从Nginx Ingress迁移至Istio时出现404错误求助
Let’s break down the common issues that might be causing the 404 error with your Istio setup—since the sample apps work fine, this is almost certainly a configuration gap specific to your Go application.
1. Confirm Istio Sidecar Injection is Active for Your Deployment
Istio relies on its sidecar proxy to route traffic to your pods. If your deployment doesn’t have the sidecar, the ingress gateway can’t reach your app at all.
Check if your pods include the Istio proxy container:
kubectl get pods -l k8s-app=mycustomapp -o jsonpath='{.items[*].spec.containers[*].name}'You should see both
mycustomappandistio-proxylisted here.If the sidecar is missing, enable automatic injection for your namespace:
kubectl label namespace <your-namespace> istio-injection=enabledThen delete and recreate your deployment to trigger injection:
kubectl delete deployment mycustomapp kubectl apply -f your-app-deployment.yamlAlternatively, manually inject the sidecar using
istioctl:istioctl kube-inject -f your-app-deployment.yaml | kubectl apply -f -
2. Fix Istio Ingress Routing with a VirtualService
While Istio 0.7.1 supports Kubernetes Ingress resources, pairing it with an Istio VirtualService often resolves routing ambiguity that causes 404s. Try adding this configuration:
apiVersion: networking.istio.io/v1alpha3 kind: VirtualService metadata: name: mycustomapp-vs spec: hosts: - mycustomapp.mycustomapp.com gateways: - istio-ingressgateway # Uses Istio's default ingress gateway http: - match: - uri: prefix: / route: - destination: host: mycustomapp port: number: 80
Apply it with kubectl apply -f virtualservice.yaml and test your app again.
3. Validate Your Service Configuration
Your service looks mostly correct, but let’s rule out small mismatches:
Confirm your service has active endpoints pointing to your pod:
kubectl get endpoints mycustomappYou should see your pod’s IP listed under the
ENDPOINTScolumn. If not, double-check that the service’s selector (k8s-app: mycustomapp) exactly matches your deployment’s labels.Istio 0.7.x works better with named ports. Update your service to add a port name for HTTP:
spec: ports: - port: 80 targetPort: 80 name: http # Add this line protocol: TCPReapply the service with
kubectl apply -f your-service.yaml.
4. Check Ingress Gateway Logs for Specific Errors
The Istio ingress gateway logs will tell you exactly why it’s returning a 404. Pull the logs with:
kubectl logs -n istio-system $(kubectl get pods -n istio-system -l app=istio-ingressgateway -o jsonpath='{.items[0].metadata.name}')
Look for entries referencing mycustomapp.mycustomapp.com—you might see messages like "no route found" or "destination service unavailable" that pinpoint the issue.
5. Configure TLS (If Using HTTPS)
Your original Nginx Ingress used cert-manager for TLS, but Istio handles TLS differently. If you’re accessing your app over HTTPS, create an Istio Gateway resource to use your existing TLS secret:
apiVersion: networking.istio.io/v1alpha3 kind: Gateway metadata: name: mycustomapp-gateway spec: selector: istio: ingressgateway # Use Istio's default ingress gateway servers: - port: number: 443 name: https protocol: HTTPS tls: mode: SIMPLE credentialName: go-tls # Your existing TLS secret from Nginx hosts: - mycustomapp.mycustomapp.com
Then update your VirtualService to use this gateway instead of the default one by replacing istio-ingressgateway with mycustomapp-gateway.
After working through these steps, your Go app should start responding through the Istio ingress. Let me know if any of these checks reveal the root cause!
内容的提问来源于stack exchange,提问作者J. Doe

