能否在curl中直接使用x-envoy-upstream-rq-timeout-ms?测试未超时疑问
问题描述
在安装了Istio的Pod中执行curl命令,发送带有x-envoy-upstream-rq-timeout-ms: 1请求头的HTTP请求至http-echo-svc.circuit-breaker/200,参考Envoy Proxy文档设置该超时参数。原本期望请求因1ms的超时而失败,因为响应头显示上游服务实际耗时为x-envoy-upstream-service-time: 5,但请求却返回200状态码未触发超时,请问测试存在什么问题?
执行日志如下:
root@nginx:/# curl -v -H "x-envoy-upstream-rq-timeout-ms: 1" 'http://http-echo-svc.circuit-breaker/200' * Trying 172.20.236.72:80... * Connected to http-echo-svc.circuit-breaker (172.20.236.72) port 80 (#0) > GET /200 HTTP/1.1 > Host: http-echo-svc.circuit-breaker > User-Agent: curl/7.74.0 > Accept: */* > x-envoy-upstream-rq-timeout-ms: 1 > * Mark bundle as not supporting multiuse < HTTP/1.1 200 OK < content-length: 0 < date: Mon, 07 Aug 2023 07:21:48 GMT < x-envoy-upstream-service-time: 5 < server: envoy < * Connection #0 to host http-echo-svc.circuit-breaker left intact
问题分析与解决方案
核心原因:Istio默认禁用请求头覆盖超时的功能
Istio为保障配置一致性和安全性,默认不允许客户端通过x-envoy-upstream-rq-timeout-ms这类请求头覆盖预设的超时规则。即使请求携带该头,Envoy Sidecar会直接忽略它,转而使用全局或VirtualService中定义的默认超时(通常为15秒)。上游服务耗时5ms远低于默认超时阈值,自然不会触发超时错误。
解决步骤
1. 显式启用请求头超时覆盖功能
你需要通过Istio配置开启该功能,有两种方式可选:
- 全局Mesh配置:对集群内所有服务生效
apiVersion: istio.io/v1alpha1 kind: MeshConfig metadata: name: default spec: defaultConfig: gatewayTopology: allow_upstream_request_timeout_override: true
- 特定VirtualService配置:仅针对目标服务生效,更推荐此方式以降低全局风险
apiVersion: networking.istio.io/v1alpha3 kind: VirtualService metadata: name: http-echo-svc namespace: circuit-breaker spec: hosts: - http-echo-svc.circuit-breaker http: - route: - destination: host: http-echo-svc.circuit-breaker timeout: 10s # 设置基础超时,允许被请求头覆盖 allow_upstream_request_timeout_override: true
2. 验证配置生效
配置更新后,重启目标服务的Sidecar(或重新部署服务),然后通过以下命令检查Envoy路由配置,确认超时覆盖功能已开启:
istioctl proxy-config route <你的Pod名称> -n circuit-breaker
在输出中查找对应路由的allow_upstream_request_timeout_override字段,确认其值为true。
3. 重新测试
配置生效后,再次执行原curl命令,此时Envoy会遵循请求头中的1ms超时设置,当上游服务耗时5ms时,会触发超时并返回504 Gateway Timeout。
内容的提问来源于stack exchange,提问作者Youngrok Ko
相关产品推荐
相关产品推荐

