本地kind搭建的K8s集群节点IP无法访问,Istio验证失败如何解决?
Kind集群Istio外部访问验证解决方案
首先说明:kind集群节点的INTERNAL-IP是Docker内部网桥子网地址,默认宿主机没有对应路由,ping不通属于正常现象,无需针对ping不通做额外排查。
你可以选择以下任意一种方案完成Istio的外部访问验证:
方案一:无需重建集群,临时端口转发(快速验证用)
直接通过kubectl端口转发能力,将Istio网关端口映射到本地宿主机:
- 执行端口转发命令:
kubectl port-forward svc/istio-ingressgateway 8080:80 -n istio-system - 保持命令运行的终端不关闭,本地访问
http://localhost:8080/productpage即可,也可以用curl验证返回结果:
返回内容包含curl http://localhost:8080/productpageSimple Bookstore App字样即为验证通过。
方案二:重建带端口映射的Kind集群(长期使用推荐)
如果需要长期使用集群对外暴露服务,建议新建带预映射端口的Kind集群:
- 删除现有集群:
kind delete cluster - 新建名为
kind-config.yaml的配置文件,内容如下:kind: Cluster apiVersion: kind.x-k8s.io/v1alpha4 nodes: - role: control-plane extraPortMappings: # 映射Istio网关常用NodePort端口到宿主机 - containerPort: 31380 hostPort: 31380 listenAddress: "0.0.0.0" - 用配置文件重建集群:
kind create cluster --config kind-config.yaml - 重新安装Istio和Bookinfo示例后,将istio-ingressgateway服务的HTTP端口NodePort指定为31380,之后直接访问
http://localhost:31380/productpage即可完成验证。
内容的提问来源于stack exchange,提问作者王小明
相关产品推荐
相关产品推荐

