You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Istio ingress gateway暴露HTTPS类型Kubernetes服务

Istio暴露HTTPS协议NIFI服务配置指南

前置检查

  • 确认cetic helm部署的NIFI Service保持ClusterIP类型,不要修改为LoadBalancer。执行kubectl get svc -n <nifi所在命名空间>记录NIFI的服务名、HTTPS监听端口(默认值为8443)。
  • 确认集群内Istio Ingress Gateway运行正常,后续所有外部流量统一走网关的外部负载均衡IP。

方案一:TLS透传模式(推荐快速上线使用)

该模式下Istio网关不做TLS解密,仅根据SNI信息将443端口流量直接转发给后端NIFI服务,TLS握手全程由NIFI本身处理,不需要在网关侧额外配置证书,配置成本最低。

  1. 配置Gateway资源:
apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name: nifi-gateway
  namespace: <nifi所在命名空间>
spec:
  selector:
    istio: ingressgateway # 匹配默认Istio入口网关的标签
  servers:
  - port:
      number: 443
      name: tls-passthrough
      protocol: TLS
    hosts:
    - "nifi.your-dns-domain.com" # 替换为实际的NIFI服务域名
    tls:
      mode: PASSTHROUGH # 核心配置:开启TLS透传
  1. 配置VirtualService绑定路由规则:
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: nifi-vs
  namespace: <nifi所在命名空间>
spec:
  hosts:
  - "nifi.your-dns-domain.com"
  gateways:
  - nifi-gateway
  tls:
  - match:
    - port: 443
      sniHosts:
      - "nifi.your-dns-domain.com"
    route:
    - destination:
        host: nifi # 替换为实际NIFI的Service名称
        port:
          number: 8443 # 替换为实际NIFI Service的HTTPS端口

注意:该模式要求NIFI持有的证书包含使用域名的SAN字段,否则浏览器会报证书不信任错误。cetic chart默认签发自签证书,测试环境可将自签CA导入本地信任链,生产环境替换为正规CA签发的证书挂载到NIFI即可。


方案二:网关层TLS终止模式(适合统一证书管理场景)

如果希望公网证书统一在Istio网关层维护,不想频繁修改NIFI内部证书配置,可以使用该模式:用户侧到网关走公网可信HTTPS连接,网关到NIFI走集群内部HTTPS连接,跳过自签证书校验即可。

  1. 提前将域名对应的公网证书存储到istio-system命名空间:
kubectl create -n istio-system secret tls nifi-tls-cert --key=your-private.key --cert=your-public-cert.crt
  1. 配置Gateway资源绑定证书:
apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name: nifi-gateway
  namespace: <nifi所在命名空间>
spec:
  selector:
    istio: ingressgateway
  servers:
  - port:
      number: 443
      name: https
      protocol: HTTPS
    hosts:
    - "nifi.your-dns-domain.com"
    tls:
      mode: SIMPLE
      credentialName: nifi-tls-cert # 对应上一步创建的证书Secret名称
  1. 配置VirtualService和DestinationRule,指定回源HTTPS规则:
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: nifi-vs
  namespace: <nifi所在命名空间>
spec:
  hosts:
  - "nifi.your-dns-domain.com"
  gateways:
  - nifi-gateway
  http:
  - route:
    - destination:
        host: nifi
        port:
          number: 8443
---
apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
  name: nifi-dr
  namespace: <nifi所在命名空间>
spec:
  host: nifi
  trafficPolicy:
    tls:
      mode: SIMPLE # 回源使用HTTPS协议
      insecureSkipVerify: true # 跳过NIFI自签证书校验,集群内部使用无安全风险

cetic NIFI部署专属注意事项

  • 必须修改helm values中的两个参数,否则会出现访问403、重定向地址错误问题:
properties:
  webHttpsHost: "0.0.0.0"
  webProxyHost: "nifi.your-dns-domain.com" # 替换为实际DNS域名
  • 所有配置生效后,将DNS域名的A记录指向Istio Ingress Gateway的EXTERNAL-IP即可,该IP可通过kubectl get svc istio-ingressgateway -n istio-system查询。
  • 如果配置完访问不通,先检查NIFI Pod是否注入Istio sidecar,若未注入,给NIFI所在命名空间打上istio-injection=enabled标签后重启NIFI Pod即可。

内容的提问来源于stack exchange,提问作者unknown

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.26 19:45:31