如何将含sub_filter的Nginx配置迁移至Istio/Envoy暴露AWS VPC ES
Got it, let's walk through converting your Nginx setup to Istio step by step. Your core needs are routing traffic to Kibana/Cognito, fixing redirects, updating cookie domains, and replacing the internal ES domain in responses—all things we can replicate with Istio's VirtualService and EnvoyFilter.
Step 1: Expand Your VirtualService
First, let's flesh out your existing VirtualService to cover all the routes and proxy behaviors from your Nginx config:
apiVersion: networking.istio.io/v1alpha3 kind: VirtualService metadata: name: siem-route namespace: siem spec: hosts: - siem.jupiter.money gateways: - istio-system/http-gateway http: # Route for Kibana requests (matches Nginx's /_plugin/kibana location) - match: - uri: prefix: /_plugin/kibana route: - destination: host: vpc-mykibana-111xxx.us-east1.es.amazonaws.com port: number: 443 # Handle redirects (equivalent to Nginx's proxy_redirect) redirect: replaceAuthority: siem.jupiter.money # Mimic Nginx header and cookie settings headers: request: set: Accept-Encoding: "" # Disable encoding so content replacement works properly response: # Update cookie domain (matches proxy_cookie_domain) add: Set-Cookie: "$request_cookie; Domain=siem.jupiter.money; Path=/" # Route for Cognito-related paths - match: - uri: regex: /(log|sign|error|fav|forgot|change|confirm).* route: - destination: host: mydomain.auth.us-east-1.amazoncognito.com port: number: 443 # Rewrite redirects from Cognito/ES to your public domain redirect: replaceAuthority: siem.jupiter.money headers: response: # Update Cognito cookie domain add: Set-Cookie: "$request_cookie; Domain=siem.jupiter.money; Path=/"
The replaceAuthority setting takes care of rewriting any redirect URLs that point to the ES or Cognito domains to your public host siem.jupiter.money—just like your Nginx proxy_redirect rules.
Step 2: Replicate sub_filter with EnvoyFilter
Istio doesn't have a direct sub_filter equivalent in VirtualService, so we'll use an EnvoyFilter to inject Envoy's response transformation logic. This will swap all instances of the internal ES domain with your public domain in the response body:
Option 1: Lua Filter (Works with Most Istio/Envoy Versions)
apiVersion: networking.istio.io/v1alpha3 kind: EnvoyFilter metadata: name: kibana-subfilter namespace: siem spec: workloadSelector: labels: istio: ingressgateway # Target the Istio ingress gateway configPatches: - applyTo: HTTP_FILTER match: context: GATEWAY listener: portNumber: 443 filterChain: filter: name: "envoy.filters.network.http_connection_manager" subFilter: name: "envoy.filters.http.router" patch: operation: INSERT_BEFORE value: name: envoy.filters.http.lua typed_config: "@type": "type.googleapis.com/envoy.extensions.filters.http.lua.v3.Lua" inline_code: | function envoy_on_response(response_handle) local body = response_handle:body() local body_str = body:getBytes(0, body:length()) -- Replace the internal ES domain with your public host local modified_body = string.gsub(body_str, "vpc-mykibana-111xxx.us-east1.es.amazonaws.com", "siem.jupiter.money") body:setBytes(modified_body) response_handle:body(body) end
Option 2: Built-in Regex Replacement (Newer Envoy Versions)
If you're running a recent Istio version (1.13+), you can use Envoy's native regex replacement filter instead of Lua:
apiVersion: networking.istio.io/v1alpha3 kind: EnvoyFilter metadata: name: kibana-subfilter namespace: siem spec: workloadSelector: labels: istio: ingressgateway configPatches: - applyTo: HTTP_FILTER match: context: GATEWAY listener: portNumber: 443 filterChain: filter: name: "envoy.filters.network.http_connection_manager" subFilter: name: "envoy.filters.http.router" patch: operation: INSERT_BEFORE value: name: envoy.filters.http.response_transformer typed_config: "@type": "type.googleapis.com/envoy.extensions.filters.http.response_transformer.v3.ResponseTransformer" transformation: response_body_transform: regex_replace: pattern: google_re2: {} regex: "vpc-mykibana-111xxx.us-east1.es.amazonaws.com" substitution: "siem.jupiter.money" replace_all: true
Step 3: Ensure Your Gateway is HTTPS-Ready
Double-check that your Istio gateway is configured to serve HTTPS with a valid certificate for siem.jupiter.money:
apiVersion: networking.istio.io/v1alpha3 kind: Gateway metadata: name: http-gateway namespace: istio-system spec: selector: istio: ingressgateway servers: - port: number: 443 name: https protocol: HTTPS tls: mode: SIMPLE credentialName: siem-jupiter-money-tls # Name of your Kubernetes Secret with cert/key hosts: - siem.jupiter.money
Quick Validation Tips
- After applying all configs, access
https://siem.jupiter.money/_plugin/kibanaand check that redirects land on your public domain (not the ES VPC domain). - Use browser dev tools to inspect the response body—make sure there are no references to
vpc-mykibana-111xxx.us-east1.es.amazonaws.com. - Verify that cookies are set with the correct domain (
siem.jupiter.money).
内容的提问来源于stack exchange,提问作者rohit

