You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让指定Deployment注入指向新istiod的Sidecar(无需移除命名空间标签)

为指定Deployment强制注入新版Istio Sidecar(无需修改命名空间标签)

Istio的Sidecar注入遵循明确的优先级规则:Pod模板注解 > Pod标签 > 命名空间注解 > 命名空间标签。你之前尝试的Pod标签优先级低于命名空间标签,所以不生效。正确的做法是给目标Deployment的Pod模板添加注解来覆盖命名空间的设置。

具体操作

  1. 编辑目标Deployment的配置,在Pod模板的metadata.annotations中添加以下两个注解:

    • sidecar.istio.io/inject: "true":明确开启Sidecar注入
    • istio.io/rev: "1-14-1":指定使用的Istio修订版本

    示例Deployment片段:

    apiVersion: apps/v1
    kind: Deployment
    metadata:
      name: your-test-deployment
    spec:
      replicas: 1
      selector:
        matchLabels:
          app: your-test-app
      template:
        metadata:
          annotations:
            sidecar.istio.io/inject: "true"
            istio.io/rev: "1-14-1"
          labels:
            app: your-test-app
        spec:
          containers:
          - name: app-container
            image: your-app-image:tag
    
  2. 应用更新:

    kubectl apply -f your-deployment.yaml
    # 或者直接在线编辑:kubectl edit deployment your-test-deployment
    

验证生效

  • 查看新Pod的标签,确认istio.io/rev已设置为1-14-1:
    kubectl get pod <pod-name> --show-labels | grep istio.io/rev
    
  • 检查Sidecar镜像版本:
    kubectl exec <pod-name> -c istio-proxy -- istioctl version
    
    输出中会显示Sidecar的版本为1.14.1,且连接的istiod也是对应版本。

注意事项

  • 仅需更新Deployment的Pod模板,旧Pod不会自动更新,需要滚动重启Deployment让新配置生效:kubectl rollout restart deployment your-test-deployment
  • 这种方式可以逐个测试Deployment,验证无误后再批量修改命名空间标签完成全量升级。

内容的提问来源于stack exchange,提问作者saurav

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 01:31:03