如何让指定Deployment注入指向新istiod的Sidecar(无需移除命名空间标签)
为指定Deployment强制注入新版Istio Sidecar(无需修改命名空间标签)
Istio的Sidecar注入遵循明确的优先级规则:Pod模板注解 > Pod标签 > 命名空间注解 > 命名空间标签。你之前尝试的Pod标签优先级低于命名空间标签,所以不生效。正确的做法是给目标Deployment的Pod模板添加注解来覆盖命名空间的设置。
具体操作
编辑目标Deployment的配置,在Pod模板的
metadata.annotations中添加以下两个注解:sidecar.istio.io/inject: "true":明确开启Sidecar注入istio.io/rev: "1-14-1":指定使用的Istio修订版本
示例Deployment片段:
apiVersion: apps/v1 kind: Deployment metadata: name: your-test-deployment spec: replicas: 1 selector: matchLabels: app: your-test-app template: metadata: annotations: sidecar.istio.io/inject: "true" istio.io/rev: "1-14-1" labels: app: your-test-app spec: containers: - name: app-container image: your-app-image:tag应用更新:
kubectl apply -f your-deployment.yaml # 或者直接在线编辑:kubectl edit deployment your-test-deployment
验证生效
- 查看新Pod的标签,确认
istio.io/rev已设置为1-14-1:kubectl get pod <pod-name> --show-labels | grep istio.io/rev - 检查Sidecar镜像版本:
输出中会显示Sidecar的版本为1.14.1,且连接的istiod也是对应版本。kubectl exec <pod-name> -c istio-proxy -- istioctl version
注意事项
- 仅需更新Deployment的Pod模板,旧Pod不会自动更新,需要滚动重启Deployment让新配置生效:
kubectl rollout restart deployment your-test-deployment - 这种方式可以逐个测试Deployment,验证无误后再批量修改命名空间标签完成全量升级。
内容的提问来源于stack exchange,提问作者saurav
相关产品推荐
相关产品推荐

