Istio基于Cookie的虚拟服务路由失效问题排查求助
我们按照Istio规则配置文档设置了基于Cookie的路由规则,预期携带feature-b=true Cookie访问api0-prod.dev.domain.com时,流量会路由到api-gateway.blue.svc.cluster.local,但实际无论Cookie如何设置,流量都被发送到api-gateway.green.svc.cluster.local。
以下是当前使用的Istio VirtualService配置:
apiVersion: networking.istio.io/v1beta1 kind: VirtualService metadata: annotations: meta.helm.sh/release-name: prodstagingistio meta.helm.sh/release-namespace: istio-system creationTimestamp: "2022-07-14T16:12:56Z" generation: 22 labels: app.kubernetes.io/managed-by: Helm name: api-gateway-virtualservice namespace: istio-system resourceVersion: "149056406" uid: a5be0a58-6fd8-467c-9a98-5de9ac71b1dd spec: gateways: - api-gateway hosts: - api0-prod.dev.domain.com - api0-staging.dev.domain.com http: - match: - authority: exact: api0-prod.dev.domain.com headers: cookie: regex: ^(.*;.)?(feature-b=true)(;.*)?$ route: - destination: host: api-gateway.blue.svc.cluster.local - match: - authority: exact: api0-prod.dev.domain.com route: - destination: host: api-gateway.green.svc.cluster.local - match: - authority: exact: api0-staging.dev.domain.com route: - destination: host: api-gateway.orange.svc.cluster.local
失效原因排查
- 正则表达式错误:当前Cookie匹配的正则表达式
^(.*;.)?(feature-b=true)(;.*)?$中,;后面的.是多余的,这会强制要求;后面必须存在任意字符。但Cookie的合法格式可能是:- 单独的
feature-b=true - 多个Cookie时的
xxx=yyy; feature-b=true
前者会因为(.*;.)?无法匹配而导致整个规则不生效,进而触发下一条路由规则。正确的正则应该改为^(.*;)?(feature-b=true)(;.*)?$,去掉;后的.。
- 单独的
- 路由匹配顺序优先级:Istio的VirtualService中
http数组内的规则是按顺序匹配的,一旦前面的规则不满足,就会匹配后续第一个符合条件的规则。由于第一个带Cookie校验的规则失效,流量会直接匹配第二个针对api0-prod.dev.domain.com的规则,从而路由到green服务。
修正后的配置示例
apiVersion: networking.istio.io/v1beta1 kind: VirtualService metadata: annotations: meta.helm.sh/release-name: prodstagingistio meta.helm.sh/release-namespace: istio-system creationTimestamp: "2022-07-14T16:12:56Z" generation: 22 labels: app.kubernetes.io/managed-by: Helm name: api-gateway-virtualservice namespace: istio-system resourceVersion: "149056406" uid: a5be0a58-6fd8-467c-9a98-5de9ac71b1dd spec: gateways: - api-gateway hosts: - api0-prod.dev.domain.com - api0-staging.dev.domain.com http: - match: - authority: exact: api0-prod.dev.domain.com headers: cookie: regex: ^(.*;)?(feature-b=true)(;.*)?$ route: - destination: host: api-gateway.blue.svc.cluster.local - match: - authority: exact: api0-prod.dev.domain.com route: - destination: host: api-gateway.green.svc.cluster.local - match: - authority: exact: api0-staging.dev.domain.com route: - destination: host: api-gateway.orange.svc.cluster.local
内容的提问来源于stack exchange,提问作者Ming Yu
相关产品推荐
相关产品推荐

