You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从外部访问EC2实例中带Istio的Minikube内应用?

问题:EC2实例外部无法访问Minikube集群内的Istio示例应用

我有一台EC2实例,公网IP为13.XX.XX.XX(记为IP1),实例内运行Minikube集群,集群IP为10.XX.XX.XX(记为IP2)。集群中部署了istio-sample测试应用,在EC2内部通过curl http://IP2可以正常访问,但从EC2外部设备访问http://IP1失败。

环境配置详情

Pods状态

ubuntu@ip:~/istio-1.18.2$ kubectl get pods --all-namespaces
NAMESPACE      NAME                                       READY   STATUS    RESTARTS   AGE
default        details-v1-698b5d8c98-h5tbb                2/2     Running   0          24m
default        productpage-v1-75875cf969-zv858            2/2     Running   0          24m
default        ratings-v1-5967f59c58-5wwx2                2/2     Running   0          24m
default        reviews-v1-9c6bb6658-tb8rp                 2/2     Running   0          24m
default        reviews-v2-8454bb78d8-rrtl8                2/2     Running   0          24m
default        reviews-v3-6dc9897554-h6h5n                2/2     Running   0          24m
istio-system   istio-egressgateway-57f9b4cdf5-tdbj8       1/1     Running   0          74m
istio-system   istio-ingressgateway-54f4b997fc-grnqz      1/1     Running   0          74m
istio-system   istiod-5489dc5cb7-mk5gd                    1/1     Running   0          75m
kube-system    coredns-64897985d-ffjkq                    1/1     Running   0          76m
kube-system    etcd-ip-172-xx-xx-xxx                      1/1     Running   3          77m
kube-system    kube-apiserver-ip-172-xx-xx-xxx            1/1     Running   3          77m
kube-system    kube-controller-manager-ip-172-xx-xx-xxx   1/1     Running   3          77m
kube-system    kube-proxy-97gr2                           1/1     Running   0          76m
kube-system    kube-scheduler-ip-172-xx-xx-xxx            1/1     Running   3          77m
kube-system    storage-provisioner                        1/1     Running   0          77m

Services状态

ubuntu@:~/istio-1.18.2$ kubectl get svc --all-namespaces
NAMESPACE      NAME                   TYPE           CLUSTER-IP       EXTERNAL-IP   PORT(S)                                                                      AGE
default        details                ClusterIP      10.106.199.96            9080/TCP                                                                     24m
default        kubernetes             ClusterIP      10.96.0.1                443/TCP                                                                      77m
default        productpage            ClusterIP      10.104.163.184           9080/TCP                                                                     24m
default        ratings                ClusterIP      10.97.82.158             9080/TCP                                                                     24m
default        reviews                ClusterIP      10.105.167.84            9080/TCP                                                                     24m
istio-system   istio-egressgateway    ClusterIP      10.103.41.18             80/TCP,443/TCP                                                               75m
istio-system   istio-ingressgateway   LoadBalancer   10.106.66.152         15021:31706/TCP,80:31892/TCP,443:30491/TCP,31400:30512/TCP,15443:31409/TCP   75m
istio-system   istiod                 ClusterIP      10.96.231.111            15010/TCP,15012/TCP,443/TCP,15014/TCP                                        75m
kube-system    kube-dns               ClusterIP      10.96.0.10               53/UDP,53/TCP,9153/TCP                                                       77m

Nodes状态

ubuntu@:~/istio-1.18.2$ kubectl get nodes --all-namespaces
NAME               STATUS   ROLES                  AGE   VERSION
ip-172-xx-xx-xxx   Ready    control-plane,master   77m   v1.23.3

解决方案

1. 检查EC2安全组规则

确保EC2的安全组允许外部访问Istio IngressGateway暴露的NodePort端口(从Services状态看,80端口映射到了31892):

  • 添加入站规则:允许0.0.0.0/0(或指定IP段)访问TCP端口31892
  • 同时确认EC2实例的网络ACL没有拦截该端口的流量

2. 配置端口转发

执行以下命令将EC2主机的80端口转发到Istio IngressGateway的80端口,让外部流量可以直接通过EC2公网IP访问:

nohup kubectl port-forward --address 0.0.0.0 svc/istio-ingressgateway -n istio-system 80:80 &

执行后,外部设备可通过http://IP1/productpage访问应用。

3. 确认Istio Ingress规则

确保已创建正确的Istio Gateway和VirtualService规则,将外部流量路由到productpage服务:

创建Gateway配置(gateway.yaml)

apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name: bookinfo-gateway
spec:
  selector:
    istio: ingressgateway # 使用Istio默认的IngressGateway
  servers:
  - port:
      number: 80
      name: http
      protocol: HTTP
    hosts:
    - "*"

创建VirtualService配置(virtualservice.yaml)

apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: bookinfo
spec:
  hosts:
  - "*"
  gateways:
  - bookinfo-gateway
  http:
  - match:
    - uri:
        exact: /productpage
    - uri:
        prefix: /static
    - uri:
        exact: /login
    - uri:
        exact: /logout
    - uri:
        prefix: /api/v1/products
    route:
    - destination:
        host: productpage
        port:
          number: 9080

应用配置:

kubectl apply -f gateway.yaml -f virtualservice.yaml

4. 验证流量路径

  • 在EC2内部测试访问Istio IngressGateway的NodePort:curl http://localhost:31892/productpage,确认能正常返回内容
  • 如果外部访问仍失败,检查EC2本地防火墙(如ufw)是否允许端口:
sudo ufw allow 31892/tcp

内容的提问来源于stack exchange,提问作者dipak mehta

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 23:45:29