AKS集群与Istio配置SSL后应用无法访问的问题排查
HTTPS访问Istio配置的httpbin应用失败排查步骤
1. 验证Gateway与Secret的一致性
- 命名空间匹配检查:你创建的TLS Secret
httpbin-credential在istio-system命名空间,但Gateway配置未指定命名空间(默认部署到default)。Istio Gateway的credentialName仅能引用同一命名空间的Secret,需调整:- 要么在Gateway YAML中添加
metadata.namespace: istio-system,将Gateway部署到istio-system - 要么将Secret复制到
default命名空间:kubectl get secret httpbin-credential -n istio-system -o yaml | sed 's/namespace: istio-system/namespace: default/' | kubectl apply -f -
- 要么在Gateway YAML中添加
- Secret有效性检查:执行以下命令确认Secret格式正确:
需确保kubectl get secret httpbin-credential -n istio-system -o yamltype为kubernetes.io/tls,且data字段包含tls.crt和tls.key。 - Gateway Selector匹配:你安装的Istio Ingress Gateway在
istio-ingress命名空间,需确认Gateway的selector与Ingress Gateway Pod的标签一致:- 查看Ingress Gateway Pod的标签:
kubectl get pods -n istio-ingress --show-labels - 若标签为
istio: ingressgateway(默认值),需修改Gateway的spec.selector为istio: ingressgateway。
- 查看Ingress Gateway Pod的标签:
2. 确认Ingress Gateway网络可达性
- Service外部IP检查:确认Ingress Gateway的LoadBalancer已分配外部IP:
确保kubectl get svc istio-ingress -n istio-ingressEXTERNAL-IP字段已赋值,且hosts文件中httpbin.example.com映射的是该IP。 - 端口入站规则检查:检查AKS集群所在子网的网络安全组(NSG)是否允许443端口的入站流量,目标为Ingress Gateway所在节点的IP范围。
- 直接连通性测试:用curl直接测试IP连通性,排除DNS解析问题:
若为自签名证书,需添加curl -v https://httpbin.example.com --resolve httpbin.example.com:443:<EXTERNAL-IP>-k参数忽略证书验证:curl -vk https://httpbin.example.com --resolve httpbin.example.com:443:<EXTERNAL-IP>
3. 验证Istio配置与Sidecar注入
- Sidecar注入检查:确认httpbin Pod已注入Istio Sidecar:
输出需包含kubectl get pods -l app=httpbin -o jsonpath='{.items[0].spec.containers[*].name}'istio-proxy容器,若未包含,需重启Pod:kubectl rollout restart deployment httpbin - VirtualService配置验证:确认VirtualService正确关联Gateway和后端服务:
需确保:kubectl get virtualservice httpbin -o yamlhosts包含httpbin.example.comgateways引用的mygateway存在且命名空间匹配route.destination.port.number为8000(与httpbin Service的端口一致)
- 组件日志排查:
- 查看Istiod日志,确认配置加载无错误:
kubectl logs -n istio-system -l app=istiod - 查看Ingress Gateway日志,排查SSL握手或路由匹配问题:
kubectl logs -n istio-ingress -l istio=ingressgateway
- 查看Istiod日志,确认配置加载无错误:
4. 证书有效性验证
- 证书CN匹配检查:确认证书的通用名称(CN)与
httpbin.example.com一致:openssl x509 -in example_certs1/httpbin.example.com.crt -text -noout | grep "Subject:" - 证书信任问题:若使用自签名证书,客户端(浏览器/curl)需信任该证书,否则会出现SSL验证错误。
内容的提问来源于stack exchange,提问作者One Developer
相关产品推荐
相关产品推荐

