You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Istio与Kubernetes时流量拆分出现健康上游异常问题

排查Istio流量拆分中"no healthy upstream"问题的步骤

兄弟,我之前在Istio做流量拆分时也踩过一模一样的坑,咱们一步步来定位解决:

1. 先核对Service与Deployment的标签匹配逻辑

你的greeting Service用了app: greeting作为selector,这是流量能转发到Pod的核心前提!你得立刻确认hello Deployment的Pod标签是否完全匹配这个selector:

  • 执行命令查看两个Deployment的标签配置:
    kubectl get deployments hello howdy -o yaml | grep -A 5 "labels"
    
  • 如果hello的Pod标签里没有app: greeting,赶紧修改它的Deployment配置,在spec.template.metadata.labels里加上这个标签——只有标签匹配,Service才能把流量导向它的Pod。

2. 确认Istio Sidecar是否注入到hello的Pod中

Istio是靠sidecar容器管理Pod流量的,如果hello的Pod没注入istio-proxy,Istio根本识别不到这个服务的存在:

  • 检查Pod的容器列表,确认包含istio-proxy:
    kubectl get pods -l app=greeting -o jsonpath='{.items[*].spec.containers[*].name}' | tr ' ' '\n'
    
  • 如果没有注入,要么给当前命名空间开启自动注入:
    kubectl label namespace <你的命名空间> istio-injection=enabled
    
    要么手动给hello的Deployment添加注入注解,然后重启Deployment生效:
    metadata:
      annotations:
        sidecar.istio.io/inject: "true"
    

3. 检查Pod的健康探针配置

Istio会依赖K8s的健康探针判断Pod是否可用,如果hello的Pod没配置Liveness/Readiness探针,或者探针失败,Istio会直接标记它为"不健康上游":

  • 查看Pod的健康状态:
    kubectl describe pods -l app=greeting | grep -A 10 "Conditions"
    
  • 确保Ready状态是True,如果不是,给hello的Deployment补上正确的探针配置,比如:
    spec:
      template:
        spec:
          containers:
          - name: hello
            livenessProbe:
              httpGet:
                path: /health
                port: 8081
              initialDelaySeconds: 5
              periodSeconds: 5
            readinessProbe:
              httpGet:
                path: /health
                port: 8081
              initialDelaySeconds: 5
              periodSeconds: 5
    

4. 验证DestinationRule的子集配置

如果你的VirtualService是按subset拆分流量,那DestinationRule必须正确定义两个子集,且标签要精准匹配对应的Deployment:

  • 正确的DestinationRule示例应该是这样的:
    apiVersion: networking.istio.io/v1alpha3
    kind: DestinationRule
    metadata:
      name: greeting
    spec:
      host: greeting
      subsets:
      - name: hello
        labels:
          version: hello  # 这里要和hello Deployment的Pod标签完全匹配
      - name: howdy
        labels:
          version: howdy  # 对应howdy Deployment的标签
    
  • 同时检查VirtualService的路由是否正确指向这些子集:
    apiVersion: networking.istio.io/v1alpha3
    kind: VirtualService
    metadata:
      name: greeting
    spec:
      hosts:
      - greeting
      http:
      - route:
        - destination:
            host: greeting
            subset: hello
          weight: 50
        - destination:
            host: greeting
            subset: howdy
          weight: 50
    

最后验证

做完上面的检查调整后,重启相关Deployment,然后可以用以下方式验证:

# 查看Pod的Istio路由配置
istioctl pc routes <hello-pod-name> -o yaml
# 发送请求测试流量拆分
curl http://greeting:8081

正常情况下就能看到hello和howdy的结果交替返回了。

内容的提问来源于stack exchange,提问作者Arun Gupta

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 04:15:06