You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Istio结合SDS与双向TLS部署时遇连接失败问题求助

问题分析与解决方案

首先看你的错误日志,核心问题是:

TLS error: 268435703:SSL routines:OPENSSL_internal:WRONG_VERSION_NUMBER

这说明Istio Ingress Gateway尝试用TLS协议去连接后端nginx的80端口(纯HTTP服务),但后端并没有开启TLS监听,导致握手失败。根本原因是你集群启用了全局双向TLS(mTLS),Istio默认强制服务间通信使用mTLS,但你的nginx Pod没有注入Istio Sidecar,也没有配置对应的规则允许明文流量。

另外,你提到的SDS配置问题,也需要调整Gateway的TLS模式来适配SDS机制,而不是用传统的文件挂载方式。


第一步:解决后端通信的mTLS冲突

你有两种方案可以选择:

方案A:给nginx Pod注入Istio Sidecar

如果你的nginx服务需要加入Istio服务网格,推荐这种方式:

  1. 给nginx所在的default命名空间开启自动注入:
    kubectl label namespace default istio-injection=enabled
    
  2. 删除现有nginx Pod,让Kubernetes重新创建并自动注入Sidecar:
    kubectl delete pod nginx1
    kubectl apply -f your-nginx-pod-service.yaml
    

注入Sidecar后,Istio会自动处理mTLS握手,Ingress Gateway和nginx之间的通信会被Sidecar代理,无需额外配置。

方案B:配置DestinationRule允许明文访问后端

如果不想给nginx注入Sidecar(比如是第三方服务或无需网格管理),需要创建DestinationRule告诉Istio不要用mTLS连接这个服务:

apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
  name: nginx1
  namespace: default
spec:
  host: nginx1.default.svc.cluster.local
  trafficPolicy:
    tls:
      mode: DISABLE  # 禁用mTLS,允许明文连接

应用这个配置后,Ingress Gateway会用纯HTTP协议连接nginx的80端口,解决握手错误。


第二步:正确配置SDS的Ingress SSL终止

因为你使用SDS(Secret Discovery Service),不能在Gateway里直接指定证书文件路径,而是要通过credentialName关联Kubernetes Secret(SDS会自动从Secret中加载证书):

  1. 首先创建用于Ingress的SSL证书Secret(假设你已经有tls.crt和tls.key文件):
    kubectl create secret tls istio-ingressgateway-certs \
      --key tls.key \
      --cert tls.crt \
      -n istio-system
    
  2. 修改Gateway配置,使用SDS模式的HTTPS终止:
    apiVersion: networking.istio.io/v1alpha3
    kind: Gateway
    metadata:
      name: default-gateway
      namespace: istio-system
    spec:
      selector:
        istio: ingressgateway
      servers:
      - hosts:
        - '*'
        port:
          name: http
          number: 80
          protocol: HTTP
        # 可选:把HTTP请求重定向到HTTPS
        tls:
          httpsRedirect: true
      - hosts:
        - '*'
        port:
          name: https
          number: 443
          protocol: HTTPS
        tls:
          mode: SIMPLE
          credentialName: istio-ingressgateway-certs  # 对应你创建的Secret名称
    

这样SDS会自动从指定的Secret中获取证书,完成Ingress处的SSL终止。


验证配置

应用所有修改后,执行以下命令验证:

  1. 检查Ingress Gateway Pod状态:kubectl get pods -n istio-system | grep ingressgateway
  2. 检查Gateway配置:kubectl get gateway default-gateway -n istio-system -o yaml
  3. 访问https://your-ingress-ip/nginx1,确认可以正常访问nginx服务。

内容的提问来源于stack exchange,提问作者stiller_leser

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 09:09:21