You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

借助Istio-Ingress网关外部访问GKE服务失败问题排查

问题排查与修复方案

1. 验证Grafana服务内部可达性

先确认Grafana服务在集群内部是否能正常访问:

kubectl exec -n istio-system <任意带Sidecar的Pod名称> -- curl grafana.istio-system.svc.cluster.local:80

如果请求失败,优先排查Grafana Pod是否正常运行、服务端口配置是否正确。

2. 修正Istio Gateway的HTTP端口命名规则

你的Gateway配置中,80端口的name设置为tcp但协议是HTTP,Istio要求HTTP类型端口的名称必须以http开头,否则无法正确识别端口类型。修改后的Gateway配置如下:

apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name:  my-gateway
  namespace:  istio-system
spec:
  selector:
    istio: ingressgateway 
  servers:
  - port:
      number: 80
      name: http  # 调整为http开头的名称
      protocol: HTTP
    hosts:
    - "*"
    tls:
      httpsRedirect: false
  - port:
      number:  443
      name: https
      protocol: HTTPS
    tls:
      mode: SIMPLE
      credentialName: ${var.shared_domain_certificate_name}
    hosts:
    - "*"

3. 确认IngressGateway的LoadBalancer配置

  • 检查IngressGateway Service的外部IP和端口映射:
    kubectl get svc istio-ingressgateway -n istio-system
    
    确保EXTERNAL-IP为有效公网地址,且PORT(S)字段包含80:xxxx/TCP、443:xxxx/TCP。
  • 针对GKE私有集群,需配置VPC防火墙规则允许外部流量访问LB的80/443端口:
    gcloud compute firewall-rules create allow-istio-ingress --allow tcp:80,tcp:443 --source-ranges 0.0.0.0/0 --target-tags <你的集群节点标签>
    

4. 校验虚拟服务与网关的关联有效性

验证Istio是否正确识别虚拟服务与网关的绑定关系:

kubectl describe virtualservice grafana -n istio-system

查看输出中Gateways字段是否包含istio-system/my-gateway,确认关联配置无误。

5. 通过日志定位问题

  • 查看IngressGateway日志,确认请求是否到达及具体报错:
    kubectl logs -n istio-system -l istio=ingressgateway --tail=100
    
  • 查看Istio Pilot日志,确认配置是否正常推送至网关:
    kubectl logs -n istio-system -l istio=pilot --tail=100
    

内容的提问来源于stack exchange,提问作者ali al-baiti

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 16:32:40