使用Istio与Kubernetes时流量拆分出现健康上游异常问题
排查Istio流量拆分中"no healthy upstream"问题的步骤
兄弟,我之前在Istio做流量拆分时也踩过一模一样的坑,咱们一步步来定位解决:
1. 先核对Service与Deployment的标签匹配逻辑
你的greeting Service用了app: greeting作为selector,这是流量能转发到Pod的核心前提!你得立刻确认hello Deployment的Pod标签是否完全匹配这个selector:
- 执行命令查看两个Deployment的标签配置:
kubectl get deployments hello howdy -o yaml | grep -A 5 "labels" - 如果hello的Pod标签里没有
app: greeting,赶紧修改它的Deployment配置,在spec.template.metadata.labels里加上这个标签——只有标签匹配,Service才能把流量导向它的Pod。
2. 确认Istio Sidecar是否注入到hello的Pod中
Istio是靠sidecar容器管理Pod流量的,如果hello的Pod没注入istio-proxy,Istio根本识别不到这个服务的存在:
- 检查Pod的容器列表,确认包含
istio-proxy:kubectl get pods -l app=greeting -o jsonpath='{.items[*].spec.containers[*].name}' | tr ' ' '\n' - 如果没有注入,要么给当前命名空间开启自动注入:
要么手动给hello的Deployment添加注入注解,然后重启Deployment生效:kubectl label namespace <你的命名空间> istio-injection=enabledmetadata: annotations: sidecar.istio.io/inject: "true"
3. 检查Pod的健康探针配置
Istio会依赖K8s的健康探针判断Pod是否可用,如果hello的Pod没配置Liveness/Readiness探针,或者探针失败,Istio会直接标记它为"不健康上游":
- 查看Pod的健康状态:
kubectl describe pods -l app=greeting | grep -A 10 "Conditions" - 确保
Ready状态是True,如果不是,给hello的Deployment补上正确的探针配置,比如:spec: template: spec: containers: - name: hello livenessProbe: httpGet: path: /health port: 8081 initialDelaySeconds: 5 periodSeconds: 5 readinessProbe: httpGet: path: /health port: 8081 initialDelaySeconds: 5 periodSeconds: 5
4. 验证DestinationRule的子集配置
如果你的VirtualService是按subset拆分流量,那DestinationRule必须正确定义两个子集,且标签要精准匹配对应的Deployment:
- 正确的DestinationRule示例应该是这样的:
apiVersion: networking.istio.io/v1alpha3 kind: DestinationRule metadata: name: greeting spec: host: greeting subsets: - name: hello labels: version: hello # 这里要和hello Deployment的Pod标签完全匹配 - name: howdy labels: version: howdy # 对应howdy Deployment的标签 - 同时检查VirtualService的路由是否正确指向这些子集:
apiVersion: networking.istio.io/v1alpha3 kind: VirtualService metadata: name: greeting spec: hosts: - greeting http: - route: - destination: host: greeting subset: hello weight: 50 - destination: host: greeting subset: howdy weight: 50
最后验证
做完上面的检查调整后,重启相关Deployment,然后可以用以下方式验证:
# 查看Pod的Istio路由配置 istioctl pc routes <hello-pod-name> -o yaml # 发送请求测试流量拆分 curl http://greeting:8081
正常情况下就能看到hello和howdy的结果交替返回了。
内容的提问来源于stack exchange,提问作者Arun Gupta
相关产品推荐
相关产品推荐

