You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Envoy多路径匹配与重写配置排查:上游503问题咨询

Envoy 503错误排查与配置修正

问题描述

我能成功连接到Envoy,但Envoy与上游主机通信时返回503状态码导致请求中断。我需要实现本地路径匹配、重写为远程路径后调用上游服务,请问我的Envoy启动配置是否正确?

原配置代码

static_resources:
  listeners:
  - name: envoy_listener
    address:
      socket_address:
        protocol: TCP
        address: 0.0.0.0
        port_value: 9000
    filter_chains:
    - filters:
      - name: envoy.filters.network.http_connection_manager
        typed_config:
          "@type": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager
          stat_prefix: ingress_http
          common_http_protocol_options:
            idle_timeout: 600s
          access_log:
          - name: envoy.access_loggers.stdout
            typed_config:
              "@type": type.googleapis.com/envoy.extensions.access_loggers.stream.v3.StdoutAccessLog
              log_format:
                json_format:
                  "timestamp": "%START_TIME%"
                  "protocol": "%PROTOCOL%"
                  "duration": "%DURATION%"
                  "response_code": "%RESPONSE_CODE%"
                  "user_agent": "%REQ(USER-AGENT)%"
          route_config:
            name: routes
            virtual_hosts:
            - name: 1po
              domains:
              - "*"
              routes:
              - match:
                  path_match_policy:
                    name: envoy.path.match.uri_template.uri_template_matcher
                    typed_config:
                      "@type": type.googleapis.com/envoy.extensions.path.match.uri_template.v3.UriTemplateMatchConfig
                      path_template: "/test"
                route:
                  path_rewrite_policy:
                    name: envoy.path.rewrite.uri_template.uri_template_rewriter
                    typed_config:
                      "@type": type.googleapis.com/envoy.extensions.path.rewrite.uri_template.v3.UriTemplateRewriteConfig
                      path_template_rewrite: "/imghp"
                  cluster: "recommendations"
                  retry_policy:
                    retry_on: "5xx"
                    num_retries: 0
              - match:
                  path_match_policy:
                    name: envoy.path.match.uri_template.uri_template_matcher
                    typed_config:
                      "@type": type.googleapis.com/envoy.extensions.path.match.uri_template.v3.UriTemplateMatchConfig
                      path_template: "/test2"
                route:
                  path_rewrite_policy:
                    name: envoy.path.rewrite.uri_template.uri_template_rewriter
                    typed_config:
                      "@type": type.googleapis.com/envoy.extensions.path.rewrite.uri_template.v3.UriTemplateRewriteConfig
                      path_template_rewrite: "/translate"
                  cluster: "access"
                  retry_policy:
                    retry_on: "5xx"
                    num_retries: 0
          http_filters:
          - name: envoy.filters.http.router
            typed_config:
              "@type": type.googleapis.com/envoy.extensions.filters.http.router.v3.Router
  clusters:
  - name: recommendations
    typed_extension_protocol_options:
      envoy.extensions.upstreams.http.v3.HttpProtocolOptions:
        "@type": type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions
        upstream_http_protocol_options:
          auto_sni: true
        common_http_protocol_options:
          idle_timeout: 600s
        explicit_http_config:
          http2_protocol_options:
            max_concurrent_streams: 100
    connect_timeout: 5.0s
    circuit_breakers:
      thresholds:
        - priority: DEFAULT
          max_connections: 1024
        - priority: DEFAULT
          max_pending_requests: 1024
        - priority: DEFAULT
          max_requests: 1024
        - priority: DEFAULT
          max_retries: 0
    type: STRICT_DNS
    dns_refresh_rate: 3600s
    load_assignment:
      cluster_name: recommendations
      endpoints:
      - lb_endpoints:
        - endpoint:
            address:
              socket_address:
                address: google.com
                port_value: 443
  - name: access
    typed_extension_protocol_options:
      envoy.extensions.upstreams.http.v3.HttpProtocolOptions:
        "@type": type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions
        upstream_http_protocol_options:
          auto_sni: true
        common_http_protocol_options:
          idle_timeout: 600s
        explicit_http_config:
          http2_protocol_options:
            max_concurrent_streams: 100
    connect_timeout: 5.0s
    circuit_breakers:
      thresholds:
        - priority: DEFAULT
          max_connections: 1024
        - priority: DEFAULT
          max_pending_requests: 1024
        - priority: DEFAULT
          max_requests: 1024
        - priority: DEFAULT
          max_retries: 0
    type: STRICT_DNS
    dns_refresh_rate: 3600s
    load_assignment:
      cluster_name: access
      endpoints:
      - lb_endpoints:
        - endpoint:
            address:
              socket_address:
                address: yahoo.com
                port_value: 443
admin:
  access_log:
  - name: envoy.access_loggers.stdout
    typed_config:
      "@type": type.googleapis.com/envoy.extensions.access_loggers.stream.v3.StdoutAccessLog
  address:
    socket_address:
      protocol: TCP
      address: 127.0.0.1
      port_value: 9045

请求日志信息

{
   "upstream_cluster":"recommendations",
   "downstream_transport_failure_reason":null,
   "response_code":503,
   "downstream_remote_address":"127.0.0.1:41770",
   "request_duration":0,
   "response_tx_duration":null,
   "duration":0,
   "timestamp":"2023-06-09T18:14:52.599Z",
   "connection_termination_details":null,
   "upstream_request_attempt_count":1,
   "upstream_local_address":null,
   "grpc_status":"Unavailable",
   "virtual_cluster_name":null,
   "upstream_transport_failure_reason":"immediate_connect_error:_Network_is_unreachable",
   "protocol":"HTTP/1.1",
   "response_duration":null,
   "request_tx_duration":null,
   "connection_id":0,
   "upstream_remote_address":"[2a00:1450:4014:80a::200e]:443",
   "upstream_host":"[2a00:1450:4014:80a::200e]:443",
   "upstream_protocol":null,
   "path":"/test",
   "downstream_handshake_duration":null,
   "response_flags":"UF,URX",
   "stream_id":"48bd2614-3e54-4c77-8adc-d37a1b148130",
   "route_name":null,
   "user_agent":"curl/7.74.0",
   "response_code_details":"upstream_reset_before_response_started{connection_failure,immediate_connect_error:_Network_is_unreachable}"
}

问题分析与修正

核心错误点

  1. 缺少HTTPS上游的TLS配置:上游集群使用443端口(HTTPS服务),但原配置未启用TLS加密传输,Envoy默认用明文HTTP连接,导致无法与上游建立有效会话。
  2. IPv6网络不可达:日志显示Envoy解析到上游的IPv6地址,但本地网络无法访问IPv6资源,触发连接失败。
  3. 路径匹配与重写的逻辑本身语法正确,无需修改,待上述问题修复后即可正常生效。

修正后的配置

给每个上游集群添加transport_socket配置启用TLS,并指定DNS优先解析IPv4:

static_resources:
  listeners:
  - name: envoy_listener
    address:
      socket_address:
        protocol: TCP
        address: 0.0.0.0
        port_value: 9000
    filter_chains:
    - filters:
      - name: envoy.filters.network.http_connection_manager
        typed_config:
          "@type": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager
          stat_prefix: ingress_http
          common_http_protocol_options:
            idle_timeout: 600s
          access_log:
          - name: envoy.access_loggers.stdout
            typed_config:
              "@type": type.googleapis.com/envoy.extensions.access_loggers.stream.v3.StdoutAccessLog
              log_format:
                json_format:
                  "timestamp": "%START_TIME%"
                  "protocol": "%PROTOCOL%"
                  "duration": "%DURATION%"
                  "response_code": "%RESPONSE_CODE%"
                  "user_agent": "%REQ(USER-AGENT)%"
          route_config:
            name: routes
            virtual_hosts:
            - name: 1po
              domains:
              - "*"
              routes:
              - match:
                  path_match_policy:
                    name: envoy.path.match.uri_template.uri_template_matcher
                    typed_config:
                      "@type": type.googleapis.com/envoy.extensions.path.match.uri_template.v3.UriTemplateMatchConfig
                      path_template: "/test"
                route:
                  path_rewrite_policy:
                    name: envoy.path.rewrite.uri_template.uri_template_rewriter
                    typed_config:
                      "@type": type.googleapis.com/envoy.extensions.path.rewrite.uri_template.v3.UriTemplateRewriteConfig
                      path_template_rewrite: "/imghp"
                  cluster: "recommendations"
                  retry_policy:
                    retry_on: "5xx"
                    num_retries: 0
              - match:
                  path_match_policy:
                    name: envoy.path.match.uri_template.uri_template_matcher
                    typed_config:
                      "@type": type.googleapis.com/envoy.extensions.path.match.uri_template.v3.UriTemplateMatchConfig
                      path_template: "/test2"
                route:
                  path_rewrite_policy:
                    name: envoy.path.rewrite.uri_template.uri_template_rewriter
                    typed_config:
                      "@type": type.googleapis.com/envoy.extensions.path.rewrite.uri_template.v3.UriTemplateRewriteConfig
                      path_template_rewrite: "/translate"
                  cluster: "access"
                  retry_policy:
                    retry_on: "5xx"
                    num_retries: 0
          http_filters:
          - name: envoy.filters.http.router
            typed_config:
              "@type": type.googleapis.com/envoy.extensions.filters.http.router.v3.Router
  clusters:
  - name: recommendations
    typed_extension_protocol_options:
      envoy.extensions.upstreams.http.v3.HttpProtocolOptions:
        "@type": type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions
        upstream_http_protocol_options:
          auto_sni: true
        common_http_protocol_options:
          idle_timeout: 600s
        explicit_http_config:
          http2_protocol_options:
            max_concurrent_streams: 100
    connect_timeout: 5.0s
    circuit_breakers:
      thresholds:
        - priority: DEFAULT
          max_connections: 1024
        - priority: DEFAULT
          max_pending_requests: 1024
        - priority: DEFAULT
          max_requests: 1024
        - priority: DEFAULT
          max_retries: 0
    type: STRICT_DNS
    # 指定优先解析IPv4
    dns_lookup_family: V4_ONLY
    dns_refresh_rate: 3600s
    # 添加TLS配置
    transport_socket:
      name: envoy.transport_sockets.tls
      typed_config:
        "@type": type.googleapis.com/envoy.extensions.transport_sockets.tls.v3.UpstreamTlsContext
        common_tls_context:
          validation_context:
            trusted_ca:
              filename: "/etc/ssl/certs/ca-certificates.crt"
    load_assignment:
      cluster_name: recommendations
      endpoints:
      - lb_endpoints:
        - endpoint:
            address:
              socket_address:
                address: google.com
                port_value: 443
  - name: access
    typed_extension_protocol_options:
      envoy.extensions.upstreams.http.v3.HttpProtocolOptions:
        "@type": type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions
        upstream_http_protocol_options:
          auto_sni: true
        common_http_protocol_options:
          idle_timeout: 600s
        explicit_http_config:
          http2_protocol_options:
            max_concurrent_streams: 100
    connect_timeout: 5.0s
    circuit_breakers:
      thresholds:
        - priority: DEFAULT
          max_connections: 1024
        - priority: DEFAULT
          max_pending_requests: 1024
        - priority: DEFAULT
          max_requests: 1024
        - priority: DEFAULT
          max_retries: 0
    type: STRICT_DNS
    # 指定优先解析IPv4
    dns_lookup_family: V4_ONLY
    dns_refresh_rate: 3600s
    # 添加TLS配置
    transport_socket:
      name: envoy.transport_sockets.tls
      typed_config:
        "@type": type.googleapis.com/envoy.extensions.transport_sockets.tls.v3.UpstreamTlsContext
        common_tls_context:
          validation_context:
            trusted_ca:
              filename: "/etc/ssl/certs/ca-certificates.crt"
    load_assignment:
      cluster_name: access
      endpoints:
      - lb_endpoints:
        - endpoint:
            address:
              socket_address:
                address: yahoo.com
                port_value: 443
admin:
  access_log:
  - name: envoy.access_loggers.stdout
    typed_config:
      "@type": type.googleapis.com/envoy.extensions.access_loggers.stream.v3.StdoutAccessLog
  address:
    socket_address:
      protocol: TCP
      address: 127.0.0.1
      port_value: 9045

关键修正说明

  • TLS配置:通过transport_socket启用TLS加密,指定系统根证书路径验证上游证书,确保HTTPS连接安全有效。
  • IPv4优先解析:添加dns_lookup_family: V4_ONLY,避免Envoy解析到无法访问的IPv6地址,解决网络不可达问题。

总结

原配置中的路径匹配与重写逻辑是正确的,503错误源于HTTPS上游未配置TLS和IPv6网络不可达。应用上述修正后,Envoy即可正常与上游建立连接,实现路径重转发的需求。

内容的提问来源于stack exchange,提问作者Martin Smola

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 08:19:55