Istio gRPC网关接收请求但客户端无法获取响应求助
Istio入口网关配置gRPC服务时响应异常问题
问题描述
配置Istio入口网关暴露gRPC服务后,Postman可通过Reflector拉取到gRPC方法,但无法接收服务端响应,返回Received RST_STREAM with code 0。服务端日志显示请求已接收、处理并发送响应,但客户端收不到结果。尝试修改网关协议为grpc/http无效,仅HTTP2可用,怀疑问题与mTLS或gRPC的TLS要求相关。
Istio配置
apiVersion: networking.istio.io/v1beta1 kind: Gateway metadata: name: test-grpc-gateway namespace: istio-system spec: selector: app:-grpc-gateway environment: test servers: - hosts: - test-grpc-gateway.apps.osh-cln01-test.eub.kz port: name: http2 number: 80 protocol: HTTP2 --- apiVersion: networking.istio.io/v1beta1 kind: VirtualService metadata: name: adapter-info-grpc namespace: istio-system spec: gateways: - test-grpc-gateway hosts: - '*' http: - match: - uri: prefix: / route: - destination: host: adapter-info.adapters.svc.cluster.local port: number: 10540 subset: adapter-info-grpc --- apiVersion: networking.istio.io/v1beta1 kind: DestinationRule metadata: name: adapter-rsbk-info-grpc namespace: adapters spec: host: adapter-info.adapters.svc.cluster.local subsets: - labels: app.kubernetes.io/instance: adapter-info app.kubernetes.io/name: adapter-info name: adapter-info-grpc trafficPolicy: portLevelSettings: - loadBalancer: simple: ROUND_ROBIN port: number: 10540
服务端日志
2023-12-05T14:49:50.8062336+06:00 [INF] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Hosting.Diagnostics) Request starting HTTP/2 POST http://test-grpc-gateway.apps.osh-cln01-test.example.com/grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo application/grpc - 2023-12-05T14:49:50.8079935+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Routing.Matching.DfaMatcher) 3 candidate(s) found for the request path "/grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo" 2023-12-05T14:49:50.8080435+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Routing.Matching.DfaMatcher) Endpoint "gRPC - /grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo" with route pattern "/grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo" is valid for the request path "/grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo" 2023-12-05T14:49:50.8080710+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Routing.Matching.DfaMatcher) Endpoint "gRPC - Unimplemented method for grpc.reflection.v1alpha.ServerReflection" with route pattern "grpc.reflection.v1alpha.ServerReflection/{unimplementedMethod:grpcunimplemented}" is valid for the request path "/grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo" 2023-12-05T14:49:50.8080886+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Routing.Matching.DfaMatcher) Endpoint "gRPC - Unimplemented service" with route pattern "{unimplementedService}/{unimplementedMethod:grpcunimplemented}" is valid for the request path "/grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo" 2023-12-05T14:49:50.8081917+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Routing.EndpointRoutingMiddleware) Request matched endpoint "gRPC - /grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo" 2023-12-05T14:49:50.8087639+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.StaticFiles.StaticFileMiddleware) Static files was skipped as the request already matched an endpoint. 2023-12-05T14:49:50.8088214+06:00 [INF] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Routing.EndpointMiddleware) Executing endpoint "gRPC - /grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo" 2023-12-05T14:49:50.8209506+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Grpc.AspNetCore.Server.ServerCallHandler) Reading message. 2023-12-05T14:49:50.8210085+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Server.Kestrel) Connection id "0HMVLDSFKPKGC", Request id "0HMVLDSFKPKGC:00000001": started reading request body. 2023-12-05T14:49:50.8210705+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Server.Kestrel) Connection id "0HMVLDSFKPKGC", Request id "0HMVLDSFKPKGC:00000001": done reading request body. 2023-12-05T14:49:50.8246357+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Grpc.AspNetCore.Server.ServerCallHandler) Sending message. 2023-12-05T14:49:50.8254736+06:00 [DBG] [0HMVLDSFKPKGC:00000001] (Grpc.AspNetCore.Server.ServerCallHandler) Reading message. 2023-12-05T14:49:50.8257861+06:00 [INF] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Routing.EndpointMiddleware) Executed endpoint "gRPC - /grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo" 2023-12-05T14:49:50.8261282+06:00 [INF] [0HMVLDSFKPKGC:00000001] (Microsoft.AspNetCore.Hosting.Diagnostics) Request finished HTTP/2 POST http://test-grpc-gateway.apps.osh-cln01-test.example.com/grpc.reflection.v1alpha.ServerReflection/ServerReflectionInfo application/grpc - - 200 - application/grpc 19.8670ms 2023-12-05T14:4
解决方案建议
- 修复Gateway Selector语法错误:当前Gateway的
selector.app:-grpc-gateway存在格式错误,缺少前缀内容,需修改为正确的标签值(例如app: test-grpc-gateway),否则网关无法匹配到对应的Ingress Pod,流量无法正常转发。 - 调整VirtualService路由类型:将VirtualService中的
http字段替换为grpc,同时将hosts指定为网关的具体域名,避免通配符匹配问题:apiVersion: networking.istio.io/v1beta1 kind: VirtualService metadata: name: adapter-info-grpc namespace: istio-system spec: gateways: - test-grpc-gateway hosts: - test-grpc-gateway.apps.osh-cln01-test.eub.kz grpc: - match: - uri: prefix: / route: - destination: host: adapter-info.adapters.svc.cluster.local port: number: 10540 subset: adapter-info-grpc - 配置mTLS策略:若集群启用全局mTLS,需在DestinationRule的
trafficPolicy中添加TLS配置,确保网关与后端服务的通信兼容:
若后端未启用mTLS,可将trafficPolicy: tls: mode: ISTIO_MUTUAL portLevelSettings: - loadBalancer: simple: ROUND_ROBIN port: number: 10540mode设置为DISABLE。 - 验证后端服务配置:确认后端gRPC服务确实监听在10540端口并使用HTTP2协议,同时Istio Sidecar已正确注入到后端服务Pod中。
- 检查网关TLS配置:gRPC通常要求TLS加密传输,若客户端需通过HTTPS访问,需在Gateway中配置443端口并提供对应证书,避免因协议加密不匹配导致响应中断。
内容的提问来源于stack exchange,提问作者Илес Шелматов
相关产品推荐
相关产品推荐

