You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Istio环境下Bookinfo示例应用启动失败:Proxy Init容器崩溃

Fixing "iptables: Chain already exists" in Istio Proxy Init Container for Bookinfo App

Hey there, I’ve dealt with this exact issue a few times when setting up Istio and Bookinfo. That proxy init crash happens when the iptables chains Istio needs already exist on the node—usually from a previous failed deployment or conflicting tooling. Let’s walk through the fixes step by step:

1. Clean Up Residual Resources & Iptables Rules

First, let’s wipe any leftover Bookinfo resources and stale iptables chains that might be causing conflicts:

  • Delete all Bookinfo components:
    kubectl delete -f samples/bookinfo/platform/kube/bookinfo.yaml
    
  • Log into the node where the failing Pod was scheduled (you can find the node with kubectl describe pod <failed-pod-name> | grep Node:), then check for Istio-specific iptables chains:
    iptables -L | grep istio
    
  • If you see chains like ISTIO_INBOUND, ISTIO_OUTBOUND, or ISTIO_REDIRECT, delete them:
    iptables -F ISTIO_INBOUND
    iptables -F ISTIO_OUTBOUND
    iptables -F ISTIO_REDIRECT
    iptables -X ISTIO_INBOUND
    iptables -X ISTIO_OUTBOUND
    iptables -X ISTIO_REDIRECT
    
    Note: If you don’t have direct node access, you can run these commands via a privileged Pod deployed to the target node.

2. Check for Conflicting Tools

Istio’s proxy init relies on modifying iptables, so other tools that tweak firewall rules can cause clashes:

  • Look for CNIs like Calico, Cilium, or security tools that modify iptables on your nodes.
  • Temporarily disable any non-essential iptables-managing tools and try redeploying Bookinfo. If the issue resolves, you’ll need to adjust the conflicting tool’s configuration to avoid overlapping with Istio’s chains.

3. Adjust Proxy Init’s Iptables Behavior

If cleaning up doesn’t work, you can tweak the proxy init container to handle existing chains gracefully:

  • Edit the Istio sidecar injector ConfigMap:
    kubectl edit configmap istio-sidecar-injector -n istio-system
    
  • Find the proxy_init section in the values YAML block, then add the environment variable INIT_SKIP_IPTABLES=true (this works for most recent Istio versions) to make the init container skip checking for existing chains.

4. Verify Version Compatibility

Make sure your Istio version matches the Bookinfo sample version you’re using. Mismatched versions can lead to unexpected configuration conflicts:

  • Use the Bookinfo YAML that comes bundled with your installed Istio release (from the samples/bookinfo directory) instead of using an external version.

Verify the Fix

After trying the above steps, redeploy Bookinfo and check the Pod status:

kubectl apply -f samples/bookinfo/platform/kube/bookinfo.yaml
kubectl get pods

If all pods start successfully, you’re good to go! If not, check the proxy init logs again with:

kubectl logs <pod-name> -c istio-init

This will help identify any remaining lingering issues.

内容的提问来源于stack exchange,提问作者santosh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 07:49:02