通过Istio转发至Salesforce自定义域名时出现TLS错误及503问题求助
Istio 重定向至Salesforce自定义域名时出现503错误
问题现象
通过Istio将连接重定向至Salesforce自定义域名时,浏览器返回503错误,具体提示:
upstream connect error or disconnect/reset before headers. retried and the latest reset reason: connection failure, transport failure reason: TLS error: 268436536:SSL routines:OPENSSL_internal:TLSV1_ALERT_INTERNAL_ERROR
Istio调试日志如下:
debug envoy pool queueing stream due to no available connections (ready=0 busy=0 connecting=0) debug envoy pool trying to create new connection debug envoy pool creating a new connection (connecting=0) debug envoy connection [C479766] current connecting state: true debug envoy client [C479766] connecting debug envoy connection [C479766] connecting to <removedIP>:443 debug envoy connection[C479766] connection in progress debug envoy connection [C479766] connected debug envoy connection [C479766] remote address: <removedIP>:443,TLS error: 268436536:SSL routines:OPENSSL_internal:TLSV1_ALERT_INTERNAL_ERROR debug envoy connection [C479766] closing socket: 0 debug envoy connection [C479766] remote address: <removedIP>:443,TLS error: 268436536:SSL routines:OPENSSL_internal:TLSV1_ALERT_INTERNAL_ERROR debug envoy client [C479766] disconnect. resetting 0 pending requests debug envoy pool [C479766] client disconnected, failure reason: TLS error: 268436536:SSL routines:OPENSSL_internal:TLSV1_ALERT_INTERNAL_ERROR debug envoy router [C479765][S8990209301599029630] upstream reset: reset reason: connection failure, transport failure reason: TLS error: 268436536:SSL routines:OPENSSL_internal:TLSV1_ALERT_INTERNAL_ERROR
环境信息
- Istio版本:1.15
- Kubernetes版本:1.24
解决方法
1. 配置正确的SNI
Salesforce自定义域名的TLS握手依赖正确的SNI字段,Istio发起上游连接时需确保SNI匹配目标域名。在DestinationRule中指定TLS模式和目标主机:
apiVersion: networking.istio.io/v1alpha3 kind: DestinationRule metadata: name: salesforce-custom-domain spec: host: your-salesforce-custom-domain.com trafficPolicy: tls: mode: SIMPLE host: your-salesforce-custom-domain.com
2. 匹配TLS版本与Cipher套件
Salesforce对TLS版本和Cipher套件有严格要求,需确保Istio使用兼容配置(推荐TLS 1.2及以上)。可在DestinationRule中指定:
apiVersion: networking.istio.io/v1alpha3 kind: DestinationRule metadata: name: salesforce-custom-domain spec: host: your-salesforce-custom-domain.com trafficPolicy: tls: mode: SIMPLE host: your-salesforce-custom-domain.com tlsSettings: minProtocolVersion: TLSV1_2 maxProtocolVersion: TLSV1_3 cipherSuites: - ECDHE-ECDSA-AES128-GCM-SHA256 - ECDHE-RSA-AES128-GCM-SHA256 - ECDHE-ECDSA-AES256-GCM-SHA384 - ECDHE-RSA-AES256-GCM-SHA384
3. 信任上游证书
若Salesforce自定义域名使用私有CA或自签名证书,需将对应CA证书添加到Istio信任池中,或在DestinationRule中指定证书路径:
apiVersion: networking.istio.io/v1alpha3 kind: DestinationRule metadata: name: salesforce-custom-domain spec: host: your-salesforce-custom-domain.com trafficPolicy: tls: mode: SIMPLE host: your-salesforce-custom-domain.com caCertificates: /etc/istio/ssl/salesforce-ca.crt
4. 验证网络连通性
确认Istio sidecar能访问Salesforce自定义域名的443端口,无防火墙或安全组拦截。可在sidecar容器内执行以下命令测试TLS握手:
curl -v https://your-salesforce-custom-domain.com
内容的提问来源于stack exchange,提问作者mati kepa
相关产品推荐
相关产品推荐

