如何在Rancher托管单集群中将Istio ingress等组件部署为DaemonSet
Istio组件DaemonSet模式部署方案
前置校验
确认当前使用Istio版本≥1.10,低版本对组件部署类型的自定义配置兼容性较差;Rancher托管集群无需额外调整集群基础权限,只要持有Istio资源编辑权限即可操作。
1. 自定义配置编写
Istio原生支持通过IstioOperator覆写组件的部署类型,无需手动修改官方默认的Deployment资源,参考配置如下:
apiVersion: install.istio.io/v1alpha1 kind: IstioOperator spec: profile: default # 可替换为当前使用的部署profile components: # Ingress网关配置为DaemonSet ingressGateways: - name: istio-ingressgateway enabled: true k8s: kind: DaemonSet strategy: rollingUpdate: maxSurge: 0 maxUnavailable: 1 # 可选:配置节点选择器,仅调度到指定标签的边缘节点 nodeSelector: node-role.kubernetes.io/edge: "true" # 可选:配置污点容忍,适配特殊节点的污点规则 tolerations: - key: node-role.kubernetes.io/edge operator: Exists effect: NoSchedule # 按需配置资源配额,适配大流量场景 resources: requests: cpu: 2 memory: 2Gi limits: cpu: 4 memory: 4Gi # 可选:开启主机网络,降低转发延迟,适合超高流量场景 # hostNetwork: true # Egress网关配置为DaemonSet egressGateways: - name: istio-egressgateway enabled: true k8s: kind: DaemonSet nodeSelector: node-role.kubernetes.io/egress: "true" tolerations: - key: node-role.kubernetes.io/egress operator: Exists effect: NoSchedule # 其他核心组件(如istiod)如需配置为DaemonSet,参考以下配置 pilot: enabled: true k8s: kind: DaemonSet nodeSelector: node-role.kubernetes.io/istio-control: "true"
2. 部署/更新操作
- 若为首次部署Istio,直接执行命令:
istioctl install -f <你的配置文件名>.yaml - 若为已有Istio环境升级,执行命令:
istioctl upgrade -f <你的配置文件名>.yaml - 若你是通过Rancher应用商店安装的Istio,无需使用istioctl命令,直接在Rancher的Istio应用配置页的
Values配置段中,找到对应组件的kind参数,修改为DaemonSet后重新升级应用即可生效。
3. 部署结果验证
执行命令kubectl get ds -n istio-system,若对应组件的DaemonSet资源存在,且DESIRED实例数和你选定的节点数一致,即为部署成功。
注意事项
- 无特殊需求时建议添加nodeSelector过滤部署节点,避免不必要的资源占用
- DaemonSet模式下实例数和对应标签的节点数绑定,增减节点即可完成扩缩容,比HPA更适合大流量网关场景
- 调整配置前先备份现有Istio配置,避免配置错误影响业务
内容的提问来源于stack exchange,提问作者Anthony Vinay
相关产品推荐
相关产品推荐

