Istio多版本残留清理及升级至1.14.1技术咨询
Istio环境清理与升级问题
环境背景
两年前在K8s v1.22.13集群中安装了Istio,现无法确认初始安装方式(Operator或istioctl),当前环境信息如下:
版本信息
./bin/istioctl version client version: 1.11.3 control plane version: 1.11.3 data plane version: 1.11.3 (352 proxies)
Istio相关命名空间
kubectl get ns | grep istio istio-operator Active 726d istio-system Active 726d
GitOps中的IstioOperator配置
apiVersion: install.istio.io/v1alpha1 kind: IstioOperator metadata: name: istiocontrolplane namespace: istio-system spec: profile: default meshConfig: accessLogFile: /dev/stdout extensionProviders: - name: xxxx envoyExtAuthzHttp: service: oauth2-proxy-xxxx.keycloak.svc.cluster.local port: 4180 includeHeadersInCheck: - authorization - cookie headersToUpstreamOnAllow: - authorization - path - cookie - x-auth-request-access-token - x-auth-request-user - x-auth-request-email headersToDownstreamOnDeny: - content-type - set-cookie components: ingressGateways: - name: istio-ingressgateway k8s: hpaSpec: minReplicas: 2 service: type: NodePort ports: - name: http2 nodePort: 32080 port: 80 protocol: TCP targetPort: 8080 - name: https nodePort: 32443 port: 443 protocol: TCP targetPort: 8443 pilot: k8s: hpaSpec: minReplicas: 2
istio-operator命名空间资源(省略ReplicaSet和Service)
k -n istio-operator get all NAME READY STATUS RESTARTS AGE pod/istio-operator-1-12-5-65c9f7bf96-qcdsc 1/1 Running 0 15m pod/istio-operator-1-14-1-9874cfdcb-bwtwg 1/1 Running 3 (51d ago) 83d pod/istio-operator-58dc7d74f5-pbkcs 1/1 Running 48 (48d ago) 83d NAME READY UP-TO-DATE AVAILABLE AGE deployment.apps/istio-operator 1/1 1 1 726d deployment.apps/istio-operator-1-12-5 1/1 1 1 15m deployment.apps/istio-operator-1-14-1 1/1 1 1 146d
istio-system命名空间Deployment
NAME READY UP-TO-DATE AVAILABLE AGE CONTAINERS IMAGES SELECTOR istio-ingressgateway 2/2 2 2 726d istio-proxy docker.io/istio/proxyv2:1.11.3 app=istio-ingressgateway,istio=ingressgateway istiod 2/2 2 2 726d discovery
当前需求:清理混乱环境并升级至Istio 1.14.1,同时使用自定义EnvoyFilter实现OAuth2认证和Lua重定向功能。
问题解答
1. 初始安装方式判断
- 初始为Operator方式安装:存在
istio-operator命名空间及运行的operator Pod,同时GitOps中保留了IstioOperator配置文件,这是Operator安装的核心标识。 - 存在混合操作痕迹:当前控制平面版本为1.11.3,但istio-operator命名空间中存在1.12.5、1.14.1版本的operator Deployment,推测后续尝试过用不同版本operator升级但未完成,导致环境混乱。
2. 清理并移除旧版本步骤
步骤1:备份关键资源
- 备份Istio核心资源:
kubectl get all -n istio-system -o yaml > istio-system-backup.yaml kubectl get all -n istio-operator -o yaml > istio-operator-backup.yaml kubectl get IstioOperator -n istio-system -o yaml > istio-operator-config-backup.yaml
- 备份自定义EnvoyFilter资源:
kubectl get EnvoyFilter -A -o yaml > envoyfilter-backup.yaml
步骤2:卸载当前Istio控制平面
使用对应版本(1.11.3)的istioctl彻底卸载:
./bin/istioctl uninstall --purge -y
说明:
--purge参数会清理所有Istio相关CRD、空命名空间及残留资源。
步骤3:清理残留的operator资源
手动删除旧版本operator Deployment:
kubectl delete deployment -n istio-operator istio-operator istio-operator-1-12-5 istio-operator-1-14-1
若命名空间残留无效资源,可删除后重建:
kubectl delete ns istio-operator kubectl create ns istio-operator
步骤4:验证清理结果
检查Istio相关资源是否清理完毕:
kubectl get crd | grep istio.io kubectl get ns | grep istio kubectl get pods -n istio-system
3. 环境清理建议
- 确认备份完整性:确保自定义配置(EnvoyFilter、IstioOperator配置)已完整备份,避免清理后丢失核心功能。
- 分阶段清理:先卸载控制平面,再清理operator资源,最后检查CRD和残留资源,避免遗漏。
- 清理sidecar注入痕迹:为曾注入sidecar的命名空间移除注入标签,防止后续误操作:
kubectl label ns <目标命名空间> istio-injection-
- 更新本地客户端:删除旧版本istioctl,后续统一使用1.14.1版本客户端操作。
- 确认版本兼容性:Istio 1.14.1支持K8s 1.20-1.23,与当前K8s v1.22.13兼容,可放心升级。
- 统一安装方式:升级时选择Operator结合GitOps的方式,避免混合使用istioctl与Operator导致环境再次混乱。
内容的提问来源于stack exchange,提问作者jen
相关产品推荐
相关产品推荐

