如何配置Istio作为HTTPS代理,基于URI路径转发后端请求?
你当前的问题出在Gateway用了TLS PASSTHROUGH模式——这种模式下Istio不会解密客户端发来的HTTPS流量,只是把加密的TLS连接直接透传给后端服务,所以Istio根本看不到请求里的URI路径,自然HTTPRoute的规则没法生效。
要实现基于URI的HTTPS请求路由,得让Istio能解析HTTP内容,以下是两种可行方案:
方案一:Istio终止TLS(推荐,支持路径路由)
让Istio作为HTTPS入口,先解密客户端的TLS流量,解析出URI路径后再按规则路由,最后可以选择和后端服务用HTTP或HTTPS通信。
步骤1:修改Gateway配置(启用TLS终止)
首先创建包含证书和私钥的Secret(证书需匹配你的访问域名10.50.176.77),然后修改Gateway:
apiVersion: networking.istio.io/v1alpha3 kind: Gateway metadata: name: your-gateway-name spec: selector: istio: ingressgateway # 替换成你的IngressGateway标签 servers: - hosts: - 10.50.176.77 port: name: https number: 443 # 标准HTTPS端口,也可保留15443 protocol: HTTPS tls: mode: SIMPLE # 启用TLS终止 credentialName: your-tls-secret # 替换成你的证书Secret名称
步骤2:修改VirtualService配置
去掉原来的tls部分,保留http路由规则(此时Istio处理的是解密后的HTTP流量):
apiVersion: networking.istio.io/v1alpha3 kind: VirtualService metadata: name: your-vs-name spec: hosts: - 10.50.176.77 gateways: - your-gateway-name # 关联上面修改的Gateway http: - match: - uri: prefix: /login route: - destination: host: console-web port: number: 8099 - match: - uri: prefix: /auth route: - destination: host: console-auth port: number: 8098
步骤3:后端服务为HTTPS时配置重新加密
如果console-web和console-auth本身用HTTPS协议,需配置DestinationRule让Istio与后端通信时重新加密:
apiVersion: networking.istio.io/v1alpha3 kind: DestinationRule metadata: name: console-web-dr spec: host: console-web trafficPolicy: tls: mode: SIMPLE # 与后端用HTTPS通信 --- apiVersion: networking.istio.io/v1alpha3 kind: DestinationRule metadata: name: console-auth-dr spec: host: console-auth trafficPolicy: tls: mode: SIMPLE
配置完成后,客户端通过https://10.50.176.77/login或https://10.50.176.77/auth访问时,Istio会解密TLS流量,按URI路径路由到对应后端,且与后端保持HTTPS通信。
方案二:保持PASSTHROUGH模式(仅支持SNI路由,不支持路径)
如果业务必须让后端直接处理客户端TLS连接(比如需要客户端证书认证),只能基于SNI子域名路由,无法实现路径分流。示例配置如下:
apiVersion: networking.istio.io/v1alpha3 kind: VirtualService metadata: name: your-vs-name spec: hosts: - web.10.50.176.77 - auth.10.50.176.77 gateways: - your-passthrough-gateway tls: - match: - port: 15443 sniHosts: - web.10.50.176.77 route: - destination: host: console-web port: number: 8099 - match: - port: 15443 sniHosts: - auth.10.50.176.77 route: - destination: host: console-auth port: number: 8098
注意:该方案仅能按子域名分流,无法满足你基于URI路径路由的需求,因此优先选择方案一。
内容的提问来源于stack exchange,提问作者zxq
相关产品推荐
相关产品推荐

