You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Istio终止Redis流量TLS时出现404错误求助

问题分析与解决思路

你的核心问题是误用了VirtualService的路由段类型:

  • 当Istio网关以SIMPLE模式终止TLS后,需要转发的是明文TCP流量到Redis,此时应该使用tcp路由块,而非tls路由块(tls块仅适用于TLS透传场景,也就是PASSTHROUGH模式)。这就是为什么你会收到route_not_found错误——网关找不到对应TCP流量的路由规则。

修正后的配置

1. 更新VirtualService(关键修改)

将原VirtualService中的tls段替换为tcp段,明确匹配443端口的流量并转发到Redis的6379端口:

apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
  name: redis-vs
  namespace: infra-redis-poc
spec:
  gateways:
    - istio-system/gateway
  hosts:
  - redis.cluster.company.com
  tcp:
  - match:
    - port: 443
      sniHosts:
      - redis.cluster.company.com
    route:
    - destination:
        host: redis.infra-redis-poc.svc.cluster.local
        port:
          number: 6379

2. 验证Gateway配置(确保以下几点)

  • 确认domain-cert Secret包含redis.cluster.company.com的域名:
    kubectl get secret domain-cert -n istio-system -o jsonpath='{.data.tls\.crt}' | base64 -d | openssl x509 -text | grep "DNS:"
    
  • 确认Gateway的HTTPS服务器配置正确(你的现有配置已经符合要求,无需修改):
    - hosts:
      - '*'
      port:
        name: https
        number: 443
        protocol: HTTPS
      tls:
        credentialName: domain-cert
        mode: SIMPLE
    

额外验证步骤

  1. 客户端连接测试:使用Redis CLI通过TLS连接网关的443端口
    redis-cli -h redis.cluster.company.com -p 443 --tls
    
  2. 查看Istio网关日志,确认TLS终止和流量转发情况:
    kubectl logs -n istio-system -l istio=ingressgateway -c istio-proxy | grep redis.cluster.company.com
    
  3. 检查VirtualService是否生效:
    istioctl analyze
    

内容的提问来源于stack exchange,提问作者PatrikJ

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 04:12:21