You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Istio网格内调用服务时VirtualService与DestinationRule未生效排查

Istio蓝绿部署集群内Pod调用路由失效问题

我尝试使用Istio VirtualService和DestinationRule实现蓝绿部署,集群外部通过入口网关调用可正常路由到指定版本,但当Pod之间相互调用时,请求会在蓝绿实例间均衡分配。所有相关Pod均已注入Envoy Sidecar,Istio入口网关通过默认istioctl install命令安装。

相关配置清单

Gateway配置

apiVersion: networking.istio.io/v1
kind: Gateway
metadata:
  name: bg-gateway
  namespace: bluegreen-playground
spec:
  selector:
    istio: ingressgateway
  servers:
  - port:
      number: 8080
      name: http
      protocol: HTTP
    hosts:
    - bluegreen.myexample.com

VirtualService配置

apiVersion: networking.istio.io/v1
kind: VirtualService
metadata:
  name: bg-route
  namespace: bluegreen-playground
spec:
  gateways:
    - bg-gateway
  hosts:
  - bluegreen.myexample.com
  - core-svc.bluegreen-playground.svc.cluster.local
  - front-svc.bluegreen-playground.svc.cluster.local
  http:
  - name: core
    match: 
    - uri:
        prefix: "/core"
    route:
    - destination:
        host: core-svc.bluegreen-playground.svc.cluster.local
        subset: blue
  - name: front
    match: 
    - uri: 
        prefix: "/"
    route:
    - destination:
        host: front-svc.bluegreen-playground.svc.cluster.local
        subset: blue

DestinationRule(core服务)

apiVersion: networking.istio.io/v1
kind: DestinationRule
metadata:
  name: core-destination
  namespace: bluegreen-playground
spec:
  host: core-svc.bluegreen-playground.svc.cluster.local
  subsets:
  - name: blue
    labels:
      version: v1
  - name: green
    labels:
      version: v2

DestinationRule(front服务)

apiVersion: networking.istio.io/v1
kind: DestinationRule
metadata:
  name: front-destination
  namespace: bluegreen-playground
spec:
  host: front-svc.bluegreen-playground.svc.cluster.local
  subsets:
  - name: blue
    labels:
      version: v1
  - name: green
    labels:
      version: v2

所有Pod均已正确标记version: v1或version: v2标签,微服务通过标准Kubernetes服务FQDN(如front-svc.bluegreen-playground.svc.cluster.local)相互调用。


问题原因与解决方法

问题根源

当前VirtualService的gateways字段仅指定了自定义的bg-gateway,这意味着该路由规则仅对通过入口网关进入的外部请求生效。集群内部Pod之间的调用属于服务网格内部流量,不会匹配这个VirtualService的规则,因此会按照Kubernetes Service的默认负载均衡策略(轮询)分配到蓝绿实例。

解决步骤

修改VirtualService的gateways字段,添加mesh标识符(Istio内置的代表整个服务网格内所有Sidecar的网关),让路由规则同时作用于外部网关流量和内部Pod调用流量:

apiVersion: networking.istio.io/v1
kind: VirtualService
metadata:
  name: bg-route
  namespace: bluegreen-playground
spec:
  gateways:
    - bg-gateway
    - mesh  # 添加这一行,让规则对网格内部流量生效
  hosts:
  - bluegreen.myexample.com
  - core-svc.bluegreen-playground.svc.cluster.local
  - front-svc.bluegreen-playground.svc.cluster.local
  http:
  - name: core
    match: 
    - uri:
        prefix: "/core"
    route:
    - destination:
        host: core-svc.bluegreen-playground.svc.cluster.local
        subset: blue
  - name: front
    match: 
    - uri: 
        prefix: "/"
    route:
    - destination:
        host: front-svc.bluegreen-playground.svc.cluster.local
        subset: blue

验证方法

  1. 应用修改后的VirtualService:
    kubectl apply -f <your-virtualservice-file.yaml> -n bluegreen-playground
    
  2. 使用istioctl analyze检查配置是否存在错误:
    istioctl analyze -n bluegreen-playground
    
  3. 在集群内的Pod中执行请求测试,确认流量是否仅路由到指定的blue子集:
    kubectl exec -it <your-pod-name> -n bluegreen-playground -- curl http://core-svc.bluegreen-playground.svc.cluster.local/core
    

内容的提问来源于stack exchange,提问作者Essay97

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 13:33:14