无需Istio Gateway即可使用VirtualService?配置生效异常排查
问题描述
根据Istio VirtualService官方文档,无需创建Gateway即可使用VirtualService,但我尝试注入请求头或重路由请求时均无效果。
我的VirtualService配置如下:
# virtual-service.yaml apiVersion: networking.istio.io/v1alpha3 kind: VirtualService metadata: name: nginx-vs namespace: default spec: hosts: - nginx-web http: - headers: response: add: My-Custom-Header1: "abc-123" route: - destination: host: nginx-web port: number: 80
通过istioctl查看Pod信息,确认VirtualService已被识别并应用到目标Pod:
> istioctl x describe pod nginx-deployment-689cbb8758-5s9ss Pod: nginx-deployment-689cbb8758-5s9ss Pod Ports: 15090 (istio-proxy), 80 (nginx-web) Suggestion: add 'version' label to pod for Istio telemetry. -------------------- Service: nginx-web Port: http-nginxweb 80/HTTP targets pod port 80 VirtualService: nginx-vs 1 HTTP route(s) -------------------- Effectve PeerAuthentication: Workload mTLS: PERMISSIVE Skipping Gateway information (no ingress gateway pods)
但执行curl请求时,并未看到添加的自定义响应头:
> curl -v myapp.com ... < x-envoy-upstream-service-time: 3 < server: istio-envoy < x-envoy-decorator-operation: nginx-web.default.svc.cluster.local:80/* < Via: 1.1 google
我还尝试了重路由等其他VirtualService功能,均未生效。请问必须使用Gateway才能让VirtualService生效吗?还是我的配置未正确关联到服务?
当前我的部署已通过Kubernetes Ingress和Service处理路由,希望添加VirtualService来实现重试功能。
解决方案
外部请求必须通过Istio Gateway才能触发VirtualService生效。
若配置Istio Gateway时遇到问题,请确保istio:标签正确,通过Helm安装时标签可能并非默认值。
内容的提问来源于stack exchange,提问作者Inshaal93
相关产品推荐
相关产品推荐

