You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Istio实现无Sidecar Pod到带Sidecar Pod的HTTP流量负载均衡

问题解答

当然可以。要让无Sidecar的deployment-b Pod发往deployment-a的流量由Istio接管负载均衡,核心是让流量先进入Istio服务网格的代理层,再由Istio处理转发。以下是两种实用方案:

方案一:通过Istio Gateway + Virtual Service接管流量

这是对现有架构影响最小的方案,无需修改deployment-b的代码:

  1. 创建Istio Gateway:定义监听目标端口的Gateway,绑定到Istio默认Ingress Gateway实例:
apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name: deployment-a-gateway
  namespace: namespace-a
spec:
  selector:
    istio: ingressgateway # 匹配Istio默认Ingress Gateway的标签
  servers:
  - port:
      number: 80
      name: http
      protocol: HTTP
    hosts:
    - "deployment-a.internal" # 自定义内部访问域名
  1. 创建Virtual Service:将Gateway接收的流量路由到deployment-a的Service:
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: deployment-a-vs
  namespace: namespace-a
spec:
  hosts:
  - "deployment-a.internal"
  gateways:
  - deployment-a-gateway
  http:
  - route:
    - destination:
        host: deployment-a # deployment-a对应的K8s Service名称
        port:
          number: 80
  1. 配置Destination Rule:定义Istio的负载均衡策略(如最少请求、轮询等):
apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
  name: deployment-a-dr
  namespace: namespace-a
spec:
  host: deployment-a
  trafficPolicy:
    loadBalancer:
      simple: LEAST_REQUEST # 选择最少请求数的负载均衡策略
  1. 调整deployment-b的访问地址:让deployment-b的Pod访问deployment-a.internal(或Gateway的ClusterIP/NodePort),此时流量会经过Istio Ingress Gateway,由Istio完成负载均衡后转发到deployment-a的Pod。

方案二:保留原Service访问地址的流量接管

如果需要deployment-b继续使用原Service名称(deployment-a.namespace-a.svc.cluster.local)访问,可按以下步骤配置:

  1. 将deployment-a的Service改为Headless类型:去掉ClusterIP,让Service直接关联Pod IP:
apiVersion: v1
kind: Service
metadata:
  name: deployment-a
  namespace: namespace-a
spec:
  clusterIP: None # 设置为Headless Service
  selector:
    app: deployment-a
  ports:
  - port: 80
    targetPort: 80
  1. 配置Istio流量规则:针对该Headless Service配置负载均衡策略:
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: deployment-a-vs
  namespace: namespace-a
spec:
  hosts:
  - deployment-a.namespace-a.svc.cluster.local
  http:
  - route:
    - destination:
        host: deployment-a.namespace-a.svc.cluster.local
        port:
          number: 80
---
apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
  name: deployment-a-dr
  namespace: namespace-a
spec:
  host: deployment-a.namespace-a.svc.cluster.local
  trafficPolicy:
    loadBalancer:
      simple: ROUND_ROBIN # 轮询负载均衡策略
  1. 生效逻辑:由于deployment-a的Pod带有Istio Sidecar,Istio会自动接管该Headless Service的流量。当deployment-b访问原Service名称时,流量会被Istio网格内的代理拦截处理,完成负载均衡后转发到目标Pod。

关键注意事项

  • 需确保namespace-a中deployment-a的Pod已正确注入Istio Sidecar(自动或手动注入均可),否则Istio无法识别并管理该服务的流量。
  • 方案一适合允许调整访问地址的场景,方案二更适合需要兼容原有访问逻辑的场景。

内容的提问来源于stack exchange,提问作者hghtms

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 11:43:12