微服务部署场景下Kubernetes API Gateway配置与Istio访问故障咨询
微服务API网关架构及Istio配置问题解答
1. 架构合理性验证
你的架构理解完全正确。在多微服务部署的架构下,在所有微服务上层部署统一API Gateway作为南北向流量的唯一入口,是微服务领域的标准实践:
- 避免后端微服务直接暴露到公网,降低安全风险
- 前端无需感知各个后端微服务的独立地址,只需对接网关统一入口即可
- 可在网关层统一实现认证鉴权、限流熔断、灰度发布、日志监控等通用能力,无需每个微服务重复开发
2. Istio访问异常排查修复方案
首先你提供的catalog Service配置存在低级拼写错误,先修复:apiVersin 修改为 apiVersion,否则Service资源会创建失败。
后续可按以下优先级排查问题:
- 确认Istio入口网关访问地址正确性
执行命令kubectl get svc istio-ingressgateway -n istio-system查看Istio入口网关的服务配置:- 如果类型为
LoadBalancer且EXTERNAL-IP为localhost,才可直接使用localhost加80端口访问 - 如果类型为
NodePort,需使用返回的http对应的NodePort(你提到的30139需确认和该结果一致)进行访问
- 如果类型为
- 修正请求域名匹配规则
你本地hosts已经配置了localshoppingcart.com的解析,Istio的VirtualService默认会匹配请求头的Host字段,因此不要用localhost访问,改为使用http://localshoppingcart.com:<网关端口>/catalog访问。如果需要支持localhost访问,需要在VirtualService的hosts配置中增加localhost。 - 检查路径重写配置
如果你的catalog服务的接口根路径为/,需要在VirtualService的对应路由规则中增加路径重写配置,否则请求会将/catalog路径直接透传给后端服务,导致后端找不到对应接口返回404,参考配置如下:http: - match: - uri: prefix: /catalog rewrite: uri: / route: - destination: host: catalog-api-service.local-shoppingcart-v1.svc.cluster.local port: number: 30001 - 确认服务地址配置正确性
如果你的VirtualService和catalog服务不在同一个命名空间,destination的host不能简写为catalog-api-service,需要写全域名:catalog-api-service.local-shoppingcart-v1.svc.cluster.local - 验证后端服务可用性
先排除后端服务本身异常的问题,执行以下命令在集群内部访问catalog服务验证是否正常:kubectl run -it --rm --image=curlimages/curl test -- curl http://catalog-api-service.local-shoppingcart-v1.svc.cluster.local:30001
内容的提问来源于stack exchange,提问作者Brijesh Shah
相关产品推荐
相关产品推荐

