如何从外部访问EC2实例中带Istio的Minikube内应用?
问题:EC2实例外部无法访问Minikube集群内的Istio示例应用
我有一台EC2实例,公网IP为13.XX.XX.XX(记为IP1),实例内运行Minikube集群,集群IP为10.XX.XX.XX(记为IP2)。集群中部署了istio-sample测试应用,在EC2内部通过curl http://IP2可以正常访问,但从EC2外部设备访问http://IP1失败。
环境配置详情
Pods状态
ubuntu@ip:~/istio-1.18.2$ kubectl get pods --all-namespaces NAMESPACE NAME READY STATUS RESTARTS AGE default details-v1-698b5d8c98-h5tbb 2/2 Running 0 24m default productpage-v1-75875cf969-zv858 2/2 Running 0 24m default ratings-v1-5967f59c58-5wwx2 2/2 Running 0 24m default reviews-v1-9c6bb6658-tb8rp 2/2 Running 0 24m default reviews-v2-8454bb78d8-rrtl8 2/2 Running 0 24m default reviews-v3-6dc9897554-h6h5n 2/2 Running 0 24m istio-system istio-egressgateway-57f9b4cdf5-tdbj8 1/1 Running 0 74m istio-system istio-ingressgateway-54f4b997fc-grnqz 1/1 Running 0 74m istio-system istiod-5489dc5cb7-mk5gd 1/1 Running 0 75m kube-system coredns-64897985d-ffjkq 1/1 Running 0 76m kube-system etcd-ip-172-xx-xx-xxx 1/1 Running 3 77m kube-system kube-apiserver-ip-172-xx-xx-xxx 1/1 Running 3 77m kube-system kube-controller-manager-ip-172-xx-xx-xxx 1/1 Running 3 77m kube-system kube-proxy-97gr2 1/1 Running 0 76m kube-system kube-scheduler-ip-172-xx-xx-xxx 1/1 Running 3 77m kube-system storage-provisioner 1/1 Running 0 77m
Services状态
ubuntu@:~/istio-1.18.2$ kubectl get svc --all-namespaces NAMESPACE NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE default details ClusterIP 10.106.199.96 9080/TCP 24m default kubernetes ClusterIP 10.96.0.1 443/TCP 77m default productpage ClusterIP 10.104.163.184 9080/TCP 24m default ratings ClusterIP 10.97.82.158 9080/TCP 24m default reviews ClusterIP 10.105.167.84 9080/TCP 24m istio-system istio-egressgateway ClusterIP 10.103.41.18 80/TCP,443/TCP 75m istio-system istio-ingressgateway LoadBalancer 10.106.66.152 15021:31706/TCP,80:31892/TCP,443:30491/TCP,31400:30512/TCP,15443:31409/TCP 75m istio-system istiod ClusterIP 10.96.231.111 15010/TCP,15012/TCP,443/TCP,15014/TCP 75m kube-system kube-dns ClusterIP 10.96.0.10 53/UDP,53/TCP,9153/TCP 77m
Nodes状态
ubuntu@:~/istio-1.18.2$ kubectl get nodes --all-namespaces NAME STATUS ROLES AGE VERSION ip-172-xx-xx-xxx Ready control-plane,master 77m v1.23.3
解决方案
1. 检查EC2安全组规则
确保EC2的安全组允许外部访问Istio IngressGateway暴露的NodePort端口(从Services状态看,80端口映射到了31892):
- 添加入站规则:允许
0.0.0.0/0(或指定IP段)访问TCP端口31892 - 同时确认EC2实例的网络ACL没有拦截该端口的流量
2. 配置端口转发
执行以下命令将EC2主机的80端口转发到Istio IngressGateway的80端口,让外部流量可以直接通过EC2公网IP访问:
nohup kubectl port-forward --address 0.0.0.0 svc/istio-ingressgateway -n istio-system 80:80 &
执行后,外部设备可通过http://IP1/productpage访问应用。
3. 确认Istio Ingress规则
确保已创建正确的Istio Gateway和VirtualService规则,将外部流量路由到productpage服务:
创建Gateway配置(gateway.yaml)
apiVersion: networking.istio.io/v1alpha3 kind: Gateway metadata: name: bookinfo-gateway spec: selector: istio: ingressgateway # 使用Istio默认的IngressGateway servers: - port: number: 80 name: http protocol: HTTP hosts: - "*"
创建VirtualService配置(virtualservice.yaml)
apiVersion: networking.istio.io/v1alpha3 kind: VirtualService metadata: name: bookinfo spec: hosts: - "*" gateways: - bookinfo-gateway http: - match: - uri: exact: /productpage - uri: prefix: /static - uri: exact: /login - uri: exact: /logout - uri: prefix: /api/v1/products route: - destination: host: productpage port: number: 9080
应用配置:
kubectl apply -f gateway.yaml -f virtualservice.yaml
4. 验证流量路径
- 在EC2内部测试访问Istio IngressGateway的NodePort:
curl http://localhost:31892/productpage,确认能正常返回内容 - 如果外部访问仍失败,检查EC2本地防火墙(如ufw)是否允许端口:
sudo ufw allow 31892/tcp
内容的提问来源于stack exchange,提问作者dipak mehta
相关产品推荐
相关产品推荐

