升级Istio 1.4.5至1.15.0后PgAdmin StatefulSet无法通过VS访问
Istio 1.15.0升级后Virtual Service访问pgadmin4报错的排查与解决
环境信息
- Kubernetes 1.22
- Istio版本:从1.4.5升级至1.15.0
问题现象
通过Istio Virtual Service访问pgadmin4时,浏览器返回错误:
upstream connect error or disconnect/reset before headers. reset reason: connection failure, transport failure reason: delayed connect error: 111
但使用kubectl port-forward直接连接pgadmin4服务时可正常访问。
排查与解决步骤
1. 校验Sidecar注入状态与版本一致性
跨大版本升级后,旧版Sidecar可能与新版本控制平面不兼容:
- 检查pgadmin4所在Namespace的自动注入开关:
若返回值不是kubectl get namespace <pgadmin-namespace> -o jsonpath='{.metadata.labels.istio-injection}'enabled,手动给Deployment注入Sidecar:kubectl patch deployment <pgadmin-deployment> -n <pgadmin-namespace> --patch '{"spec":{"template":{"metadata":{"annotations":{"sidecar.istio.io/inject": "true"}}}}}' - 验证Sidecar镜像版本是否与Istiod一致:
版本不一致时,滚动更新Deployment触发Sidecar重建。kubectl get pods -n <pgadmin-namespace> -o jsonpath='{.items[*].spec.containers[?(@.name=="istio-proxy")].image}'
2. 检查Virtual Service与DestinationRule配置
- 确认Virtual Service的目标服务、端口与pgadmin4的Service完全匹配,比如pgadmin4 Service端口为80,则Virtual Service的
route.destination.port.number需对应为80。 - 若pgadmin4未启用TLS,需在DestinationRule中禁用自动TLS:
Istio 1.10+默认开启服务间自动TLS,后端不支持会直接导致连接失败。apiVersion: networking.istio.io/v1alpha3 kind: DestinationRule metadata: name: pgadmin-dr namespace: <pgadmin-namespace> spec: host: pgadmin-service.<pgadmin-namespace>.svc.cluster.local trafficPolicy: tls: mode: DISABLE
3. 确认pgadmin4监听地址
确保pgadmin4监听0.0.0.0而非127.0.0.1,否则Sidecar无法建立连接:
- 查看Deployment的环境变量或启动命令,确认
PGADMIN_LISTEN_ADDRESS这类配置值为0.0.0.0。 - 配置错误时,修改Deployment并重启Pod。
4. 检查Istio出站流量策略
Istio 1.4到1.15默认出站策略从ALLOW_ANY改为REGISTRY_ONLY:
- 查看全局出站策略:
若为kubectl get configmap istio -n istio-system -o jsonpath='{.data.mesh}' | grep outboundTrafficPolicy.modeREGISTRY_ONLY,需确认pgadmin4的Service已在Istio服务注册表中,或临时改为ALLOW_ANY测试是否恢复。
5. 查看Sidecar日志定位细节
获取pgadmin4 Pod中istio-proxy容器的日志,排查连接失败的具体原因:
kubectl logs <pgadmin-pod-name> -n <pgadmin-namespace> -c istio-proxy
日志会包含目标服务IP、端口、超时等信息,帮助进一步定位问题。
内容的提问来源于stack exchange,提问作者mati kepa
相关产品推荐
相关产品推荐

