You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Istio多版本残留清理及升级至1.14.1技术咨询

Istio环境清理与升级问题

环境背景

两年前在K8s v1.22.13集群中安装了Istio,现无法确认初始安装方式(Operator或istioctl),当前环境信息如下:

版本信息

./bin/istioctl version
client version: 1.11.3
control plane version: 1.11.3
data plane version: 1.11.3 (352 proxies)

Istio相关命名空间

kubectl get ns | grep istio
istio-operator        Active   726d
istio-system          Active   726d

GitOps中的IstioOperator配置

apiVersion: install.istio.io/v1alpha1
kind: IstioOperator
metadata:
  name: istiocontrolplane
  namespace: istio-system
spec:
  profile: default
  meshConfig:
    accessLogFile: /dev/stdout
    extensionProviders:
      - name: xxxx
        envoyExtAuthzHttp:
          service: oauth2-proxy-xxxx.keycloak.svc.cluster.local
          port: 4180
          includeHeadersInCheck:
            - authorization
            - cookie
          headersToUpstreamOnAllow:
            - authorization
            - path
            - cookie
            - x-auth-request-access-token
            - x-auth-request-user
            - x-auth-request-email
          headersToDownstreamOnDeny:
            - content-type
            - set-cookie
  components:
    ingressGateways:
      - name: istio-ingressgateway
        k8s:
          hpaSpec:
            minReplicas: 2
          service:
            type: NodePort
            ports:
              - name: http2
                nodePort: 32080
                port: 80
                protocol: TCP
                targetPort: 8080
              - name: https
                nodePort: 32443
                port: 443
                protocol: TCP
                targetPort: 8443
    pilot:
      k8s:
        hpaSpec:
          minReplicas: 2

istio-operator命名空间资源(省略ReplicaSet和Service)

k -n istio-operator get all
NAME                                         READY   STATUS    RESTARTS       AGE
pod/istio-operator-1-12-5-65c9f7bf96-qcdsc   1/1     Running   0              15m
pod/istio-operator-1-14-1-9874cfdcb-bwtwg    1/1     Running   3 (51d ago)    83d
pod/istio-operator-58dc7d74f5-pbkcs          1/1     Running   48 (48d ago)   83d

NAME                                    READY   UP-TO-DATE   AVAILABLE   AGE
deployment.apps/istio-operator          1/1     1            1           726d
deployment.apps/istio-operator-1-12-5   1/1     1            1           15m
deployment.apps/istio-operator-1-14-1   1/1     1            1           146d

istio-system命名空间Deployment

NAME                   READY   UP-TO-DATE   AVAILABLE   AGE    CONTAINERS    IMAGES                           SELECTOR
istio-ingressgateway   2/2     2            2           726d   istio-proxy   docker.io/istio/proxyv2:1.11.3   app=istio-ingressgateway,istio=ingressgateway
istiod                 2/2     2            2           726d   discovery 

当前需求:清理混乱环境并升级至Istio 1.14.1,同时使用自定义EnvoyFilter实现OAuth2认证和Lua重定向功能。


问题解答

1. 初始安装方式判断

  • 初始为Operator方式安装:存在istio-operator命名空间及运行的operator Pod,同时GitOps中保留了IstioOperator配置文件,这是Operator安装的核心标识。
  • 存在混合操作痕迹:当前控制平面版本为1.11.3,但istio-operator命名空间中存在1.12.5、1.14.1版本的operator Deployment,推测后续尝试过用不同版本operator升级但未完成,导致环境混乱。

2. 清理并移除旧版本步骤

步骤1:备份关键资源

  • 备份Istio核心资源:
kubectl get all -n istio-system -o yaml > istio-system-backup.yaml
kubectl get all -n istio-operator -o yaml > istio-operator-backup.yaml
kubectl get IstioOperator -n istio-system -o yaml > istio-operator-config-backup.yaml
  • 备份自定义EnvoyFilter资源:
kubectl get EnvoyFilter -A -o yaml > envoyfilter-backup.yaml

步骤2:卸载当前Istio控制平面

使用对应版本(1.11.3)的istioctl彻底卸载:

./bin/istioctl uninstall --purge -y

说明:--purge参数会清理所有Istio相关CRD、空命名空间及残留资源。

步骤3:清理残留的operator资源

手动删除旧版本operator Deployment:

kubectl delete deployment -n istio-operator istio-operator istio-operator-1-12-5 istio-operator-1-14-1

若命名空间残留无效资源,可删除后重建:

kubectl delete ns istio-operator
kubectl create ns istio-operator

步骤4:验证清理结果

检查Istio相关资源是否清理完毕:

kubectl get crd | grep istio.io
kubectl get ns | grep istio
kubectl get pods -n istio-system

3. 环境清理建议

  • 确认备份完整性:确保自定义配置(EnvoyFilter、IstioOperator配置)已完整备份,避免清理后丢失核心功能。
  • 分阶段清理:先卸载控制平面,再清理operator资源,最后检查CRD和残留资源,避免遗漏。
  • 清理sidecar注入痕迹:为曾注入sidecar的命名空间移除注入标签,防止后续误操作:
kubectl label ns <目标命名空间> istio-injection-
  • 更新本地客户端:删除旧版本istioctl,后续统一使用1.14.1版本客户端操作。
  • 确认版本兼容性:Istio 1.14.1支持K8s 1.20-1.23,与当前K8s v1.22.13兼容,可放心升级。
  • 统一安装方式:升级时选择Operator结合GitOps的方式,避免混合使用istioctl与Operator导致环境再次混乱。

内容的提问来源于stack exchange,提问作者jen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 20:55:28