如何配置Istio Ingress Gateway?AKS部署Bookinfo公网访问失败
问题:AKS上安装Istio后无法通过公网IP访问Bookinfo应用
我按照步骤在AKS上安装Istio,执行的命令如下:
helm repo add istio https://istio-release.storage.googleapis.com/charts helm repo update kubectl create namespace istio-system helm install istio-base istio/base -n istio-system helm install istiod istio/istiod -n istio-system --wait kubectl create namespace istio-ingress kubectl label namespace istio-ingress istio-injection=enabled helm install istio-ingress istio/gateway -n istio-ingress
随后部署Bookinfo应用进行测试,命令如下:
kubectl create namespace app kubectl label namespace app istio-injection=enabled kubectl apply -f https://raw.githubusercontent.com/istio/istio/release-1.22/samples/bookinfo/platform/kube/bookinfo.yaml -n app kubectl apply -f https://raw.githubusercontent.com/istio/istio/release-1.22/samples/bookinfo/networking/bookinfo-gateway.yaml -n app
目前可以从集群内部获取应用响应,但无法通过公网IP访问,是否需要额外配置?
解决方案
针对AKS上Istio网关的公网访问问题,需要检查并配置以下关键项:
1. 确认Istio网关服务类型
默认安装的Istio网关可能是ClusterIP类型,无法直接暴露公网IP。执行命令检查:
kubectl get svc istio-ingress -n istio-ingress
若类型为ClusterIP,修改为LoadBalancer类型:
kubectl patch svc istio-ingress -n istio-ingress -p '{"spec":{"type":"LoadBalancer"}}'
也可在安装时直接指定:
helm install istio-ingress istio/gateway -n istio-ingress --set service.type=LoadBalancer
2. 验证AKS负载均衡器公网IP分配
修改服务类型后,等待AKS分配公网IP,执行命令确认:
kubectl get svc istio-ingress -n istio-ingress
确保EXTERNAL-IP字段已分配有效公网地址(非<pending>状态)。
3. 检查网关与虚拟服务配置关联
确认bookinfo-gateway.yaml的配置正确性:
- 网关的
hosts字段是否设置为*或目标访问域名 - HTTP路由的
destination是否指向productpage服务的9080端口
执行命令查看配置细节:
kubectl get gateway -n app -o yaml kubectl get virtualservice -n app -o yaml
4. 配置AKS节点NSG入站规则
AKS节点对应的网络安全组(NSG)需要允许网关端口(默认80、443)的公网入站流量:
- 登录Azure门户,找到AKS集群对应的节点资源组(名称通常以
MC_开头) - 打开节点NSG的入站规则,添加允许80/443端口从
Any来源访问的规则
5. 测试与日志排查
获取网关公网IP后,访问http://<EXTERNAL-IP>/productpage验证。若仍有问题,查看Istio日志定位故障:
kubectl logs -n istio-ingress -l app=istio-ingressgateway kubectl logs -n istio-system -l app=istiod
内容的提问来源于stack exchange,提问作者cekodis681 cekodis681
相关产品推荐
相关产品推荐

