You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

新手求助:无法通过Istio Ingress访问HTTPS服务,求配置方法

Istio Ingress配置故障排查与修复

问题现象

执行curl https://192.168.4.241时返回连接拒绝:

curl: (7) Failed connect to 192.168.4.241:443; Connection refused

现有环境信息

后端服务信息(smartapigw-httpd为HTTPS服务)

kubectl get po smartapigw-httpd -n smartapigw --show-labels

输出:

NAME               READY   STATUS    RESTARTS   AGE     LABELS
smartapigw-httpd   2/2     Running   0          3h22m   app.kubernetes.io/managed-by=Helm,app=smartapigw-httpd,io.kompose.service=smartapigw-httpd,security.istio.io/tlsMode=istio,service.istio.io/canonical-name=smartapigw-httpd,service.istio.io/canonical-revision=latest

服务端口信息:

kubectl get svc -n smartapigw

输出片段:

service/smartapigw-httpd           NodePort    10.101.227.150   <none> 18443:31285/TCP   166m

Istio IngressGateway信息

Pod标签:

kubectl get po -n istio-system --show-labels

输出片段:

istio-ingressgateway-5ff4fb69fc-trmht   1/1     Running            0                 28h   app=istio-ingressgateway,chart=gateways,heritage=Tiller,install.operator.istio.io/owning-resource=unknown,istio.io/rev=default,istio=ingressgateway,operator.istio.io/component=IngressGateways,pod-template-hash=5ff4fb69fc,release=istio,service.istio.io/canonical-name=istio-ingressgateway,service.istio.io/canonical-revision=latest,sidecar.istio.io/inject=false

服务端口:

kubectl get svc -n istio-system

输出:

istio-ingressgateway   LoadBalancer   10.110.145.103   192.168.4.241   15021:32010/TCP,80:31631/TCP,443:30495/TCP       28h

现有配置的问题分析

  1. Gateway YAML格式错误:hosts和tls字段缩进错误,未归属到servers数组的条目下,导致Gateway配置无效;同时protocol字段拼写错误(应为HTTPS而非HTTPs)。
  2. VirtualService路由类型错误:当Gateway使用PASSTHROUGH模式(透传TLS流量)时,VirtualService应配置tls路由而非http路由,因为Istio不会终止TLS,无法解析HTTP层内容。
  3. 后端端口配置错误:VirtualService中指定的端口应为服务的ClusterIP端口(18443),而非NodePort(31285),Istio内部通过ClusterIP访问后端服务。

修正后的配置步骤

1. 删除错误的Istio资源

kubectl delete gateway smartagigw-gateway -n smartapigw
kubectl delete virtualservice smartapigw -n smartapigw

2. 应用修正后的Gateway配置

创建istio-smartapigw-gateway.yml:

apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name: smartagigw-gateway
  namespace: smartapigw
spec:
  selector:
    istio: ingressgateway
  servers:
  - port:
      number: 443
      name: https
      protocol: HTTPS
    hosts:
    - "*"
    tls:
      mode: PASSTHROUGH

执行应用:

kubectl apply -f istio-smartapigw-gateway.yml

3. 应用修正后的VirtualService配置

创建istio-smartapigw-virtualservice.yml:

apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: smartapigw
  namespace: smartapigw
spec:
  hosts:
  - "*"
  gateways:
  - smartagigw-gateway
  tls:
  - match:
    - port: 443
      sniHosts:
      - "*"
    route:
    - destination:
        host: smartapigw-httpd.smartapigw.svc.cluster.local
        port:
          number: 18443

执行应用:

kubectl apply -f istio-smartapigw-virtualservice.yml

验证配置

执行curl命令测试(若后端使用自签名证书,需添加-k参数跳过证书验证):

curl https://192.168.4.241 -k

内容的提问来源于stack exchange,提问作者user3373742

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 21:07:03