You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

跨网络Istio主从集群配置:修改Remote Pilot端口至NodePort

Adjusting Istiod Port for Remote Cluster in Multi-Network Istio Setup

I’ve dealt with this exact challenge when setting up multi-network Istio clusters using NodePort for istiod (instead of LoadBalancer), so let’s walk through how to override the default 15012 port in your remote cluster’s IstioOperator config.

The Problem

By default, Istio assumes the remote istiod is listening on port 15012. When you expose istiod via NodePort on your primary cluster, you need to explicitly tell the remote cluster to use that custom NodePort instead of the default.

Solution: Override Port in IstioOperator Config

You can adjust the port in two key places in your remote cluster’s IstioOperator manifest:

  1. Under values.pilot.remoteService to configure the operator’s remote pilot settings
  2. Under meshConfig.discoveryAddress to ensure the data plane (sidecars) connect to the correct port

Here’s a complete example config:

apiVersion: install.istio.io/v1alpha1
kind: IstioOperator
metadata:
  namespace: istio-system
  name: istio-remote-cluster
spec:
  profile: remote
  values:
    pilot:
      remoteService:
        # Replace with your primary cluster's accessible Node IP
        address: "192.168.1.100"
        # Replace with your istiod NodePort (e.g., 30012)
        port: 30012
  meshConfig:
    # Match the address and port from above
    discoveryAddress: "192.168.1.100:30012"

Why This Works

  • values.pilot.remoteService.port overrides the default 15012 port that the Istio operator uses to communicate with the primary istiod.
  • meshConfig.discoveryAddress ensures all sidecars in the remote cluster point to the correct NodePort on the primary cluster’s istiod, rather than the default port.

Post-Deployment Validation

After applying this config, verify the setup:

  • Check the remote cluster’s Istio operator logs to confirm it’s connecting to the correct port:
    kubectl logs -n istio-system deployment/istio-operator
    
  • Inspect a sidecar’s proxy config to ensure the discovery address is set properly:
    istioctl proxy-config bootstrap <pod-name> -n <namespace> | grep discoveryAddress
    

内容的提问来源于stack exchange,提问作者Umair Ahmad

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 07:46:27