You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Istio gRPC网关接收请求但客户端无法获取响应求助

Istio入口网关配置gRPC服务时响应异常问题

问题描述

配置Istio入口网关暴露gRPC服务后,Postman可通过Reflector拉取到gRPC方法,但无法接收服务端响应,返回Received RST_STREAM with code 0。服务端日志显示请求已接收、处理并发送响应,但客户端收不到结果。尝试修改网关协议为grpc/http无效,仅HTTP2可用,怀疑问题与mTLS或gRPC的TLS要求相关。

Istio配置

apiVersion: networking.istio.io/v1beta1
kind: Gateway
metadata:
  name: test-grpc-gateway
  namespace: istio-system
spec:
  selector:
    app:-grpc-gateway
    environment: test
  servers:
    - hosts:
        - test-grpc-gateway.apps.osh-cln01-test.eub.kz
      port:
        name: http2
        number: 80
        protocol: HTTP2
---
apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
  name: adapter-info-grpc
  namespace: istio-system
spec:
  gateways:
    - test-grpc-gateway
  hosts:
    - '*'
  http:
    - match:
        - uri:
            prefix: /
      route:
        - destination:
            host: adapter-info.adapters.svc.cluster.local
            port:
              number: 10540
            subset: adapter-info-grpc
---
apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
  name: adapter-rsbk-info-grpc
  namespace: adapters
spec:
  host: adapter-info.adapters.svc.cluster.local
  subsets:
    - labels:
        app.kubernetes.io/instance: adapter-info
        app.kubernetes.io/name: adapter-info
      name: adapter-info-grpc
  trafficPolicy:
    portLevelSettings:
      - loadBalancer:
          simple: ROUND_ROBIN
        port:
          number: 10540

服务端日志

2023-12-05T14:49:50.8062336+06:00 [INF] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Hosting.Diagnostics) Request starting HTTP/2 POST http://test-grpc-gateway.apps.osh-cln01-test.example.com/grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo application/grpc -
2023-12-05T14:49:50.8079935+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Routing.Matching.DfaMatcher) 3 candidate(s) found for the request path "/grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo"
2023-12-05T14:49:50.8080435+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Routing.Matching.DfaMatcher) Endpoint "gRPC - /grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo" with route pattern "/grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo" is valid for the request path "/grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo"
2023-12-05T14:49:50.8080710+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Routing.Matching.DfaMatcher) Endpoint "gRPC - Unimplemented method for grpc.reflection.v1alpha.ServerReflection" with route pattern "grpc.reflection.v1alpha.ServerReflection/{unimplementedMethod:grpcunimplemented}" is valid for the request path "/grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo"
2023-12-05T14:49:50.8080886+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Routing.Matching.DfaMatcher) Endpoint "gRPC - Unimplemented service" with route pattern "{unimplementedService}/{unimplementedMethod:grpcunimplemented}" is valid for the request path "/grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo"
2023-12-05T14:49:50.8081917+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Routing.EndpointRoutingMiddleware) Request matched endpoint "gRPC - /grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo"
2023-12-05T14:49:50.8087639+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.StaticFiles.StaticFileMiddleware) Static files was skipped as the request already matched an endpoint.
2023-12-05T14:49:50.8088214+06:00 [INF] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Routing.EndpointMiddleware) Executing endpoint "gRPC - /grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo"
2023-12-05T14:49:50.8209506+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Grpc.AspNetCore.Server.ServerCallHandler) Reading message.
2023-12-05T14:49:50.8210085+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Server.Kestrel) Connection id "0HMVLDSFKPKGC", Request id "0HMVLDSFKPKGC:00000001": started reading request body.
2023-12-05T14:49:50.8210705+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Server.Kestrel) Connection id "0HMVLDSFKPKGC", Request id "0HMVLDSFKPKGC:00000001": done reading request body.
2023-12-05T14:49:50.8246357+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Grpc.AspNetCore.Server.ServerCallHandler) Sending message.
2023-12-05T14:49:50.8254736+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Grpc.AspNetCore.Server.ServerCallHandler) Reading message.
2023-12-05T14:49:50.8257861+06:00 [INF] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Routing.EndpointMiddleware) Executed endpoint "gRPC - /grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo"
2023-12-05T14:49:50.8261282+06:00 [INF] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Hosting.Diagnostics) Request finished HTTP/2 POST http://test-grpc-gateway.apps.osh-cln01-test.example.com/grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo application/grpc - - 200 - application/grpc 19.8670ms
2023-12-05T14:4

解决方案建议

  • 修复Gateway Selector语法错误:当前Gateway的selector.app:-grpc-gateway存在格式错误,缺少前缀内容,需修改为正确的标签值(例如app: test-grpc-gateway),否则网关无法匹配到对应的Ingress Pod,流量无法正常转发。
  • 调整VirtualService路由类型:将VirtualService中的http字段替换为grpc,同时将hosts指定为网关的具体域名,避免通配符匹配问题:
    apiVersion: networking.istio.io/v1beta1
    kind: VirtualService
    metadata:
      name: adapter-info-grpc
      namespace: istio-system
    spec:
      gateways:
        - test-grpc-gateway
      hosts:
        - test-grpc-gateway.apps.osh-cln01-test.eub.kz
      grpc:
        - match:
            - uri:
                prefix: /
          route:
            - destination:
                host: adapter-info.adapters.svc.cluster.local
                port:
                  number: 10540
                subset: adapter-info-grpc
    
  • 配置mTLS策略:若集群启用全局mTLS,需在DestinationRule的trafficPolicy中添加TLS配置,确保网关与后端服务的通信兼容:
    trafficPolicy:
      tls:
        mode: ISTIO_MUTUAL
      portLevelSettings:
        - loadBalancer:
            simple: ROUND_ROBIN
          port:
            number: 10540
    
    若后端未启用mTLS,可将mode设置为DISABLE。
  • 验证后端服务配置:确认后端gRPC服务确实监听在10540端口并使用HTTP2协议,同时Istio Sidecar已正确注入到后端服务Pod中。
  • 检查网关TLS配置:gRPC通常要求TLS加密传输,若客户端需通过HTTPS访问,需在Gateway中配置443端口并提供对应证书,避免因协议加密不匹配导致响应中断。

内容的提问来源于stack exchange,提问作者Илес Шелматов

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 12:54:57