You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Istio虚拟服务仅80/443端口可用,其他端口无法正常工作

Istio Gateway自定义端口9999无法访问的问题排查与解决

问题分析

你配置的Istio Gateway和VirtualService使用9999端口无法正常路由,仅默认80/443端口可用,大概率是以下几个原因导致:

  • Istio IngressGateway未暴露9999端口
  • Gateway端口命名不符合Istio协议识别规范
  • 外部流量未正确映射到9999端口

解决步骤

1. 修正Gateway端口命名

Istio通过端口名称前缀识别协议(如http-、tcp-),你的端口名admin无法被Istio正确解析,需修改为带协议前缀的名称:

apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name: nginx-gateway
spec:
  selector:
    istio: ingressgateway
  servers:
    - port:
        name: http-9999 # 改为符合规范的端口名
        number: 9999
        protocol: HTTP
      hosts:
        - nginx.example.com

2. 暴露IngressGateway的9999端口

默认Istio IngressGateway仅开放80、443等常用端口,需修改其Service添加9999端口映射:

kubectl edit svc istio-ingressgateway -n istio-system

在ports字段中添加:

ports:
  - name: http-9999
    port: 9999
    targetPort: 9999
    # 若使用NodePort模式,可指定nodePort值;LoadBalancer模式无需额外配置

如果是通过IstioOperator安装的Istio,建议修改Operator配置持久化端口:

apiVersion: install.istio.io/v1alpha1
kind: IstioOperator
spec:
  components:
    ingressGateways:
    - name: istio-ingressgateway
      enabled: true
      k8s:
        service:
          ports:
            - name: http-9999
              port: 9999
              targetPort: 9999

3. 验证配置有效性

检查Istio配置是否存在错误:

istioctl analyze

查看IngressGateway Pod是否监听9999端口:

kubectl exec -n istio-system <istio-ingressgateway-pod-name> -- netstat -tulpn | grep 9999

4. 测试访问

使用curl验证流量是否正常路由:

curl -H "Host: nginx.example.com" http://<ingressgateway-ip>:9999

内容的提问来源于stack exchange,提问作者Aditya Joshi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 11:35:28