Istio入口网关直连服务的请求路由80/20分配失效问题
Problem Summary
I have two versions (v1, v2) of a simple Node.js app web-api. I deployed an Istio Ingress Gateway and configured a VirtualService to route 80% of traffic to v1 and 20% to v2. However, Kiali shows traffic is split 50/50 instead. Oddly, when I add a simple front-end service that only forwards requests to web-api, the traffic split rule works as expected. According to Istio docs, the Ingress Gateway should support traffic routing rules for user-facing services, but I can't figure out why this happens.
Root Cause
The core issue is missing DestinationRule configuration for the web-api service. Your VirtualService (named web-api) references subsets v1 and v2, but Istio has no way to map these subsets to your actual deployment pods without a corresponding DestinationRule.
When no DestinationRule defines the subsets, Istio falls back to default round-robin load balancing between the available pods (since you have 1 replica for each version, it ends up as a 50/50 split). When you added a front-end service, the front-end's sidecar proxy might have implicitly relied on mesh behaviors to work around the gap, but the real fix is defining the subsets explicitly.
Solution
Add a DestinationRule that maps the v1 and v2 subsets to the pod labels in your deployments. This tells Istio which pods belong to each version, allowing the traffic weights in your VirtualService to take effect.
Step 1: Create the DestinationRule
Create a file istio-destinationrule.yaml with the following content:
apiVersion: networking.istio.io/v1alpha3 kind: DestinationRule metadata: name: web-api spec: host: web-api subsets: - name: v1 labels: version: v1 - name: v2 labels: version: v2
Step 2: Apply the Configuration
Deploy the DestinationRule to your cluster:
kubectl apply -f istio-destinationrule.yaml
Step 3: Verify the Setup
- Check that the
DestinationRuleis applied correctly:kubectl get destinationrules.networking.istio.io web-api - Send multiple test requests to the Ingress Gateway's
/testendpoint and verify Kiali shows the 80/20 traffic split.
Additional Configuration Check
Your current istio-ingress.yaml routes /test directly to web-api, which should work as long as the DestinationRule exists—since the internal VirtualService targets the web-api host, traffic will flow through the split rules once subsets are defined.
Final Notes
Always remember that VirtualService subsets require a matching DestinationRule to define which pods belong to each subset. Without this, Istio can't enforce traffic splitting rules and will use default load balancing.
内容的提问来源于stack exchange,提问作者Harald Uebele

