如何通过Istio Ingress暴露Kubernetes中带自签名证书的Elasticsearch
Istio Ingress 暴露自签名证书 Elasticsearch 配置指南
问题诊断
你提供的配置存在两个核心问题:
- Gateway 的 443 端口协议错误设置为
HTTP,HTTPS 流量必须使用HTTPS协议,并配置 TLS 证书关联 - 未针对自签名证书做适配配置,无论是在 Gateway 层终止 SSL,还是透传流量给 Elasticsearch,都缺少对应配置
分步修正配置
1. 准备自签名证书 Secret
先将你的 Elasticsearch 自签名证书(或用于 Ingress 终止 SSL 的证书)创建为 Kubernetes Secret,部署到 istio-system 命名空间:
kubectl create secret tls es-ingress-cert --cert=/path/to/your/cert.pem --key=/path/to/your/key.pem -n istio-system
若选择SSL 透传模式(让 Elasticsearch 直接处理 SSL 连接),可跳过此步骤。
2. 修正 Gateway 配置
根据需求选择以下两种模式之一:
模式一:Gateway 终止 SSL(推荐)
将 443 端口改为 HTTPS 协议,指定证书 Secret,并缩小域名匹配范围到你的 Elasticsearch 域名:
apiVersion: networking.istio.io/v1beta1 kind: Gateway metadata: name: monitor-gateway namespace: istio-system labels: app: istio-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: istio-ingress app.kubernetes.io/version: 1.15.3 helm.sh/chart: gateway-1.15.3 istio: ingress spec: selector: istio: ingress servers: - hosts: - '*' port: name: http number: 80 protocol: HTTP # 可选:自动将 HTTP 请求重定向到 HTTPS tls: httpsRedirect: true - hosts: - elasticsearch.domain.com # 仅匹配 ES 域名,避免全局 HTTPS 冲突 port: name: https-es number: 443 protocol: HTTPS tls: mode: SIMPLE credentialName: es-ingress-cert # 关联之前创建的证书 Secret - hosts: - '*' port: name: tcp number: 15021 protocol: TCP
模式二:SSL 透传(直接转发 HTTPS 流量给 ES)
若不想在 Gateway 层终止 SSL,使用 TCP 路由透传流量:
apiVersion: networking.istio.io/v1beta1 kind: Gateway metadata: name: monitor-gateway namespace: istio-system labels: app: istio-ingress app.kubernetes.io/managed-by: Helm app.kubernetes.io/name: istio-ingress app.kubernetes.io/version: 1.15.3 helm.sh/chart: gateway-1.15.3 istio: ingress spec: selector: istio: ingress servers: - hosts: - '*' port: name: http number: 80 protocol: HTTP - hosts: - elasticsearch.domain.com port: name: https-es-passthrough number: 443 protocol: TCP tls: mode: PASSTHROUGH - hosts: - '*' port: name: tcp number: 15021 protocol: TCP
3. 修正 VirtualService 配置
对应上述两种模式,调整 VirtualService:
对应模式一(Gateway 终止 SSL)
如果 Elasticsearch 本身使用 HTTPS,需要配置 Istio 信任其自签名证书:
kind: VirtualService metadata: name: elasticsearch namespace: istio-system spec: hosts: - elasticsearch.domain.com gateways: - monitor-gateway http: - match: - port: 443 route: - destination: host: elasticsearch.monitor.svc.cluster.local port: number: 9200 # 若 ES 为 HTTPS 服务,添加以下配置 tls: mode: SIMPLE # 测试阶段可临时禁用证书验证(生产环境不建议) insecureSkipVerify: true # 生产环境建议关联 ES 服务器证书 Secret # credentialName: es-server-cert
对应模式二(SSL 透传)
使用 TCP 路由规则:
kind: VirtualService metadata: name: elasticsearch namespace: istio-system spec: hosts: - elasticsearch.domain.com gateways: - monitor-gateway tcp: - match: - port: 443 route: - destination: host: elasticsearch.monitor.svc.cluster.local port: number: 9200
4. 验证配置
应用配置后,执行以下命令检查状态:
# 检查 Gateway 状态 kubectl get gateway monitor-gateway -n istio-system -o yaml # 检查 VirtualService 状态 kubectl get virtualservice elasticsearch -n istio-system -o yaml # 查看 Istio Ingress Pod 日志排查问题 kubectl logs -n istio-system -l istio=ingress
额外注意事项
- 确保 Elasticsearch Service 可正常访问:在 Istio Ingress Pod 内执行
curl https://elasticsearch.monitor.svc.cluster.local:9200测试连通性 - 客户端访问时,需将自签名证书导入本地信任链,或使用
--insecure参数临时跳过验证 - Istio 1.15.3 版本较旧,若问题持续可考虑升级到稳定版本
内容的提问来源于stack exchange,提问作者sammahi
相关产品推荐
相关产品推荐

