Istio Egress Gateway自定义端口8888无法启用问题排查
First off, this scenario is absolutely supported—you can configure an Egress Gateway to handle multiple ports for the same external service. The core issue here is that Envoy isn’t listening on port 8888, which means either the port wasn’t properly exposed in the Egress Gateway pod, or the Istio configuration isn’t pushing the listener to Envoy. Let’s break down the fixes step by step:
1. Fix Your IstioOperator Configuration (Critical Missing Step)
You mentioned updating the IstioOperator to add the https-alt port mapping, but it’s easy to overlook that you need to configure both the Service ports and the container ports for the Egress Gateway’s istio-proxy container. Without defining the container port, the pod won’t expose it, and Envoy won’t create a listener for it.
Your corrected IstioOperator should look something like this:
spec: components: egressGateways: - name: istio-egressgateway enabled: true k8s: # Configure the pod's container ports first podSpec: containers: - name: istio-proxy ports: - containerPort: 8443 protocol: TCP - containerPort: 8888 protocol: TCP # Then map the Service ports to the container ports service: ports: - port: 8443 targetPort: 8443 name: https - port: 8888 targetPort: 8888 name: https-alt
The mistake you made earlier (setting targetPort: 8443 for 8888) caused duplicate 8443 entries because you didn’t have a container port 8888 to map to.
2. Reapply the IstioOperator and Restart the Egress Gateway
Istio won’t automatically pick up changes to the Operator configuration for pod-level ports without a restart. Run these commands to apply your updated config and roll out a new pod:
# Apply the corrected IstioOperator istioctl apply -f your-operator-config.yaml # Force a rollout of the Egress Gateway deployment to load the new pod configuration kubectl rollout restart deployment istio-egressgateway -n istio-system
Wait for the pod to restart—you can verify it’s up with kubectl get pods -n istio-system | grep egress.
3. Validate the Pod and Envoy Configuration
After the pod restarts, check if the container port is exposed:
kubectl describe pod <your-egress-pod-name> -n istio-system
Look under the Containers > istio-proxy > Ports section—you should see both 8443 and 8888 listed.
Next, confirm Envoy is listening on 8888 using Istio’s proxy config tool:
istioctl pc listeners <your-egress-pod-name> -n istio-system | grep 8888
You should see a listener entry for port 8888. If not, double-check your Gateway resource.
4. Verify Your Gateway, ServiceEntry, and VirtualService Configs
Make sure your Gateway is explicitly targeting the Egress Gateway and has the correct TLS passthrough rules for both ports:
apiVersion: networking.istio.io/v1alpha3 kind: Gateway metadata: name: egress-gateway spec: selector: istio: egressgateway # Critical: binds this Gateway to the Egress Gateway pods servers: - port: number: 8443 name: https protocol: HTTPS tls: mode: PASSTHROUGH hosts: - "external-service.example.com" - port: number: 8888 name: https-alt protocol: HTTPS tls: mode: PASSTHROUGH hosts: - "external-service.example.com"
Your VirtualService must also route 8888 traffic to the Egress Gateway’s 8888 port (not 8443):
apiVersion: networking.istio.io/v1alpha3 kind: VirtualService metadata: name: external-service-vs spec: hosts: - "external-service.example.com" gateways: - egress-gateway - mesh http: - match: - port: 8443 route: - destination: host: istio-egressgateway.istio-system.svc.cluster.local port: number: 8443 - match: - port: 8888 route: - destination: host: istio-egressgateway.istio-system.svc.cluster.local port: number: 8888
Your ServiceEntry should include both ports, which you mentioned you already have—just ensure the port names and protocols match across all resources.
5. Check for Istio 1.7-Specific Quirks
Istio 1.7 is an older version (end-of-life now), but multi-port Egress Gateways are fully supported. If you still see issues after the above steps, try deleting and recreating the Gateway resource (sometimes Istio’s config propagation can be finicky in older versions):
kubectl delete gateway egress-gateway -n istio-system kubectl apply -f your-gateway-config.yaml
内容的提问来源于stack exchange,提问作者Lesrac

