You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Istio正确配置暴露Kubernetes中的SFTP服务(22端口)

问题分析与修正方案

你的SFTP服务通过Istio暴露失败,主要是配置中存在几处关键错误,以下是具体问题和修正后的完整配置:

关键错误点

  1. Service与Pod标签不匹配:Deployment的Pod标签为app: sftp,但Service的selector写的是app: sftp-deployment,导致Service无法关联到Pod,流量无法转发。
  2. Gateway端口命名不符合Istio规范:TCP类型的端口名称必须以tcp-前缀开头,否则Istio无法正确识别协议类型。
  3. VirtualService中Gateway引用格式错误:无需使用完整的FQDN,直接指定Gateway名称即可。
  4. Istio IngressGateway默认未暴露22端口:默认IngressGateway仅开放80、443等端口,需要手动添加22端口的暴露规则。
  5. Deployment挂载卷名称错误:volumeMounts.name与定义的volume名称不一致,会导致存储挂载失败。

修正后的完整配置

1. 修正后的Deployment配置

apiVersion: apps/v1
kind: Deployment
metadata:
  name: sftp-deployment
spec:
  replicas: 1
  selector:
    matchLabels:
      app: sftp
  template:
    metadata:
      labels:
        app: sftp
    spec:
      volumes:
      - name: sftp-storage
        persistentVolumeClaim:
          claimName: sftp-pvc
      containers:
      - name: sftp
        image: atmoz/sftp
        ports:
        - containerPort: 22
        env:
        - name: SFTP_USERS
          value: "user1:password:::user-directory"
        volumeMounts:
        - name: sftp-storage  # 修正为与volume定义一致的名称
          mountPath: "/home/user1/user-directory"
        resources:
          requests:
            memory: "64Mi"
            cpu: "250m"
          limits:
            memory: "128Mi"
            cpu: "500m"

2. 修正后的Service配置

kind: Service
apiVersion: v1
metadata:
  name: sftp-service
spec:
  ports:
    - protocol: TCP
      port: 22
      targetPort: 22
  selector:
    app: sftp  # 匹配Pod的标签

3. 修正后的Gateway配置

apiVersion: networking.istio.io/v1beta1
kind: Gateway
metadata:
  name: sftp-gw
spec:
  selector:
    istio: ingressgateway
  servers:
    - hosts:
        - '*'  # TCP模式下无需指定具体域名,用通配符即可
      port:
        name: tcp-sftp  # 必须以tcp-开头,符合Istio协议识别规范
        number: 22
        protocol: TCP

4. 修正后的VirtualService配置

apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
  name: sftp-vs
spec:
  gateways:
    - sftp-gw  # 直接使用Gateway名称,无需FQDN
  hosts:
    - '*'
  tcp:
    - match:
        - port: 22
      route:
        - destination:
            host: sftp-service.default.svc.cluster.local
            port:
              number: 22

5. 暴露Istio IngressGateway的22端口

默认IngressGateway未开放22端口,需要修改其Service配置:

apiVersion: v1
kind: Service
metadata:
  name: istio-ingressgateway
  namespace: istio-system
spec:
  ports:
    # 保留原有端口(如80、443等)
    - name: http2
      port: 80
      targetPort: 8080
    - name: https
      port: 443
      targetPort: 8443
    # 添加SFTP的22端口
    - name: tcp-sftp
      protocol: TCP
      port: 22
      targetPort: 22
      nodePort: 30022  # 若使用NodePort模式,指定可用端口;LoadBalancer模式可省略
  type: LoadBalancer  # 根据集群环境选择LoadBalancer或NodePort

验证步骤

  1. 应用所有修正后的配置:
kubectl apply -f sftp-deployment.yaml
kubectl apply -f sftp-service.yaml
kubectl apply -f sftp-gw.yaml
kubectl apply -f sftp-vs.yaml
kubectl apply -f istio-ingressgateway-service.yaml -n istio-system
  1. 获取IngressGateway的外部访问地址:
kubectl get svc istio-ingressgateway -n istio-system
  1. 使用SFTP客户端连接:
  • 主机:IngressGateway的外部IP(LoadBalancer模式)或NodeIP(NodePort模式)
  • 端口:22(LoadBalancer)或30022(NodePort)
  • 用户名:user1
  • 密码:password

内容的提问来源于stack exchange,提问作者f.bele

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 08:08:20