CERTIFICATE_VERIFY_FAILED:TLS_error_end
- 添加HTTPS配置后访问失败
在Gateway配置中添加HTTPS相关配置并重新部署:
- port: number: 443 name: https protocol: HTTPS tls: mode: SIMPLE credentialName: my-tls-secret
生成自签证书:
openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout tls.key -out tls.crt -subj "/CN=example.com"
输出内容:
Generating a RSA private key .............................................+++++ ...........................................................................................................+++++ writing new private key to 'tls.key'
在Kubernetes中创建TLS Secret:
kubectl create -n second-app-staging secret tls my-tls-secret --key=tls.key --cert=tls.crt
输出内容:
secret/my-tls-secret created
Secret创建成功:
kubectl get secret -n second-app-staging my-tls-secret
输出内容:
NAME TYPE DATA AGE my-tls-secret kubernetes.io/tls 2 11s
现在访问 https://57.151.79.230/ 时,页面无法打开,提示**"This site can’t be reached"**。
问题
我的配置中缺少了什么?为何无法访问页面?
内容的提问来源于stack exchange,提问作者scrapkowe
相关产品推荐
相关产品推荐

