You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Istio作为HTTPS代理,基于URI路径转发后端请求?

你当前的问题出在Gateway用了TLS PASSTHROUGH模式——这种模式下Istio不会解密客户端发来的HTTPS流量,只是把加密的TLS连接直接透传给后端服务,所以Istio根本看不到请求里的URI路径,自然HTTPRoute的规则没法生效。

要实现基于URI的HTTPS请求路由,得让Istio能解析HTTP内容,以下是两种可行方案:

方案一:Istio终止TLS(推荐,支持路径路由)

让Istio作为HTTPS入口,先解密客户端的TLS流量,解析出URI路径后再按规则路由,最后可以选择和后端服务用HTTP或HTTPS通信。

步骤1:修改Gateway配置(启用TLS终止)

首先创建包含证书和私钥的Secret(证书需匹配你的访问域名10.50.176.77),然后修改Gateway:

apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name: your-gateway-name
spec:
  selector:
    istio: ingressgateway # 替换成你的IngressGateway标签
  servers:
  - hosts:
    - 10.50.176.77
    port:
      name: https
      number: 443 # 标准HTTPS端口,也可保留15443
      protocol: HTTPS
    tls:
      mode: SIMPLE # 启用TLS终止
      credentialName: your-tls-secret # 替换成你的证书Secret名称

步骤2:修改VirtualService配置

去掉原来的tls部分,保留http路由规则(此时Istio处理的是解密后的HTTP流量):

apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: your-vs-name
spec:
  hosts:
  - 10.50.176.77
  gateways:
  - your-gateway-name # 关联上面修改的Gateway
  http:
  - match:
    - uri:
        prefix: /login
    route:
    - destination:
        host: console-web
        port:
          number: 8099
  - match:
    - uri:
        prefix: /auth
    route:
    - destination:
        host: console-auth
        port:
          number: 8098

步骤3:后端服务为HTTPS时配置重新加密

如果console-web和console-auth本身用HTTPS协议,需配置DestinationRule让Istio与后端通信时重新加密:

apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
  name: console-web-dr
spec:
  host: console-web
  trafficPolicy:
    tls:
      mode: SIMPLE # 与后端用HTTPS通信
---
apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
  name: console-auth-dr
spec:
  host: console-auth
  trafficPolicy:
    tls:
      mode: SIMPLE

配置完成后,客户端通过https://10.50.176.77/login或https://10.50.176.77/auth访问时,Istio会解密TLS流量,按URI路径路由到对应后端,且与后端保持HTTPS通信。

方案二:保持PASSTHROUGH模式(仅支持SNI路由,不支持路径)

如果业务必须让后端直接处理客户端TLS连接(比如需要客户端证书认证),只能基于SNI子域名路由,无法实现路径分流。示例配置如下:

apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: your-vs-name
spec:
  hosts:
  - web.10.50.176.77
  - auth.10.50.176.77
  gateways:
  - your-passthrough-gateway
  tls:
  - match:
    - port: 15443
      sniHosts:
      - web.10.50.176.77
    route:
    - destination:
        host: console-web
        port:
          number: 8099
  - match:
    - port: 15443
      sniHosts:
      - auth.10.50.176.77
    route:
    - destination:
        host: console-auth
        port:
          number: 8098

注意:该方案仅能按子域名分流,无法满足你基于URI路径路由的需求,因此优先选择方案一。

内容的提问来源于stack exchange,提问作者zxq

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 11:46:02