You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Istio Sidecar以允许出站流量访问外部主机

Istio Sidecar 放行外部服务配置方案

配置未生效的核心原因:当outboundTrafficPolicy.mode设为REGISTRY_ONLY时,Istio仅允许访问已注册到服务网格内部的服务,外部域名默认不在网格注册列表中,仅在Sidecar的egress.hosts中添加域名路径无法生效,需要搭配ServiceEntry资源将外部域名注册到网格。


第一步:创建对应外部域名的ServiceEntry资源

apiVersion: networking.istio.io/v1beta1
kind: ServiceEntry
metadata:
  name: external-google
  namespace: namespace # 可与Sidecar同命名空间,也可配置为全局可访问
spec:
  hosts:
  - "google.com"
  ports:
  - number: 443
    name: https
    protocol: HTTPS
  resolution: DNS
  location: MESH_EXTERNAL

如需放行通配符域名,直接在hosts字段填写*.google.com即可,多域名可以在同一个hosts数组中添加多个条目。


第二步:修正Sidecar配置

原配置中"google.com/*"格式不符合规则,Sidecar的egress.hosts要求格式为<命名空间>/<服务名称>,外部服务不属于指定命名空间,需要写为*/<外部域名>,修正后的配置如下:

apiVersion: "networking.istio.io/v1beta1"
kind: "Sidecar"
metadata:
  name: "egress-sidecar"
  namespace: "namespace"
spec:
  workloadSelector:
    labels:
      app: 'target_app'
  egress:
  - hosts:
    - "namespace/*"
    - "*/google.com" # 与ServiceEntry中定义的域名一一对应
  outboundTrafficPolicy:
    mode: "REGISTRY_ONLY"

补充说明

  • 多个外部域名需要在ServiceEntry的hosts中全部声明,再同步在Sidecar的egress.hosts中添加对应*/<域名>条目
  • 确保ServiceEntry中配置的端口、协议和实际访问外部服务的参数一致
  • 无需严格限制出站流量的场景下,可将outboundTrafficPolicy.mode改为ALLOW_ANY直接放行所有出站请求,该方案安全性较低,不推荐生产环境使用

内容的提问来源于stack exchange,提问作者Luca Vlad

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.28 02:45:02