Azure AKS中Istio部署后GRPC应用Ingress访问404问题求助
问题:安装Istio后GRPC应用通过Ingress无法访问(404错误)
我在Azure Kubernetes集群中,使用Bitnami的asp.net-core Helm Chart部署了一个.NET GRPC应用,初始基于Nginx Ingress暴露服务,外部可正常访问。安装Istio后,将Ingress配置的ingressClassName改为自定义的"istio"类,出现404 Not Found nginx错误,Ingress控制器日志显示忽略该IngressClass及对应Ingress资源。
初始Helm配置
aspnet-core: fullnameOverride: app-name image: registry: registrypath repository: repopath tag: latest pullPolicy: Always args: - Service.dll bindURLs: http://+:5010;https://+:7010 service: type: ClusterIP ports: http: 7010 containerPorts: http: 7010 ingress: enabled: true pathType: Prefix hostname: host.domain.com path: / annotations: nginx.ingress.kubernetes.io/backend-protocol: "GRPCS" nginx.ingress.kubernetes.io/ssl-redirect: "true" tls: true ingressClassName: "nginx"
自定义的Istio IngressClass
apiVersion: networking.k8s.io/v1 kind: IngressClass metadata: name: istio labels: app.kubernetes.io/component: controller app.kubernetes.io/instance: ingress-nginx spec: controller: istio.io/ingress-controller
Ingress控制器报错日志
I0412 02:00:10.148428 7 store.go:578] "ignoring ingressclass as the spec.controller is not the same of this ingress" ingressclass="istio" W0412 02:01:59.300315 7 controller.go:331] ignoring ingress <serviceName> in <NAMESPACE> based on annotation : no object matching key "istio" in local store I0412 02:01:59.300359 7 main.go:107] "successfully validated configuration, accepting" ingress="<NAMESPACE>/<SERVICENAME>" I0412 02:01:59.307387 7 store.go:489] "removing ingress because of unknown ingressclass" ingress="<NAMESPACE>/<SERVICENAME>"
问题分析与修复步骤
错误根源
你创建的istio IngressClass指定的controller为istio.io/ingress-controller,但当前处理Ingress请求的仍是原Nginx Ingress控制器,它只识别自身对应的controller标识(通常为k8s.io/ingress-nginx),因此会忽略这个不匹配的IngressClass,导致Ingress资源无法被加载,最终返回404。
修复方案(无需使用Istio Ingress Gateway)
步骤1:恢复Nginx IngressClass配置
将Helm配置中的ingress.ingressClassName改回nginx,让Nginx Ingress控制器继续接管该Ingress资源。
步骤2:适配Istio Sidecar的GRPC服务访问
由于Istio会为Pod注入Sidecar代理,需要调整配置确保Nginx Ingress能正常访问GRPC服务:
- 为GRPC应用的Deployment添加Istio注解,明确端口规则:
annotations: sidecar.istio.io/inject: "true" traffic.sidecar.istio.io/includeInboundPorts: "7010" traffic.sidecar.istio.io/excludeOutboundPorts: "7010" - 创建Istio DestinationRule,指定GRPC服务的端口协议:
apiVersion: networking.istio.io/v1beta1 kind: DestinationRule metadata: name: app-name namespace: <你的命名空间> spec: host: app-name trafficPolicy: portLevelSettings: - port: number: 7010 tls: mode: DISABLE # 若集群启用全局mTLS,需调整为ISTIO_MUTUAL
额外检查点
- 确认GRPC应用的Pod已注入Istio Sidecar(查看Pod容器数量是否为2)
- 验证Nginx Ingress Pod能解析GRPC服务的ClusterIP,且7010端口可正常访问
- 检查是否存在Istio VirtualService意外拦截该服务的流量(未配置VirtualService时,Istio默认放行流量)
内容的提问来源于stack exchange,提问作者zyas
相关产品推荐
相关产品推荐

