You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Istio Gateway Reencrypt配置问题:如何加载公网证书并实现路径路由后重加密内部请求

实现方案

完全可以,这是Istio网关的标准支持场景,你只需要把原来的PASSTHROUGH模式替换为网关侧TLS终止+后端重加密的配置即可,同时满足公共证书配置、路径路由、内部TLS传输三个需求。

1. 配置Gateway完成对外TLS终止

首先将你的公共可信证书存储为集群内的kubernetes.io/tls类型Secret,需和Ingress Gateway部署在同一命名空间(通常为istio-system)。
在Gateway资源中将HTTPS端口的TLS模式设置为SIMPLE,引用上述Secret即可完成对外HTTPS服务配置,此时网关会接管TLS握手,可解析请求的完整HTTP字段(包括PATH路径、Header等),不再受PASSTHROUGH模式下仅能基于SNI路由的限制。
配置示例:

apiVersion: networking.istio.io/v1beta1
kind: Gateway
metadata:
  name: public-https-gateway
  namespace: istio-system
spec:
  selector:
    istio: ingressgateway
  servers:
  - port:
      number: 443
      name: https
      protocol: HTTPS
    tls:
      mode: SIMPLE
      credentialName: public-cert-secret # 替换为你的公共证书Secret名称
    hosts:
    - "your-service-domain.com" # 替换为你的对外服务域名

2. 配置VirtualService实现路径路由

网关侧TLS终止后,路径路由配置逻辑和普通HTTP路由完全一致,可按需求配置精确匹配、前缀匹配等路由规则,将不同路径的请求转发到对应后端服务。
配置示例:

apiVersion: networking.istio.io/v1beta1
kind: VirtualService
metadata:
  name: service-route
spec:
  hosts:
  - "your-service-domain.com"
  gateways:
  - istio-system/public-https-gateway
  http:
  # 路径/api转发到内部API服务
  - match:
    - uri:
        prefix: /api
    route:
    - destination:
        host: internal-api-service.default.svc.cluster.local
        port:
          number: 443
  # 路径/web转发到内部前端服务
  - match:
    - uri:
        prefix: /web
    route:
    - destination:
        host: internal-web-service.default.svc.cluster.local
        port:
          number: 443

3. 配置DestinationRule完成后端重加密

要实现网关转发请求到内部TLS服务时重新加密,只需给对应后端服务配置DestinationRule,指定TLS连接模式即可:

  • 若内部服务为单向TLS认证,设置tls.mode为SIMPLE
  • 若内部服务为双向TLS认证,设置tls.mode为MUTUAL,同时配置客户端证书
  • 若内部服务使用自签证书,可额外配置caCertificates指定根CA进行证书校验,测试场景下也可临时开启insecureSkipVerify: true跳过校验(不推荐生产环境使用)
    配置示例:
apiVersion: networking.istio.io/v1beta1
kind: DestinationRule
metadata:
  name: internal-api-dr
spec:
  host: internal-api-service.default.svc.cluster.local
  trafficPolicy:
    tls:
      mode: SIMPLE
      # 内部为自签证书时添加如下配置
      # caCertificates: /etc/istio/ingressgateway-certs/internal-root-ca.crt
      # 跳过证书校验(仅测试用)
      # insecureSkipVerify: true

该方案下对外使用公共可信证书提供HTTPS服务,网关基于请求路径做路由转发,内部传输全程保持TLS加密,安全性和功能需求都可以得到满足。

内容的提问来源于stack exchange,提问作者leoconco

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.02 20:27:03