You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AKS中Istio部署后GRPC应用Ingress访问404问题求助

问题:安装Istio后GRPC应用通过Ingress无法访问(404错误)

我在Azure Kubernetes集群中,使用Bitnami的asp.net-core Helm Chart部署了一个.NET GRPC应用,初始基于Nginx Ingress暴露服务,外部可正常访问。安装Istio后,将Ingress配置的ingressClassName改为自定义的"istio"类,出现404 Not Found nginx错误,Ingress控制器日志显示忽略该IngressClass及对应Ingress资源。

初始Helm配置

aspnet-core:
  fullnameOverride: app-name
  image:
    registry: registrypath
    repository: repopath
    tag: latest
    pullPolicy: Always
 
  args: 
    - Service.dll

  bindURLs: http://+:5010;https://+:7010       
  service:
    type: ClusterIP
    ports:
      http: 7010

  containerPorts:
    http: 7010

  ingress:
    enabled: true
    pathType: Prefix
    hostname: host.domain.com
    path: /
    annotations:
      nginx.ingress.kubernetes.io/backend-protocol: "GRPCS"
      nginx.ingress.kubernetes.io/ssl-redirect: "true"
    tls: true
    ingressClassName: "nginx"

自定义的Istio IngressClass

apiVersion: networking.k8s.io/v1
kind: IngressClass
metadata:
  name: istio
  labels:
    app.kubernetes.io/component: controller
    app.kubernetes.io/instance: ingress-nginx
spec:
  controller: istio.io/ingress-controller

Ingress控制器报错日志

I0412 02:00:10.148428       7 store.go:578] "ignoring ingressclass as the spec.controller is not the same of this ingress" ingressclass="istio"
W0412 02:01:59.300315       7 controller.go:331] ignoring ingress <serviceName> in <NAMESPACE> based on annotation : no object matching key "istio" in local store
I0412 02:01:59.300359       7 main.go:107] "successfully validated configuration, accepting" ingress="<NAMESPACE>/<SERVICENAME>"
I0412 02:01:59.307387       7 store.go:489] "removing ingress because of unknown ingressclass" ingress="<NAMESPACE>/<SERVICENAME>"

问题分析与修复步骤

错误根源

你创建的istio IngressClass指定的controller为istio.io/ingress-controller,但当前处理Ingress请求的仍是原Nginx Ingress控制器,它只识别自身对应的controller标识(通常为k8s.io/ingress-nginx),因此会忽略这个不匹配的IngressClass,导致Ingress资源无法被加载,最终返回404。

修复方案(无需使用Istio Ingress Gateway)

步骤1:恢复Nginx IngressClass配置

将Helm配置中的ingress.ingressClassName改回nginx,让Nginx Ingress控制器继续接管该Ingress资源。

步骤2:适配Istio Sidecar的GRPC服务访问

由于Istio会为Pod注入Sidecar代理,需要调整配置确保Nginx Ingress能正常访问GRPC服务:

  1. 为GRPC应用的Deployment添加Istio注解,明确端口规则:
    annotations:
      sidecar.istio.io/inject: "true"
      traffic.sidecar.istio.io/includeInboundPorts: "7010"
      traffic.sidecar.istio.io/excludeOutboundPorts: "7010"
    
  2. 创建Istio DestinationRule,指定GRPC服务的端口协议:
    apiVersion: networking.istio.io/v1beta1
    kind: DestinationRule
    metadata:
      name: app-name
      namespace: <你的命名空间>
    spec:
      host: app-name
      trafficPolicy:
        portLevelSettings:
        - port:
            number: 7010
          tls:
            mode: DISABLE # 若集群启用全局mTLS,需调整为ISTIO_MUTUAL
    

额外检查点

  • 确认GRPC应用的Pod已注入Istio Sidecar(查看Pod容器数量是否为2)
  • 验证Nginx Ingress Pod能解析GRPC服务的ClusterIP,且7010端口可正常访问
  • 检查是否存在Istio VirtualService意外拦截该服务的流量(未配置VirtualService时,Istio默认放行流量)

内容的提问来源于stack exchange,提问作者zyas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 22:30:34