You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将含sub_filter的Nginx配置迁移至Istio/Envoy暴露AWS VPC ES

Migrate Nginx Cognito-Protected Kibana Proxy to Istio

Got it, let's walk through converting your Nginx setup to Istio step by step. Your core needs are routing traffic to Kibana/Cognito, fixing redirects, updating cookie domains, and replacing the internal ES domain in responses—all things we can replicate with Istio's VirtualService and EnvoyFilter.

Step 1: Expand Your VirtualService

First, let's flesh out your existing VirtualService to cover all the routes and proxy behaviors from your Nginx config:

apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: siem-route
  namespace: siem
spec:
  hosts:
    - siem.jupiter.money
  gateways:
    - istio-system/http-gateway
  http:
    # Route for Kibana requests (matches Nginx's /_plugin/kibana location)
    - match:
        - uri:
            prefix: /_plugin/kibana
      route:
        - destination:
            host: vpc-mykibana-111xxx.us-east1.es.amazonaws.com
            port:
              number: 443
      # Handle redirects (equivalent to Nginx's proxy_redirect)
      redirect:
        replaceAuthority: siem.jupiter.money
      # Mimic Nginx header and cookie settings
      headers:
        request:
          set:
            Accept-Encoding: "" # Disable encoding so content replacement works properly
        response:
          # Update cookie domain (matches proxy_cookie_domain)
          add:
            Set-Cookie: "$request_cookie; Domain=siem.jupiter.money; Path=/"
    # Route for Cognito-related paths
    - match:
        - uri:
            regex: /(log|sign|error|fav|forgot|change|confirm).*
      route:
        - destination:
            host: mydomain.auth.us-east-1.amazoncognito.com
            port:
              number: 443
      # Rewrite redirects from Cognito/ES to your public domain
      redirect:
        replaceAuthority: siem.jupiter.money
      headers:
        response:
          # Update Cognito cookie domain
          add:
            Set-Cookie: "$request_cookie; Domain=siem.jupiter.money; Path=/"

The replaceAuthority setting takes care of rewriting any redirect URLs that point to the ES or Cognito domains to your public host siem.jupiter.money—just like your Nginx proxy_redirect rules.

Step 2: Replicate sub_filter with EnvoyFilter

Istio doesn't have a direct sub_filter equivalent in VirtualService, so we'll use an EnvoyFilter to inject Envoy's response transformation logic. This will swap all instances of the internal ES domain with your public domain in the response body:

Option 1: Lua Filter (Works with Most Istio/Envoy Versions)

apiVersion: networking.istio.io/v1alpha3
kind: EnvoyFilter
metadata:
  name: kibana-subfilter
  namespace: siem
spec:
  workloadSelector:
    labels:
      istio: ingressgateway # Target the Istio ingress gateway
  configPatches:
    - applyTo: HTTP_FILTER
      match:
        context: GATEWAY
        listener:
          portNumber: 443
          filterChain:
            filter:
              name: "envoy.filters.network.http_connection_manager"
              subFilter:
                name: "envoy.filters.http.router"
      patch:
        operation: INSERT_BEFORE
        value:
          name: envoy.filters.http.lua
          typed_config:
            "@type": "type.googleapis.com/envoy.extensions.filters.http.lua.v3.Lua"
            inline_code: |
              function envoy_on_response(response_handle)
                local body = response_handle:body()
                local body_str = body:getBytes(0, body:length())
                -- Replace the internal ES domain with your public host
                local modified_body = string.gsub(body_str, "vpc-mykibana-111xxx.us-east1.es.amazonaws.com", "siem.jupiter.money")
                body:setBytes(modified_body)
                response_handle:body(body)
              end

Option 2: Built-in Regex Replacement (Newer Envoy Versions)

If you're running a recent Istio version (1.13+), you can use Envoy's native regex replacement filter instead of Lua:

apiVersion: networking.istio.io/v1alpha3
kind: EnvoyFilter
metadata:
  name: kibana-subfilter
  namespace: siem
spec:
  workloadSelector:
    labels:
      istio: ingressgateway
  configPatches:
    - applyTo: HTTP_FILTER
      match:
        context: GATEWAY
        listener:
          portNumber: 443
          filterChain:
            filter:
              name: "envoy.filters.network.http_connection_manager"
              subFilter:
                name: "envoy.filters.http.router"
      patch:
        operation: INSERT_BEFORE
        value:
          name: envoy.filters.http.response_transformer
          typed_config:
            "@type": "type.googleapis.com/envoy.extensions.filters.http.response_transformer.v3.ResponseTransformer"
            transformation:
              response_body_transform:
                regex_replace:
                  pattern:
                    google_re2: {}
                    regex: "vpc-mykibana-111xxx.us-east1.es.amazonaws.com"
                  substitution: "siem.jupiter.money"
                  replace_all: true

Step 3: Ensure Your Gateway is HTTPS-Ready

Double-check that your Istio gateway is configured to serve HTTPS with a valid certificate for siem.jupiter.money:

apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name: http-gateway
  namespace: istio-system
spec:
  selector:
    istio: ingressgateway
  servers:
    - port:
        number: 443
        name: https
        protocol: HTTPS
      tls:
        mode: SIMPLE
        credentialName: siem-jupiter-money-tls # Name of your Kubernetes Secret with cert/key
      hosts:
        - siem.jupiter.money

Quick Validation Tips

  • After applying all configs, access https://siem.jupiter.money/_plugin/kibana and check that redirects land on your public domain (not the ES VPC domain).
  • Use browser dev tools to inspect the response body—make sure there are no references to vpc-mykibana-111xxx.us-east1.es.amazonaws.com.
  • Verify that cookies are set with the correct domain (siem.jupiter.money).

内容的提问来源于stack exchange,提问作者rohit

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 15:42:41