如何基于自定义Header动态配置Envoy的路径、端口及转发目标
解决Envoy自定义Header动态转发端口与路径问题
当前配置已实现Host头重写,但需补充端口和路径的动态替换逻辑,可通过Lua过滤器实现Header读取与请求参数重写,同时调整动态转发代理的配置逻辑。
修改后的完整配置
admin: address: socket_address: protocol: TCP address: 0.0.0.0 port_value: 9901 static_resources: listeners: - name: listener_0 address: socket_address: protocol: TCP address: 0.0.0.0 port_value: 9001 filter_chains: - filters: - name: envoy.filters.network.http_connection_manager typed_config: "@type": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager stat_prefix: egress_http access_log: - name: envoy.access_loggers.stdout typed_config: "@type": type.googleapis.com/envoy.extensions.access_loggers.stream.v3.StdoutAccessLog - name: envoy.access_loggers.stderr typed_config: "@type": type.googleapis.com/envoy.extensions.access_loggers.stream.v3.StderrAccessLog codec_type: AUTO route_config: name: local_route virtual_hosts: - name: local_service domains: ["*"] routes: - match: prefix: "/" route: cluster: dynamic_forward_proxy_cluster http_filters: - name: envoy.filters.http.lua typed_config: "@type": type.googleapis.com/envoy.extensions.filters.http.lua.v3.Lua inline_code: | function envoy_on_request(request_handle) -- 读取自定义Header local fwd_host = request_handle:headers():get("X-Fwd-Host") local fwd_port = request_handle:headers():get("X-Fwd-Port") local fwd_path = request_handle:headers():get("X-Fwd-Path") -- 重写请求路径 if fwd_path ~= nil then request_handle:headers():replace(":path", fwd_path) end -- 构造完整目标地址(包含端口),传递给动态转发代理 if fwd_host ~= nil and fwd_port ~= nil then local target_address = fwd_host .. ":" .. fwd_port request_handle:headers():replace(":authority", target_address) elseif fwd_host ~= nil then -- 若未指定端口,默认用80 request_handle:headers():replace(":authority", fwd_host) end end - name: envoy.filters.http.dynamic_forward_proxy typed_config: '@type': type.googleapis.com/envoy.extensions.filters.http.dynamic_forward_proxy.v3.FilterConfig dns_cache_config: name: dynamic_forward_proxy_cache_config dns_lookup_family: V4_ONLY allow_authority_override: true - name: envoy.filters.http.router typed_config: "@type": type.googleapis.com/envoy.extensions.filters.http.router.v3.Router clusters: - name: dynamic_forward_proxy_cluster lb_policy: CLUSTER_PROVIDED cluster_type: name: envoy.clusters.dynamic_forward_proxy typed_config: "@type": type.googleapis.com/envoy.extensions.clusters.dynamic_forward_proxy.v3.ClusterConfig dns_cache_config: name: dynamic_forward_proxy_cache_config dns_lookup_family: V4_ONLY allow_insecure_dynamic_hosts: true - name: backend_cluster connect_timeout: 3s type: STRICT_DNS lb_policy: ROUND_ROBIN load_assignment: cluster_name: backend_cluster endpoints: []
关键修改说明
- 添加Lua过滤器:读取三个自定义Header,重写
:path为X-Fwd-Path的值,同时将:authority构造为主机:端口格式,传递给动态转发代理作为目标地址 - 调整动态转发代理配置:开启
allow_authority_override: true允许通过:authority头覆盖目标地址,添加allow_insecure_dynamic_hosts: true支持解析带端口的主机地址 - 移除原
host_rewrite_header:改用Lua统一处理:authority头构造,避免配置冲突
验证逻辑
当请求携带以下Header时:
X-Fwd-Host: backservice-hello-dotnet.default.svc.cluster.localX-Fwd-Port: 6001X-Fwd-Path: /hello
Envoy会将请求转发至backservice-hello-dotnet.default.svc.cluster.local:6001/hello,与预期一致。
内容的提问来源于stack exchange,提问作者Raheel
相关产品推荐
相关产品推荐

