新手求助:无法通过Istio Ingress访问HTTPS服务,求配置方法
Istio Ingress配置故障排查与修复
问题现象
执行curl https://192.168.4.241时返回连接拒绝:
curl: (7) Failed connect to 192.168.4.241:443; Connection refused
现有环境信息
后端服务信息(smartapigw-httpd为HTTPS服务)
kubectl get po smartapigw-httpd -n smartapigw --show-labels
输出:
NAME READY STATUS RESTARTS AGE LABELS smartapigw-httpd 2/2 Running 0 3h22m app.kubernetes.io/managed-by=Helm,app=smartapigw-httpd,io.kompose.service=smartapigw-httpd,security.istio.io/tlsMode=istio,service.istio.io/canonical-name=smartapigw-httpd,service.istio.io/canonical-revision=latest
服务端口信息:
kubectl get svc -n smartapigw
输出片段:
service/smartapigw-httpd NodePort 10.101.227.150 <none> 18443:31285/TCP 166m
Istio IngressGateway信息
Pod标签:
kubectl get po -n istio-system --show-labels
输出片段:
istio-ingressgateway-5ff4fb69fc-trmht 1/1 Running 0 28h app=istio-ingressgateway,chart=gateways,heritage=Tiller,install.operator.istio.io/owning-resource=unknown,istio.io/rev=default,istio=ingressgateway,operator.istio.io/component=IngressGateways,pod-template-hash=5ff4fb69fc,release=istio,service.istio.io/canonical-name=istio-ingressgateway,service.istio.io/canonical-revision=latest,sidecar.istio.io/inject=false
服务端口:
kubectl get svc -n istio-system
输出:
istio-ingressgateway LoadBalancer 10.110.145.103 192.168.4.241 15021:32010/TCP,80:31631/TCP,443:30495/TCP 28h
现有配置的问题分析
- Gateway YAML格式错误:
hosts和tls字段缩进错误,未归属到servers数组的条目下,导致Gateway配置无效;同时protocol字段拼写错误(应为HTTPS而非HTTPs)。 - VirtualService路由类型错误:当Gateway使用
PASSTHROUGH模式(透传TLS流量)时,VirtualService应配置tls路由而非http路由,因为Istio不会终止TLS,无法解析HTTP层内容。 - 后端端口配置错误:VirtualService中指定的端口应为服务的ClusterIP端口(18443),而非NodePort(31285),Istio内部通过ClusterIP访问后端服务。
修正后的配置步骤
1. 删除错误的Istio资源
kubectl delete gateway smartagigw-gateway -n smartapigw kubectl delete virtualservice smartapigw -n smartapigw
2. 应用修正后的Gateway配置
创建istio-smartapigw-gateway.yml:
apiVersion: networking.istio.io/v1alpha3 kind: Gateway metadata: name: smartagigw-gateway namespace: smartapigw spec: selector: istio: ingressgateway servers: - port: number: 443 name: https protocol: HTTPS hosts: - "*" tls: mode: PASSTHROUGH
执行应用:
kubectl apply -f istio-smartapigw-gateway.yml
3. 应用修正后的VirtualService配置
创建istio-smartapigw-virtualservice.yml:
apiVersion: networking.istio.io/v1alpha3 kind: VirtualService metadata: name: smartapigw namespace: smartapigw spec: hosts: - "*" gateways: - smartagigw-gateway tls: - match: - port: 443 sniHosts: - "*" route: - destination: host: smartapigw-httpd.smartapigw.svc.cluster.local port: number: 18443
执行应用:
kubectl apply -f istio-smartapigw-virtualservice.yml
验证配置
执行curl命令测试(若后端使用自签名证书,需添加-k参数跳过证书验证):
curl https://192.168.4.241 -k
内容的提问来源于stack exchange,提问作者user3373742
相关产品推荐
相关产品推荐

