Envoy多路径匹配与重写配置排查:上游503问题咨询
Envoy 503错误排查与配置修正
问题描述
我能成功连接到Envoy,但Envoy与上游主机通信时返回503状态码导致请求中断。我需要实现本地路径匹配、重写为远程路径后调用上游服务,请问我的Envoy启动配置是否正确?
原配置代码
static_resources: listeners: - name: envoy_listener address: socket_address: protocol: TCP address: 0.0.0.0 port_value: 9000 filter_chains: - filters: - name: envoy.filters.network.http_connection_manager typed_config: "@type": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager stat_prefix: ingress_http common_http_protocol_options: idle_timeout: 600s access_log: - name: envoy.access_loggers.stdout typed_config: "@type": type.googleapis.com/envoy.extensions.access_loggers.stream.v3.StdoutAccessLog log_format: json_format: "timestamp": "%START_TIME%" "protocol": "%PROTOCOL%" "duration": "%DURATION%" "response_code": "%RESPONSE_CODE%" "user_agent": "%REQ(USER-AGENT)%" route_config: name: routes virtual_hosts: - name: 1po domains: - "*" routes: - match: path_match_policy: name: envoy.path.match.uri_template.uri_template_matcher typed_config: "@type": type.googleapis.com/envoy.extensions.path.match.uri_template.v3.UriTemplateMatchConfig path_template: "/test" route: path_rewrite_policy: name: envoy.path.rewrite.uri_template.uri_template_rewriter typed_config: "@type": type.googleapis.com/envoy.extensions.path.rewrite.uri_template.v3.UriTemplateRewriteConfig path_template_rewrite: "/imghp" cluster: "recommendations" retry_policy: retry_on: "5xx" num_retries: 0 - match: path_match_policy: name: envoy.path.match.uri_template.uri_template_matcher typed_config: "@type": type.googleapis.com/envoy.extensions.path.match.uri_template.v3.UriTemplateMatchConfig path_template: "/test2" route: path_rewrite_policy: name: envoy.path.rewrite.uri_template.uri_template_rewriter typed_config: "@type": type.googleapis.com/envoy.extensions.path.rewrite.uri_template.v3.UriTemplateRewriteConfig path_template_rewrite: "/translate" cluster: "access" retry_policy: retry_on: "5xx" num_retries: 0 http_filters: - name: envoy.filters.http.router typed_config: "@type": type.googleapis.com/envoy.extensions.filters.http.router.v3.Router clusters: - name: recommendations typed_extension_protocol_options: envoy.extensions.upstreams.http.v3.HttpProtocolOptions: "@type": type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions upstream_http_protocol_options: auto_sni: true common_http_protocol_options: idle_timeout: 600s explicit_http_config: http2_protocol_options: max_concurrent_streams: 100 connect_timeout: 5.0s circuit_breakers: thresholds: - priority: DEFAULT max_connections: 1024 - priority: DEFAULT max_pending_requests: 1024 - priority: DEFAULT max_requests: 1024 - priority: DEFAULT max_retries: 0 type: STRICT_DNS dns_refresh_rate: 3600s load_assignment: cluster_name: recommendations endpoints: - lb_endpoints: - endpoint: address: socket_address: address: google.com port_value: 443 - name: access typed_extension_protocol_options: envoy.extensions.upstreams.http.v3.HttpProtocolOptions: "@type": type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions upstream_http_protocol_options: auto_sni: true common_http_protocol_options: idle_timeout: 600s explicit_http_config: http2_protocol_options: max_concurrent_streams: 100 connect_timeout: 5.0s circuit_breakers: thresholds: - priority: DEFAULT max_connections: 1024 - priority: DEFAULT max_pending_requests: 1024 - priority: DEFAULT max_requests: 1024 - priority: DEFAULT max_retries: 0 type: STRICT_DNS dns_refresh_rate: 3600s load_assignment: cluster_name: access endpoints: - lb_endpoints: - endpoint: address: socket_address: address: yahoo.com port_value: 443 admin: access_log: - name: envoy.access_loggers.stdout typed_config: "@type": type.googleapis.com/envoy.extensions.access_loggers.stream.v3.StdoutAccessLog address: socket_address: protocol: TCP address: 127.0.0.1 port_value: 9045
请求日志信息
{ "upstream_cluster":"recommendations", "downstream_transport_failure_reason":null, "response_code":503, "downstream_remote_address":"127.0.0.1:41770", "request_duration":0, "response_tx_duration":null, "duration":0, "timestamp":"2023-06-09T18:14:52.599Z", "connection_termination_details":null, "upstream_request_attempt_count":1, "upstream_local_address":null, "grpc_status":"Unavailable", "virtual_cluster_name":null, "upstream_transport_failure_reason":"immediate_connect_error:_Network_is_unreachable", "protocol":"HTTP/1.1", "response_duration":null, "request_tx_duration":null, "connection_id":0, "upstream_remote_address":"[2a00:1450:4014:80a::200e]:443", "upstream_host":"[2a00:1450:4014:80a::200e]:443", "upstream_protocol":null, "path":"/test", "downstream_handshake_duration":null, "response_flags":"UF,URX", "stream_id":"48bd2614-3e54-4c77-8adc-d37a1b148130", "route_name":null, "user_agent":"curl/7.74.0", "response_code_details":"upstream_reset_before_response_started{connection_failure,immediate_connect_error:_Network_is_unreachable}" }
问题分析与修正
核心错误点
- 缺少HTTPS上游的TLS配置:上游集群使用443端口(HTTPS服务),但原配置未启用TLS加密传输,Envoy默认用明文HTTP连接,导致无法与上游建立有效会话。
- IPv6网络不可达:日志显示Envoy解析到上游的IPv6地址,但本地网络无法访问IPv6资源,触发连接失败。
- 路径匹配与重写的逻辑本身语法正确,无需修改,待上述问题修复后即可正常生效。
修正后的配置
给每个上游集群添加transport_socket配置启用TLS,并指定DNS优先解析IPv4:
static_resources: listeners: - name: envoy_listener address: socket_address: protocol: TCP address: 0.0.0.0 port_value: 9000 filter_chains: - filters: - name: envoy.filters.network.http_connection_manager typed_config: "@type": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager stat_prefix: ingress_http common_http_protocol_options: idle_timeout: 600s access_log: - name: envoy.access_loggers.stdout typed_config: "@type": type.googleapis.com/envoy.extensions.access_loggers.stream.v3.StdoutAccessLog log_format: json_format: "timestamp": "%START_TIME%" "protocol": "%PROTOCOL%" "duration": "%DURATION%" "response_code": "%RESPONSE_CODE%" "user_agent": "%REQ(USER-AGENT)%" route_config: name: routes virtual_hosts: - name: 1po domains: - "*" routes: - match: path_match_policy: name: envoy.path.match.uri_template.uri_template_matcher typed_config: "@type": type.googleapis.com/envoy.extensions.path.match.uri_template.v3.UriTemplateMatchConfig path_template: "/test" route: path_rewrite_policy: name: envoy.path.rewrite.uri_template.uri_template_rewriter typed_config: "@type": type.googleapis.com/envoy.extensions.path.rewrite.uri_template.v3.UriTemplateRewriteConfig path_template_rewrite: "/imghp" cluster: "recommendations" retry_policy: retry_on: "5xx" num_retries: 0 - match: path_match_policy: name: envoy.path.match.uri_template.uri_template_matcher typed_config: "@type": type.googleapis.com/envoy.extensions.path.match.uri_template.v3.UriTemplateMatchConfig path_template: "/test2" route: path_rewrite_policy: name: envoy.path.rewrite.uri_template.uri_template_rewriter typed_config: "@type": type.googleapis.com/envoy.extensions.path.rewrite.uri_template.v3.UriTemplateRewriteConfig path_template_rewrite: "/translate" cluster: "access" retry_policy: retry_on: "5xx" num_retries: 0 http_filters: - name: envoy.filters.http.router typed_config: "@type": type.googleapis.com/envoy.extensions.filters.http.router.v3.Router clusters: - name: recommendations typed_extension_protocol_options: envoy.extensions.upstreams.http.v3.HttpProtocolOptions: "@type": type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions upstream_http_protocol_options: auto_sni: true common_http_protocol_options: idle_timeout: 600s explicit_http_config: http2_protocol_options: max_concurrent_streams: 100 connect_timeout: 5.0s circuit_breakers: thresholds: - priority: DEFAULT max_connections: 1024 - priority: DEFAULT max_pending_requests: 1024 - priority: DEFAULT max_requests: 1024 - priority: DEFAULT max_retries: 0 type: STRICT_DNS # 指定优先解析IPv4 dns_lookup_family: V4_ONLY dns_refresh_rate: 3600s # 添加TLS配置 transport_socket: name: envoy.transport_sockets.tls typed_config: "@type": type.googleapis.com/envoy.extensions.transport_sockets.tls.v3.UpstreamTlsContext common_tls_context: validation_context: trusted_ca: filename: "/etc/ssl/certs/ca-certificates.crt" load_assignment: cluster_name: recommendations endpoints: - lb_endpoints: - endpoint: address: socket_address: address: google.com port_value: 443 - name: access typed_extension_protocol_options: envoy.extensions.upstreams.http.v3.HttpProtocolOptions: "@type": type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions upstream_http_protocol_options: auto_sni: true common_http_protocol_options: idle_timeout: 600s explicit_http_config: http2_protocol_options: max_concurrent_streams: 100 connect_timeout: 5.0s circuit_breakers: thresholds: - priority: DEFAULT max_connections: 1024 - priority: DEFAULT max_pending_requests: 1024 - priority: DEFAULT max_requests: 1024 - priority: DEFAULT max_retries: 0 type: STRICT_DNS # 指定优先解析IPv4 dns_lookup_family: V4_ONLY dns_refresh_rate: 3600s # 添加TLS配置 transport_socket: name: envoy.transport_sockets.tls typed_config: "@type": type.googleapis.com/envoy.extensions.transport_sockets.tls.v3.UpstreamTlsContext common_tls_context: validation_context: trusted_ca: filename: "/etc/ssl/certs/ca-certificates.crt" load_assignment: cluster_name: access endpoints: - lb_endpoints: - endpoint: address: socket_address: address: yahoo.com port_value: 443 admin: access_log: - name: envoy.access_loggers.stdout typed_config: "@type": type.googleapis.com/envoy.extensions.access_loggers.stream.v3.StdoutAccessLog address: socket_address: protocol: TCP address: 127.0.0.1 port_value: 9045
关键修正说明
- TLS配置:通过
transport_socket启用TLS加密,指定系统根证书路径验证上游证书,确保HTTPS连接安全有效。 - IPv4优先解析:添加
dns_lookup_family: V4_ONLY,避免Envoy解析到无法访问的IPv6地址,解决网络不可达问题。
总结
原配置中的路径匹配与重写逻辑是正确的,503错误源于HTTPS上游未配置TLS和IPv6网络不可达。应用上述修正后,Envoy即可正常与上游建立连接,实现路径重转发的需求。
内容的提问来源于stack exchange,提问作者Martin Smola
相关产品推荐
相关产品推荐

