You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AKS集群中Istio Gateway无法访问问题求助

排查AKS集群中Istio Gateway无法访问的问题

环境配置

AKS集群Terraform代码

resource "azurerm_virtual_network" "test" {
  name                = var.virtual_network_name
  location            = azurerm_resource_group.rg.location
  resource_group_name = azurerm_resource_group.rg.name
  address_space       = [var.virtual_network_address_prefix]

  subnet {
    name           = var.aks_subnet_name
    address_prefix = var.aks_subnet_address_prefix
  }

  subnet {
    name           = "appgwsubnet"
    address_prefix = var.app_gateway_subnet_address_prefix
  }

  tags = var.tags
}

data "azurerm_subnet" "kubesubnet" {
  name                 = var.aks_subnet_name
  virtual_network_name = azurerm_virtual_network.test.name
  resource_group_name  = azurerm_resource_group.rg.name
  depends_on           = [azurerm_virtual_network.test]
}

resource "azurerm_kubernetes_cluster" "k8s" {
  name       = var.aks_name
  location   = azurerm_resource_group.rg.location
  dns_prefix = var.aks_dns_prefix

  resource_group_name = azurerm_resource_group.rg.name

  http_application_routing_enabled = false

  linux_profile {
    admin_username = var.vm_user_name

    ssh_key {
      key_data = file(var.public_ssh_key_path)
    }
  }

  default_node_pool {
    name            = "agentpool"
    node_count      = var.aks_agent_count
    vm_size         = var.aks_agent_vm_size
    os_disk_size_gb = var.aks_agent_os_disk_size
    vnet_subnet_id  = data.azurerm_subnet.kubesubnet.id
  }

  service_principal {
    client_id     = local.client_id
    client_secret = local.client_secret
  }

  network_profile {
    network_plugin     = "azure"
    dns_service_ip     = var.aks_dns_service_ip
    docker_bridge_cidr = var.aks_docker_bridge_cidr
    service_cidr       = var.aks_service_cidr
  }

  # Enabled the cluster configuration to the Azure kubernets with RBAC
  azure_active_directory_role_based_access_control { 
    managed                     = var.azure_active_directory_role_based_access_control_managed
    admin_group_object_ids      = var.active_directory_role_based_access_control_admin_group_object_ids
    azure_rbac_enabled          = var.azure_rbac_enabled
  }

  oms_agent {
    log_analytics_workspace_id  = module.log_analytics_workspace[0].id
  }

  timeouts {
    create = "20m"
    delete = "20m"
  }  

  depends_on = [data.azurerm_subnet.kubesubnet,module.log_analytics_workspace]
  tags       = var.tags
}

resource "azurerm_role_assignment" "ra1" {
  scope                = data.azurerm_subnet.kubesubnet.id
  role_definition_name = "Network Contributor"
  principal_id         = local.client_objectid
  depends_on = [data.azurerm_subnet.kubesubnet]
}

Istio安装步骤

#Prerequisites
helm repo add istio https://istio-release.storage.googleapis.com/charts
helm repo update

#create namespace
kubectl create namespace istio-system

# helm install istio-base and istiod
helm install istio-base istio/base -n istio-system
helm install istiod istio/istiod -n istio-system --wait

# Check the installation status
helm status istiod -n istio-system

#create namespace and enable istio-injection for envoy proxy containers
kubectl create namespace istio-ingress
kubectl label namespace istio-ingress istio-injection=enabled

## helm install istio-ingress for traffic management
helm install istio-ingress istio/gateway -n istio-ingress --wait

## Mark the default namespace as istio-injection=enabled
kubectl label namespace default istio-injection=enabled

## Install the App and Gateway
kubectl apply -f https://raw.githubusercontent.com/istio/istio/release-1.16/samples/bookinfo/platform/kube/bookinfo.yaml
kubectl apply -f https://raw.githubusercontent.com/istio/istio/release-1.16/samples/bookinfo/networking/bookinfo-gateway.yaml

# Check the Services, Pods and Gateway
kubectl get services
kubectl get pods
kubectl get gateway

# Ensure the app is running
kubectl exec "$(kubectl get pod -l app=ratings -o jsonpath='{.items[0].metadata.name}')" -c ratings -- curl -sS productpage:9080/productpage | grep -o "<title>.*</title>"

问题现象

  1. 集群内部测试应用运行正常,可通过内部域名访问Bookinfo的productpage
  2. 已获取到Istio-ingress服务的外部IP,但无法通过该IP访问应用
  3. 执行以下端口查询命令时无输出/报错:
kubectl -n "$INGRESS_NS" get service "$INGRESS_NAME" -o jsonpath='{.spec.ports[?(@.name=="http2")].port}'
kubectl -n "$INGRESS_NS" get service "$INGRESS_NAME" -o jsonpath='{.spec.ports[?(@.name=="https")].port}'
kubectl -n "$INGRESS_NS" get service "$INGRESS_NAME" -o jsonpath='{.spec.ports[?(@.name=="tcp")].port}'

排查步骤建议

1. 确认Ingress Gateway服务的基本配置

先明确Ingress服务的名称和命名空间,执行以下命令查看完整的服务信息:

kubectl get svc -n istio-ingress

检查输出中的NAME(通常为istio-ingress)、TYPE(应为LoadBalancer)、EXTERNAL-IP是否已分配,以及PORT(S)列的端口配置。

2. 验证Gateway资源配置

检查Bookinfo Gateway的规则是否正确:

kubectl get gateway bookinfo-gateway -o yaml

确认spec.servers中是否包含正确的端口(如80)、hosts配置(是否为*或预期域名),以及对应的tls配置(未启用HTTPS时应为空)。

3. 检查Istio Ingress Pod状态

确认Ingress Gateway的Pod是否正常运行,且Envoy代理已正确注入:

kubectl get pods -n istio-ingress
kubectl describe pod <ingress-pod-name> -n istio-ingress

查看Pod的事件日志,确认是否有启动失败、网络配置错误等问题。

4. 验证端口查询命令的变量正确性

之前的端口查询命令依赖INGRESS_NS和INGRESS_NAME变量,先确认变量是否正确设置:

export INGRESS_NS=istio-ingress
export INGRESS_NAME=istio-ingress
# 再执行端口查询
kubectl -n "$INGRESS_NS" get service "$INGRESS_NAME" -o jsonpath='{.spec.ports[?(@.name=="http2")].port}'

如果服务的端口名称不是http2,可通过kubectl get svc $INGRESS_NAME -n $INGRESS_NS -o yaml查看实际的端口名称。

5. 检查AKS网络策略与安全组

  • 确认AKS节点的NSG(网络安全组)是否允许外部访问Ingress Gateway的端口(默认是80/443)
  • 检查集群是否启用了网络策略,是否有策略阻止了外部流量到Ingress服务
  • 确认虚拟网络中的路由表是否配置正确,无流量阻断规则

6. 测试Envoy代理的内部访问

在Ingress Pod中直接测试是否能访问后端服务:

kubectl exec -it <ingress-pod-name> -n istio-ingress -- curl http://productpage.default.svc.cluster.local:9080/productpage

如果能访问,说明后端服务正常,问题出在外部流量到Ingress的路径;如果不能访问,检查Istio的Sidecar注入和服务发现配置。

7. 查看Istio日志

查看Istiod和Ingress Gateway的日志,排查配置同步或流量转发错误:

# 查看Istiod日志
kubectl logs -n istio-system -l app=istiod
# 查看Ingress Gateway日志
kubectl logs -n istio-ingress -l app=istio-ingress

内容的提问来源于stack exchange,提问作者One Developer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 00:20:31