You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AKS集群与Istio配置SSL后应用无法访问的问题排查

HTTPS访问Istio配置的httpbin应用失败排查步骤

1. 验证Gateway与Secret的一致性

  • 命名空间匹配检查:你创建的TLS Secret httpbin-credential 在 istio-system 命名空间,但Gateway配置未指定命名空间(默认部署到default)。Istio Gateway的credentialName仅能引用同一命名空间的Secret,需调整:
    • 要么在Gateway YAML中添加metadata.namespace: istio-system,将Gateway部署到istio-system
    • 要么将Secret复制到default命名空间:
      kubectl get secret httpbin-credential -n istio-system -o yaml | sed 's/namespace: istio-system/namespace: default/' | kubectl apply -f -
      
  • Secret有效性检查:执行以下命令确认Secret格式正确:
    kubectl get secret httpbin-credential -n istio-system -o yaml
    
    需确保type为kubernetes.io/tls,且data字段包含tls.crt和tls.key。
  • Gateway Selector匹配:你安装的Istio Ingress Gateway在istio-ingress命名空间,需确认Gateway的selector与Ingress Gateway Pod的标签一致:
    1. 查看Ingress Gateway Pod的标签:
      kubectl get pods -n istio-ingress --show-labels
      
    2. 若标签为istio: ingressgateway(默认值),需修改Gateway的spec.selector为istio: ingressgateway。

2. 确认Ingress Gateway网络可达性

  • Service外部IP检查:确认Ingress Gateway的LoadBalancer已分配外部IP:
    kubectl get svc istio-ingress -n istio-ingress
    
    确保EXTERNAL-IP字段已赋值,且hosts文件中httpbin.example.com映射的是该IP。
  • 端口入站规则检查:检查AKS集群所在子网的网络安全组(NSG)是否允许443端口的入站流量,目标为Ingress Gateway所在节点的IP范围。
  • 直接连通性测试:用curl直接测试IP连通性,排除DNS解析问题:
    curl -v https://httpbin.example.com --resolve httpbin.example.com:443:<EXTERNAL-IP>
    
    若为自签名证书,需添加-k参数忽略证书验证:
    curl -vk https://httpbin.example.com --resolve httpbin.example.com:443:<EXTERNAL-IP>
    

3. 验证Istio配置与Sidecar注入

  • Sidecar注入检查:确认httpbin Pod已注入Istio Sidecar:
    kubectl get pods -l app=httpbin -o jsonpath='{.items[0].spec.containers[*].name}'
    
    输出需包含istio-proxy容器,若未包含,需重启Pod:
    kubectl rollout restart deployment httpbin
    
  • VirtualService配置验证:确认VirtualService正确关联Gateway和后端服务:
    kubectl get virtualservice httpbin -o yaml
    
    需确保:
    • hosts包含httpbin.example.com
    • gateways引用的mygateway存在且命名空间匹配
    • route.destination.port.number为8000(与httpbin Service的端口一致)
  • 组件日志排查:
    • 查看Istiod日志,确认配置加载无错误:
      kubectl logs -n istio-system -l app=istiod
      
    • 查看Ingress Gateway日志,排查SSL握手或路由匹配问题:
      kubectl logs -n istio-ingress -l istio=ingressgateway
      

4. 证书有效性验证

  • 证书CN匹配检查:确认证书的通用名称(CN)与httpbin.example.com一致:
    openssl x509 -in example_certs1/httpbin.example.com.crt -text -noout | grep "Subject:"
    
  • 证书信任问题:若使用自签名证书,客户端(浏览器/curl)需信任该证书,否则会出现SSL验证错误。

内容的提问来源于stack exchange,提问作者One Developer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 17:10:36