You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Istio为AKS上的应用配置流量路由遇阻求助

Istio Ingress 配置访问失败排查问题

环境与已完成配置

  • 已通过ArgoCD在AKS上完成应用部署,应用运行正常
  • 自行从零部署Istio,配置Ingress流量路由

Gateway 配置

执行命令:

kubectl get -n second-app-staging gw -o yaml

输出内容:

apiVersion: v1
items:
- apiVersion: networking.istio.io/v1
  kind: Gateway
  metadata:
    annotations:
      kubectl.kubernetes.io/last-applied-configuration: |
        {"apiVersion":"networking.istio.io/v1beta1","kind":"Gateway","metadata":{"annotations":{},"name":"second-app-gateway","namespace":"second-app-staging"},"spec":{"selector":{"istio":"ingressgateway"},"servers":[{"hosts":["*"],"port":{"name":"http","number":80,"protocol":"HTTP"}}]}}
    creationTimestamp: "2025-03-02T20:39:46Z"
    generation: 1
    name: second-app-gateway
    namespace: second-app-staging
    resourceVersion: "1082933"
    uid: 1a0e457a-6514-4a16-bc50-020a8ce07baf
  spec:
    selector:
      istio: ingressgateway
    servers:
    - hosts:
      - '*'
      port:
        name: http
        number: 80
        protocol: HTTP
kind: List
metadata:
  resourceVersion: ""

VirtualService 配置

执行命令:

kubectl get virtualservice -n second-app-staging -o yaml

输出内容:

apiVersion: v1
items:
- apiVersion: networking.istio.io/v1
  kind: VirtualService
  metadata:
    annotations:
      kubectl.kubernetes.io/last-applied-configuration: |
        {"apiVersion":"networking.istio.io/v1beta1","kind":"VirtualService","metadata":{"annotations":{},"name":"second-app-vs","namespace":"second-app-staging"},"spec":{"gateways":["second-app-gateway"],"hosts":["*"],"http":[{"match":[{"uri":{"prefix":"/"}}],"route":[{"destination":{"host":"staging-welcome-php","port":{"number":8080}}}]}]}}
    creationTimestamp: "2025-03-02T20:41:01Z"
    generation: 1
    name: second-app-vs
    namespace: second-app-staging
    resourceVersion: "1083268"
    uid: 81d97334-79f4-4d81-98b2-d4c5f49dd1ca
  spec:
    gateways:
    - second-app-gateway
    hosts:
    - '*'
    http:
    - match:
      - uri:
          prefix: /
      route:
      - destination:
          host: staging-welcome-php
          port:
            number: 8080
kind: List
metadata:
  resourceVersion: ""

应用Service状态

执行命令:

kubectl get svc -n second-app-staging staging-welcome-php

输出内容:

NAME                  TYPE        CLUSTER-IP     EXTERNAL-IP   PORT(S)    AGE
staging-welcome-php   ClusterIP   10.0.132.229   <none>        8080/TCP   23h

Istio IngressGateway状态

执行命令:

kubectl get svc -n istio-system

输出内容:

NAME                   TYPE           CLUSTER-IP    EXTERNAL-IP     PORT(S)                                      AGE
istio-ingressgateway   LoadBalancer   10.0.178.74   57.151.79.230   15021:31837/TCP,80:30589/TCP,443:31199/TCP   30m
istiod                 ClusterIP      10.0.51.162   <none>          15010/TCP,15012/TCP,443/TCP,15014/TCP        30m

访问问题记录

  1. HTTP访问错误
    访问 http://57.151.79.230/ 时,出现以下错误:

upstream connect error or disconnect/reset before headers. retried and the latest reset reason: remote connection failure, transport failure reason: TLS_error:|268435581:SSL routines:OPENSSL_internal:CERTIFICATE_VERIFY_FAILED:TLS_error_end

  1. 添加HTTPS配置后访问失败
    在Gateway配置中添加HTTPS相关配置并重新部署:
- port:
      number: 443
      name: https
      protocol: HTTPS
    tls:
      mode: SIMPLE
      credentialName: my-tls-secret 

生成自签证书:

openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout tls.key -out tls.crt -subj "/CN=example.com"

输出内容:

Generating a RSA private key
.............................................+++++
...........................................................................................................+++++
writing new private key to 'tls.key'

在Kubernetes中创建TLS Secret:

kubectl create -n second-app-staging secret tls my-tls-secret --key=tls.key --cert=tls.crt

输出内容:

secret/my-tls-secret created

Secret创建成功:

kubectl get secret -n second-app-staging my-tls-secret

输出内容:

NAME            TYPE                DATA   AGE
my-tls-secret   kubernetes.io/tls   2      11s

现在访问 https://57.151.79.230/ 时,页面无法打开,提示**"This site can’t be reached"**。

问题

我的配置中缺少了什么?为何无法访问页面?


内容的提问来源于stack exchange,提问作者scrapkowe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 01:50:57