You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes Istio:代理至带自签名证书的HTTPS后端

配置Istio忽略后端HTTPS服务的无效证书并保持前端TLS正常

要实现你的需求,核心是拆分两个独立的TLS链路:客户端与Istio网关之间的合法TLS终止(保证浏览器显示绿色安全标识),以及Istio代理与后端HTTPS服务之间跳过证书校验(适配第三方自签名证书)。以下是具体配置步骤:

1. 确保Istio Gateway的TLS终止配置正确

维持网关的TLS终止逻辑不变,使用受浏览器信任的合法证书(比如Let's Encrypt签发的证书),这部分是保证前端绿色标识的关键。示例配置:

apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name: your-ingress-gateway
  namespace: default
spec:
  selector:
    istio: ingressgateway # 匹配你的Ingress Gateway Pod标签
  servers:
  - port:
      number: 443
      name: https
      protocol: HTTPS
    tls:
      mode: SIMPLE
      credentialName: valid-domain-cert # 对应K8s中存储合法证书的Secret
    hosts:
    - "your-custom-domain.com" # 你的自有域名

2. 配置Istio跳过后端服务的证书校验

针对后端的自签名证书,通过DestinationRule配置Istio代理(Ingress Gateway或Sidecar)在转发请求时忽略证书有效性检查:

apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
  name: backend-service-dr
  namespace: backend-namespace # 后端Service所在的命名空间
spec:
  host: backend-service.backend-namespace.svc.cluster.local # 后端Service的完整FQDN
  trafficPolicy:
    tls:
      mode: SIMPLE # 明确后端使用HTTPS协议
      insecureSkipVerify: true # 关键配置:跳过证书校验

3. 关联Gateway与后端服务(可选,通过VirtualService)

如果需要将网关的流量路由到后端服务,补充VirtualService配置:

apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: backend-route-vs
  namespace: default
spec:
  hosts:
  - "your-custom-domain.com"
  gateways:
  - your-ingress-gateway
  http:
  - route:
    - destination:
        host: backend-service.backend-namespace.svc.cluster.local
        port:
          number: 443 # 后端的HTTPS端口

关键说明

  • insecureSkipVerify: true 会让Istio在与后端建立TLS连接时,跳过证书的签名验证、域名匹配检查等,直接接受自签名证书。
  • 客户端与网关之间的TLS链路完全正常,使用的是受信任的合法证书,因此浏览器会显示绿色安全标识。
  • 仅建议在你完全信任后端服务的场景下使用该配置,因为关闭证书校验存在中间人攻击风险,但对于第三方供应商的自签名证书,这是无法通过常规信任链解决的必要操作。

内容的提问来源于stack exchange,提问作者Jamie Clarke

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 10:25:23