AKS集群中Istio Gateway无法访问问题求助
排查AKS集群中Istio Gateway无法访问的问题
环境配置
AKS集群Terraform代码
resource "azurerm_virtual_network" "test" { name = var.virtual_network_name location = azurerm_resource_group.rg.location resource_group_name = azurerm_resource_group.rg.name address_space = [var.virtual_network_address_prefix] subnet { name = var.aks_subnet_name address_prefix = var.aks_subnet_address_prefix } subnet { name = "appgwsubnet" address_prefix = var.app_gateway_subnet_address_prefix } tags = var.tags } data "azurerm_subnet" "kubesubnet" { name = var.aks_subnet_name virtual_network_name = azurerm_virtual_network.test.name resource_group_name = azurerm_resource_group.rg.name depends_on = [azurerm_virtual_network.test] } resource "azurerm_kubernetes_cluster" "k8s" { name = var.aks_name location = azurerm_resource_group.rg.location dns_prefix = var.aks_dns_prefix resource_group_name = azurerm_resource_group.rg.name http_application_routing_enabled = false linux_profile { admin_username = var.vm_user_name ssh_key { key_data = file(var.public_ssh_key_path) } } default_node_pool { name = "agentpool" node_count = var.aks_agent_count vm_size = var.aks_agent_vm_size os_disk_size_gb = var.aks_agent_os_disk_size vnet_subnet_id = data.azurerm_subnet.kubesubnet.id } service_principal { client_id = local.client_id client_secret = local.client_secret } network_profile { network_plugin = "azure" dns_service_ip = var.aks_dns_service_ip docker_bridge_cidr = var.aks_docker_bridge_cidr service_cidr = var.aks_service_cidr } # Enabled the cluster configuration to the Azure kubernets with RBAC azure_active_directory_role_based_access_control { managed = var.azure_active_directory_role_based_access_control_managed admin_group_object_ids = var.active_directory_role_based_access_control_admin_group_object_ids azure_rbac_enabled = var.azure_rbac_enabled } oms_agent { log_analytics_workspace_id = module.log_analytics_workspace[0].id } timeouts { create = "20m" delete = "20m" } depends_on = [data.azurerm_subnet.kubesubnet,module.log_analytics_workspace] tags = var.tags } resource "azurerm_role_assignment" "ra1" { scope = data.azurerm_subnet.kubesubnet.id role_definition_name = "Network Contributor" principal_id = local.client_objectid depends_on = [data.azurerm_subnet.kubesubnet] }
Istio安装步骤
#Prerequisites helm repo add istio https://istio-release.storage.googleapis.com/charts helm repo update #create namespace kubectl create namespace istio-system # helm install istio-base and istiod helm install istio-base istio/base -n istio-system helm install istiod istio/istiod -n istio-system --wait # Check the installation status helm status istiod -n istio-system #create namespace and enable istio-injection for envoy proxy containers kubectl create namespace istio-ingress kubectl label namespace istio-ingress istio-injection=enabled ## helm install istio-ingress for traffic management helm install istio-ingress istio/gateway -n istio-ingress --wait ## Mark the default namespace as istio-injection=enabled kubectl label namespace default istio-injection=enabled ## Install the App and Gateway kubectl apply -f https://raw.githubusercontent.com/istio/istio/release-1.16/samples/bookinfo/platform/kube/bookinfo.yaml kubectl apply -f https://raw.githubusercontent.com/istio/istio/release-1.16/samples/bookinfo/networking/bookinfo-gateway.yaml # Check the Services, Pods and Gateway kubectl get services kubectl get pods kubectl get gateway # Ensure the app is running kubectl exec "$(kubectl get pod -l app=ratings -o jsonpath='{.items[0].metadata.name}')" -c ratings -- curl -sS productpage:9080/productpage | grep -o "<title>.*</title>"
问题现象
- 集群内部测试应用运行正常,可通过内部域名访问Bookinfo的productpage
- 已获取到Istio-ingress服务的外部IP,但无法通过该IP访问应用
- 执行以下端口查询命令时无输出/报错:
kubectl -n "$INGRESS_NS" get service "$INGRESS_NAME" -o jsonpath='{.spec.ports[?(@.name=="http2")].port}' kubectl -n "$INGRESS_NS" get service "$INGRESS_NAME" -o jsonpath='{.spec.ports[?(@.name=="https")].port}' kubectl -n "$INGRESS_NS" get service "$INGRESS_NAME" -o jsonpath='{.spec.ports[?(@.name=="tcp")].port}'
排查步骤建议
1. 确认Ingress Gateway服务的基本配置
先明确Ingress服务的名称和命名空间,执行以下命令查看完整的服务信息:
kubectl get svc -n istio-ingress
检查输出中的NAME(通常为istio-ingress)、TYPE(应为LoadBalancer)、EXTERNAL-IP是否已分配,以及PORT(S)列的端口配置。
2. 验证Gateway资源配置
检查Bookinfo Gateway的规则是否正确:
kubectl get gateway bookinfo-gateway -o yaml
确认spec.servers中是否包含正确的端口(如80)、hosts配置(是否为*或预期域名),以及对应的tls配置(未启用HTTPS时应为空)。
3. 检查Istio Ingress Pod状态
确认Ingress Gateway的Pod是否正常运行,且Envoy代理已正确注入:
kubectl get pods -n istio-ingress kubectl describe pod <ingress-pod-name> -n istio-ingress
查看Pod的事件日志,确认是否有启动失败、网络配置错误等问题。
4. 验证端口查询命令的变量正确性
之前的端口查询命令依赖INGRESS_NS和INGRESS_NAME变量,先确认变量是否正确设置:
export INGRESS_NS=istio-ingress export INGRESS_NAME=istio-ingress # 再执行端口查询 kubectl -n "$INGRESS_NS" get service "$INGRESS_NAME" -o jsonpath='{.spec.ports[?(@.name=="http2")].port}'
如果服务的端口名称不是http2,可通过kubectl get svc $INGRESS_NAME -n $INGRESS_NS -o yaml查看实际的端口名称。
5. 检查AKS网络策略与安全组
- 确认AKS节点的NSG(网络安全组)是否允许外部访问Ingress Gateway的端口(默认是80/443)
- 检查集群是否启用了网络策略,是否有策略阻止了外部流量到Ingress服务
- 确认虚拟网络中的路由表是否配置正确,无流量阻断规则
6. 测试Envoy代理的内部访问
在Ingress Pod中直接测试是否能访问后端服务:
kubectl exec -it <ingress-pod-name> -n istio-ingress -- curl http://productpage.default.svc.cluster.local:9080/productpage
如果能访问,说明后端服务正常,问题出在外部流量到Ingress的路径;如果不能访问,检查Istio的Sidecar注入和服务发现配置。
7. 查看Istio日志
查看Istiod和Ingress Gateway的日志,排查配置同步或流量转发错误:
# 查看Istiod日志 kubectl logs -n istio-system -l app=istiod # 查看Ingress Gateway日志 kubectl logs -n istio-ingress -l app=istio-ingress
内容的提问来源于stack exchange,提问作者One Developer
相关产品推荐
相关产品推荐

