Istio网格内调用服务时VirtualService与DestinationRule未生效排查
Istio蓝绿部署集群内Pod调用路由失效问题
我尝试使用Istio VirtualService和DestinationRule实现蓝绿部署,集群外部通过入口网关调用可正常路由到指定版本,但当Pod之间相互调用时,请求会在蓝绿实例间均衡分配。所有相关Pod均已注入Envoy Sidecar,Istio入口网关通过默认istioctl install命令安装。
相关配置清单
Gateway配置
apiVersion: networking.istio.io/v1 kind: Gateway metadata: name: bg-gateway namespace: bluegreen-playground spec: selector: istio: ingressgateway servers: - port: number: 8080 name: http protocol: HTTP hosts: - bluegreen.myexample.com
VirtualService配置
apiVersion: networking.istio.io/v1 kind: VirtualService metadata: name: bg-route namespace: bluegreen-playground spec: gateways: - bg-gateway hosts: - bluegreen.myexample.com - core-svc.bluegreen-playground.svc.cluster.local - front-svc.bluegreen-playground.svc.cluster.local http: - name: core match: - uri: prefix: "/core" route: - destination: host: core-svc.bluegreen-playground.svc.cluster.local subset: blue - name: front match: - uri: prefix: "/" route: - destination: host: front-svc.bluegreen-playground.svc.cluster.local subset: blue
DestinationRule(core服务)
apiVersion: networking.istio.io/v1 kind: DestinationRule metadata: name: core-destination namespace: bluegreen-playground spec: host: core-svc.bluegreen-playground.svc.cluster.local subsets: - name: blue labels: version: v1 - name: green labels: version: v2
DestinationRule(front服务)
apiVersion: networking.istio.io/v1 kind: DestinationRule metadata: name: front-destination namespace: bluegreen-playground spec: host: front-svc.bluegreen-playground.svc.cluster.local subsets: - name: blue labels: version: v1 - name: green labels: version: v2
所有Pod均已正确标记version: v1或version: v2标签,微服务通过标准Kubernetes服务FQDN(如front-svc.bluegreen-playground.svc.cluster.local)相互调用。
问题原因与解决方法
问题根源
当前VirtualService的gateways字段仅指定了自定义的bg-gateway,这意味着该路由规则仅对通过入口网关进入的外部请求生效。集群内部Pod之间的调用属于服务网格内部流量,不会匹配这个VirtualService的规则,因此会按照Kubernetes Service的默认负载均衡策略(轮询)分配到蓝绿实例。
解决步骤
修改VirtualService的gateways字段,添加mesh标识符(Istio内置的代表整个服务网格内所有Sidecar的网关),让路由规则同时作用于外部网关流量和内部Pod调用流量:
apiVersion: networking.istio.io/v1 kind: VirtualService metadata: name: bg-route namespace: bluegreen-playground spec: gateways: - bg-gateway - mesh # 添加这一行,让规则对网格内部流量生效 hosts: - bluegreen.myexample.com - core-svc.bluegreen-playground.svc.cluster.local - front-svc.bluegreen-playground.svc.cluster.local http: - name: core match: - uri: prefix: "/core" route: - destination: host: core-svc.bluegreen-playground.svc.cluster.local subset: blue - name: front match: - uri: prefix: "/" route: - destination: host: front-svc.bluegreen-playground.svc.cluster.local subset: blue
验证方法
- 应用修改后的VirtualService:
kubectl apply -f <your-virtualservice-file.yaml> -n bluegreen-playground - 使用
istioctl analyze检查配置是否存在错误:istioctl analyze -n bluegreen-playground - 在集群内的Pod中执行请求测试,确认流量是否仅路由到指定的
blue子集:kubectl exec -it <your-pod-name> -n bluegreen-playground -- curl http://core-svc.bluegreen-playground.svc.cluster.local/core
内容的提问来源于stack exchange,提问作者Essay97
相关产品推荐
相关产品推荐

