You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置Istio网关后无法访问HTTPS URL,请求协助排查

排查Istio HTTPS访问503错误的步骤

针对启用mTLS(PERMISSIVE模式)后HTTPS访问返回503、HTTP正常的问题,可按以下步骤逐一排查:

1. 验证后端服务的端口配置

你的VirtualService中目标服务端口指定为443:

destination:
  host: myservicename.mycorp.us.com
  port:
    number: 443
  • 执行kubectl get svc <service-name> -n <service-namespace>,确认后端Kubernetes Service是否真的暴露了443端口。
  • 如果服务本身监听HTTP端口(如8080),仅通过Istio sidecar处理mTLS,那么VirtualService应指向Service的HTTP端口(而非443)——PERMISSIVE模式允许sidecar与服务之间用明文通信。

2. 检查PeerAuthentication的作用范围

你的PeerAuthentication部署在default命名空间:

apiVersion: security.istio.io/v1beta1
kind: PeerAuthentication
metadata:
  name: default
spec:
  mtls:
    mode: PERMISSIVE
  • 若后端服务不在default命名空间,该配置不会对其生效。需在服务所在命名空间创建相同配置的PeerAuthentication,或添加namespaceSelector让配置覆盖多个命名空间。

3. 确认网关证书的位置与有效性

Gateway配置中引用的mycorp-cert Secret必须部署在Istio IngressGateway所在的命名空间(通常为istio-system):

tls:
  mode: SIMPLE
  credentialName: mycorp-cert
  • 执行kubectl get secret mycorp-cert -n istio-system,检查Secret是否存在且包含tls.crt和tls.key字段。
  • 若Secret在istio-config命名空间,IngressGateway Pod无法加载证书,会导致HTTPS请求处理失败并返回503。

4. 验证VirtualService目标Host的正确性

VirtualService中destination.host需使用Kubernetes Service的集群内FQDN,格式为<service-name>.<namespace>.svc.cluster.local:

  • 若myservicename.mycorp.us.com是外部域名,需确保集群内DNS能正确解析到后端Service,或直接改用集群内FQDN。

5. 查看IngressGateway日志定位具体错误

执行以下命令查看IngressGateway的日志,获取503错误的具体原因:

kubectl logs -n istio-system $(kubectl get pods -n istio-system -l istio=ingressgateway -o jsonpath='{.items[0].metadata.name}')

常见错误包括证书加载失败、路由匹配失败、后端连接超时/拒绝等,这些信息能直接指向问题根源。

6. 检查后端服务的健康状态

  • 执行kubectl get endpoints <service-name> -n <service-namespace>,确认Service关联的Pod端点是否正常就绪。
  • 若端点未就绪,Istio会返回503,需先排查服务本身的健康问题。

内容的提问来源于stack exchange,提问作者Venu Reddy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 12:52:44