Istio终止Redis流量TLS时出现404错误求助
问题分析与解决思路
你的核心问题是误用了VirtualService的路由段类型:
- 当Istio网关以
SIMPLE模式终止TLS后,需要转发的是明文TCP流量到Redis,此时应该使用tcp路由块,而非tls路由块(tls块仅适用于TLS透传场景,也就是PASSTHROUGH模式)。这就是为什么你会收到route_not_found错误——网关找不到对应TCP流量的路由规则。
修正后的配置
1. 更新VirtualService(关键修改)
将原VirtualService中的tls段替换为tcp段,明确匹配443端口的流量并转发到Redis的6379端口:
apiVersion: networking.istio.io/v1beta1 kind: VirtualService metadata: name: redis-vs namespace: infra-redis-poc spec: gateways: - istio-system/gateway hosts: - redis.cluster.company.com tcp: - match: - port: 443 sniHosts: - redis.cluster.company.com route: - destination: host: redis.infra-redis-poc.svc.cluster.local port: number: 6379
2. 验证Gateway配置(确保以下几点)
- 确认
domain-certSecret包含redis.cluster.company.com的域名:kubectl get secret domain-cert -n istio-system -o jsonpath='{.data.tls\.crt}' | base64 -d | openssl x509 -text | grep "DNS:" - 确认Gateway的HTTPS服务器配置正确(你的现有配置已经符合要求,无需修改):
- hosts: - '*' port: name: https number: 443 protocol: HTTPS tls: credentialName: domain-cert mode: SIMPLE
额外验证步骤
- 客户端连接测试:使用Redis CLI通过TLS连接网关的443端口
redis-cli -h redis.cluster.company.com -p 443 --tls - 查看Istio网关日志,确认TLS终止和流量转发情况:
kubectl logs -n istio-system -l istio=ingressgateway -c istio-proxy | grep redis.cluster.company.com - 检查VirtualService是否生效:
istioctl analyze
内容的提问来源于stack exchange,提问作者PatrikJ
相关产品推荐
相关产品推荐

