Istio配置HTTPS转HTTP报404 NR route_not_found问题解决方法
Istio HTTPS TLS终止子路径404问题排查与解决
问题现象
- HTTP 80端口访问完全正常
- HTTPS 443端口仅根路径
/可正常访问返回HTTP 200,访问任意子路径(如/blabla)时返回HTTP 404
故障复现命令
curl https://serviceA.example.com
curl https://serviceA.example.com/blabla
Istio访问日志报错
GET /blabla HTTP/2" 404 NR route_not_found
相关YAML配置
apiVersion: networking.istio.io/v1alpha3 kind: Gateway metadata: name: serviceA-gateway namespace: default spec: selector: istio: ingressgateway servers: - port: number: 80 name: HTTP protocol: HTTP hosts: - "serviceA.example.com" - port: number: 443 name: https protocol: HTTPS tls: mode: SIMPLE credentialName: serviceA.example.com hosts: - "*" --- apiVersion: networking.istio.io/v1alpha3 kind: VirtualService metadata: name: serviceA-swearl namespace: default spec: hosts: - serviceA.example.com gateways: - serviceA-gateway HTTP: - route: - destination: host: serviceA.default.svc.cluster.local port: number: 80
部署环境说明
- 底层集群:AWS EKS
- Istio部署方式:Istio Operator
- 入口负载均衡类型:NLB
- TLS证书存储:对应Secret存放在
istio-system命名空间下 - 业务侧Service、Deployment均已配置Istio要求的匹配标签
根因与解决方案
根因
Ingress定义中的pathType配置为ImplementationSpecific,该配置下Istio的路径匹配规则仅对根路径生效,所有子路径无法匹配到对应路由规则,因此返回route_not_found类型404错误。
解决方案
将Ingress资源中的pathType配置从ImplementationSpecific修改为Prefix即可解决子路径访问404的问题。
相关参考
Configure Ingress pathType ImplementationSpecific behavior #26883(Istio官方Issue)
内容的提问来源于stack exchange,提问作者mar5
相关产品推荐
相关产品推荐

