You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Istio Ingress暴露Kubernetes中带自签名证书的Elasticsearch

Istio Ingress 暴露自签名证书 Elasticsearch 配置指南

问题诊断

你提供的配置存在两个核心问题:

  1. Gateway 的 443 端口协议错误设置为 HTTP,HTTPS 流量必须使用 HTTPS 协议,并配置 TLS 证书关联
  2. 未针对自签名证书做适配配置,无论是在 Gateway 层终止 SSL,还是透传流量给 Elasticsearch,都缺少对应配置

分步修正配置

1. 准备自签名证书 Secret

先将你的 Elasticsearch 自签名证书(或用于 Ingress 终止 SSL 的证书)创建为 Kubernetes Secret,部署到 istio-system 命名空间:

kubectl create secret tls es-ingress-cert --cert=/path/to/your/cert.pem --key=/path/to/your/key.pem -n istio-system

若选择SSL 透传模式(让 Elasticsearch 直接处理 SSL 连接),可跳过此步骤。

2. 修正 Gateway 配置

根据需求选择以下两种模式之一:

模式一:Gateway 终止 SSL(推荐)

将 443 端口改为 HTTPS 协议,指定证书 Secret,并缩小域名匹配范围到你的 Elasticsearch 域名:

apiVersion: networking.istio.io/v1beta1
kind: Gateway
metadata:
  name: monitor-gateway
  namespace: istio-system
  labels:
    app: istio-ingress
    app.kubernetes.io/managed-by: Helm
    app.kubernetes.io/name: istio-ingress
    app.kubernetes.io/version: 1.15.3
    helm.sh/chart: gateway-1.15.3
    istio: ingress
spec:
  selector:
    istio: ingress
  servers:
  - hosts:
    - '*'
    port:
      name: http
      number: 80
      protocol: HTTP
    # 可选:自动将 HTTP 请求重定向到 HTTPS
    tls:
      httpsRedirect: true
  - hosts:
    - elasticsearch.domain.com # 仅匹配 ES 域名,避免全局 HTTPS 冲突
    port:
      name: https-es
      number: 443
      protocol: HTTPS
    tls:
      mode: SIMPLE
      credentialName: es-ingress-cert # 关联之前创建的证书 Secret
  - hosts:
    - '*'
    port:
      name: tcp
      number: 15021
      protocol: TCP

模式二:SSL 透传(直接转发 HTTPS 流量给 ES)

若不想在 Gateway 层终止 SSL,使用 TCP 路由透传流量:

apiVersion: networking.istio.io/v1beta1
kind: Gateway
metadata:
  name: monitor-gateway
  namespace: istio-system
  labels:
    app: istio-ingress
    app.kubernetes.io/managed-by: Helm
    app.kubernetes.io/name: istio-ingress
    app.kubernetes.io/version: 1.15.3
    helm.sh/chart: gateway-1.15.3
    istio: ingress
spec:
  selector:
    istio: ingress
  servers:
  - hosts:
    - '*'
    port:
      name: http
      number: 80
      protocol: HTTP
  - hosts:
    - elasticsearch.domain.com
    port:
      name: https-es-passthrough
      number: 443
      protocol: TCP
    tls:
      mode: PASSTHROUGH
  - hosts:
    - '*'
    port:
      name: tcp
      number: 15021
      protocol: TCP

3. 修正 VirtualService 配置

对应上述两种模式,调整 VirtualService:

对应模式一(Gateway 终止 SSL)

如果 Elasticsearch 本身使用 HTTPS,需要配置 Istio 信任其自签名证书:

kind: VirtualService
metadata:
  name: elasticsearch
  namespace: istio-system
spec:
  hosts:
    - elasticsearch.domain.com
  gateways:
    - monitor-gateway
  http:
    - match:
      - port: 443
      route:
      - destination:
          host: elasticsearch.monitor.svc.cluster.local
          port:
            number: 9200
        # 若 ES 为 HTTPS 服务,添加以下配置
        tls:
          mode: SIMPLE
          # 测试阶段可临时禁用证书验证(生产环境不建议)
          insecureSkipVerify: true
          # 生产环境建议关联 ES 服务器证书 Secret
          # credentialName: es-server-cert

对应模式二(SSL 透传)

使用 TCP 路由规则:

kind: VirtualService
metadata:
  name: elasticsearch
  namespace: istio-system
spec:
  hosts:
    - elasticsearch.domain.com
  gateways:
    - monitor-gateway
  tcp:
    - match:
      - port: 443
      route:
      - destination:
          host: elasticsearch.monitor.svc.cluster.local
          port:
            number: 9200

4. 验证配置

应用配置后,执行以下命令检查状态:

# 检查 Gateway 状态
kubectl get gateway monitor-gateway -n istio-system -o yaml
# 检查 VirtualService 状态
kubectl get virtualservice elasticsearch -n istio-system -o yaml
# 查看 Istio Ingress Pod 日志排查问题
kubectl logs -n istio-system -l istio=ingress

额外注意事项

  • 确保 Elasticsearch Service 可正常访问:在 Istio Ingress Pod 内执行 curl https://elasticsearch.monitor.svc.cluster.local:9200 测试连通性
  • 客户端访问时,需将自签名证书导入本地信任链,或使用 --insecure 参数临时跳过验证
  • Istio 1.15.3 版本较旧,若问题持续可考虑升级到稳定版本

内容的提问来源于stack exchange,提问作者sammahi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 00:04:02