Istio环境下Bookinfo示例应用启动失败:Proxy Init容器崩溃
Hey there, I’ve dealt with this exact issue a few times when setting up Istio and Bookinfo. That proxy init crash happens when the iptables chains Istio needs already exist on the node—usually from a previous failed deployment or conflicting tooling. Let’s walk through the fixes step by step:
1. Clean Up Residual Resources & Iptables Rules
First, let’s wipe any leftover Bookinfo resources and stale iptables chains that might be causing conflicts:
- Delete all Bookinfo components:
kubectl delete -f samples/bookinfo/platform/kube/bookinfo.yaml - Log into the node where the failing Pod was scheduled (you can find the node with
kubectl describe pod <failed-pod-name> | grep Node:), then check for Istio-specific iptables chains:iptables -L | grep istio - If you see chains like
ISTIO_INBOUND,ISTIO_OUTBOUND, orISTIO_REDIRECT, delete them:
Note: If you don’t have direct node access, you can run these commands via a privileged Pod deployed to the target node.iptables -F ISTIO_INBOUND iptables -F ISTIO_OUTBOUND iptables -F ISTIO_REDIRECT iptables -X ISTIO_INBOUND iptables -X ISTIO_OUTBOUND iptables -X ISTIO_REDIRECT
2. Check for Conflicting Tools
Istio’s proxy init relies on modifying iptables, so other tools that tweak firewall rules can cause clashes:
- Look for CNIs like Calico, Cilium, or security tools that modify iptables on your nodes.
- Temporarily disable any non-essential iptables-managing tools and try redeploying Bookinfo. If the issue resolves, you’ll need to adjust the conflicting tool’s configuration to avoid overlapping with Istio’s chains.
3. Adjust Proxy Init’s Iptables Behavior
If cleaning up doesn’t work, you can tweak the proxy init container to handle existing chains gracefully:
- Edit the Istio sidecar injector ConfigMap:
kubectl edit configmap istio-sidecar-injector -n istio-system - Find the
proxy_initsection in thevaluesYAML block, then add the environment variableINIT_SKIP_IPTABLES=true(this works for most recent Istio versions) to make the init container skip checking for existing chains.
4. Verify Version Compatibility
Make sure your Istio version matches the Bookinfo sample version you’re using. Mismatched versions can lead to unexpected configuration conflicts:
- Use the Bookinfo YAML that comes bundled with your installed Istio release (from the
samples/bookinfodirectory) instead of using an external version.
Verify the Fix
After trying the above steps, redeploy Bookinfo and check the Pod status:
kubectl apply -f samples/bookinfo/platform/kube/bookinfo.yaml kubectl get pods
If all pods start successfully, you’re good to go! If not, check the proxy init logs again with:
kubectl logs <pod-name> -c istio-init
This will help identify any remaining lingering issues.
内容的提问来源于stack exchange,提问作者santosh

