You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Istio VirtualService跳转HTTPS服务遇TLS错误求助

问题分析与解决方案

核心问题定位

错误信息 TLS error: Secret is not supplied by SDS 表明 Istio 的 Envoy 代理期望通过Secret Discovery Service (SDS) 获取 TLS 证书,但当前配置未通过 SDS 提供所需的 CA 证书。手动将证书复制到 Envoy 容器的方式不符合 Istio 的 SDS 管理机制,导致验证失败。

分步解决方案

1. 创建 Kubernetes Secret 存储 CA 证书

首先将 CA 证书打包为 Kubernetes Secret,Istio 会通过 SDS 自动将其挂载到 Envoy 侧车容器:

kubectl create secret generic jhipster-registry-ca --from-file=ca.crt=REGISTRY.crt -n int
  • 替换 REGISTRY.crt 为你的实际 CA 证书文件名
  • 确保 Secret 与目标服务处于同一命名空间(int)

2. 修改 DestinationRule 引用 Secret

更新 DestinationRule,将 caCertificates 字段从文件路径改为 Secret 名称,让 Istio 通过 SDS 加载证书:

apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
  name: jhipster-registry-destinationrule
  namespace: int
spec:
  host: jhipster-registry
  trafficPolicy:
    tls:
      mode: SIMPLE
      caCertificates: jhipster-registry-ca # 引用刚创建的 Secret 名称

3. 验证证书与目标主机匹配

确保上游服务的 TLS 证书包含以下任一标识:

  • Kubernetes 服务名:jhipster-registry
  • 服务完整域名:jhipster-registry.int.svc.cluster.local

如果证书的 SAN/CN 是外部域名(如 jhipster-registry.myDomain.be),需在 DestinationRule 中添加 serverName 字段指定验证用的主机名:

trafficPolicy:
  tls:
    mode: SIMPLE
    caCertificates: jhipster-registry-ca
    serverName: jhipster-registry.myDomain.be # 匹配证书中的 SAN/CN

4. 应用配置并重启服务

# 应用更新后的 DestinationRule
kubectl apply -f destinationrule.yaml

# 重启目标服务,让侧车容器加载新配置
kubectl rollout restart deployment jhipster-registry -n int

5. 验证配置生效

  • 检查 Secret 是否正确创建:
    kubectl get secret jhipster-registry-ca -n int -o yaml
    
  • 确认服务 Pod 包含 Istio 侧车容器(2 个容器运行):
    kubectl get pods -n int | grep jhipster-registry
    

内容的提问来源于stack exchange,提问作者OniHanzo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 05:04:57