Istio Delegate Virtual Service路由404问题求助:多域名转发异常
Istio 404 NR route_not_found 问题排查与修复
问题根源分析
你的配置存在三个核心问题,导致api.example.com/svcA/api/foo/bar返回404:
Gateway Hosts格式错误
Istio Gateway的hosts字段不需要添加命名空间前缀(如nsA/api.example.com),直接填写域名即可。错误的格式会导致Gateway无法识别目标域名,请求无法进入Istio的路由流程。同时原Gateway缺少port配置,这是必填项,否则Gateway无法监听流量。被委托Virtual Service的Hosts不匹配
当single-hostnameVirtual Service将请求委托给svcAVirtual Service时,请求的Host头仍然是api.example.com,但原svcAVS的hosts仅包含svcA.example.com,因此不会匹配其路由规则,最终返回404。URI重写配置位置错误
原配置中rewrite与delegate并列的写法不符合Istio规则,需要将rewrite与match、delegate放在同一HTTP规则层级,确保URI重写后再传递给被委托的VS。
修复后的完整配置
1. 修正Gateway配置
--- apiVersion: networking.istio.io/v1beta1 kind: Gateway metadata: name: gateway namespace: nsA spec: servers: - port: number: 80 name: http protocol: HTTP hosts: - api.example.com - svcA.example.com
2. 修正统一入口Virtual Service
--- apiVersion: networking.istio.io/v1beta1 kind: VirtualService metadata: name: single-hostname namespace: nsA spec: gateways: - nsA/gateway hosts: - api.example.com http: - match: - uri: prefix: /svcA/ rewrite: uri: / delegate: name: svcA namespace: nsB
3. 更新业务Virtual Service
--- apiVersion: networking.istio.io/v1beta1 kind: VirtualService metadata: name: svcA namespace: nsB spec: gateways: - nsA/gateway hosts: - svcA.example.com - api.example.com # 新增该Host,匹配委托过来的请求 http: - match: - uri: prefix: /api/foo/bar route: - destination: host: svcA.nsB.svc.cluster.local
验证逻辑
修复后,请求api.example.com/svcA/api/foo/bar的处理流程:
- Gateway匹配
api.example.com域名,接收请求 single-hostnameVS匹配/svcA/前缀的URI,将其重写为/api/foo/bar- 委托给
nsB命名空间下的svcAVS svcAVS匹配api.example.com域名与/api/foo/bar前缀,路由至目标服务svcA.nsB.svc.cluster.local
内容的提问来源于stack exchange,提问作者mwalto7
相关产品推荐
相关产品推荐

