You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为私有AKS中带Istio的Document Intelligence容器配置APIM动态路由及头重写

问题:Azure APIM 路由到Istio服务并重写Document Intelligence异步响应头

环境配置

  • AKS:启用Istio边车注入的私有集群
  • 容器:每个Azure AI Document Intelligence模型(Layout、Invoice、ID等)对应独立部署/服务,通过Istio内部FQDN暴露(如layout.myservices.mydomain.com、invoice.myservices.mydomain.com)
  • APIM:部署在关联虚拟网络中,作为内部消费者的唯一入口

目标

  • 在APIM中创建统一API,根据URL路径中的{model}段动态路由到对应Istio内部服务
  • 重写异步请求返回的Operation-Location响应头,将内部Kubernetes URL替换为APIM公共地址,使客户端通过APIM轮询结果

遇到的问题

  • 使用<set-backend-service>时干扰Istio对Host头的预期,导致路由异常
  • 出站策略中的正则表达式未正确替换Operation-Location中的内部URL,客户端仍收到原地址

可行APIM策略片段

以下策略可解决动态路由和响应头重写问题,同时适配Istio的Host头要求:

<policies>
    <inbound>
        <!-- 从URL路径提取model参数(假设API路径为 /doc-intel/{model}/...) -->
        <set-variable name="modelName" value="@(context.Request.MatchedParameters["model"])" />
        
        <!-- 动态构造对应Istio服务的FQDN -->
        <set-variable name="backendFqdn" value="@($"{(string)context.Variables["modelName"]}.myservices.mydomain.com")" />
        
        <!-- 设置后端服务地址,同时显式指定Host头为Istio服务FQDN,满足Istio路由要求 -->
        <set-backend-service base-url="@($"http://{(string)context.Variables["backendFqdn"]}:5000")" />
        <set-header name="Host" exists-action="override">
            <value>@((string)context.Variables["backendFqdn"])</value>
        </set-header>
        
        <!-- 移除APIM的API前缀,将原始请求路径转发给后端服务 -->
        <rewrite-uri template="@(context.Request.Url.Path.Replace($"/doc-intel/{(string)context.Variables["modelName"]}", ""))" />
    </inbound>
    <backend>
        <forward-request />
    </backend>
    <outbound>
        <!-- 正则匹配并替换Operation-Location中的内部URL -->
        <find-and-replace from="http://([a-z]+)\.myservices\.mydomain\.com:5000(.*)" to="https://my-apim.azure-api.net/doc-intel/$1$2" />
        
        <!-- 兜底替换,确保所有内部URL都被转换为APIM地址 -->
        <set-header name="Operation-Location" exists-action="override">
            <value>@(context.Response.Headers.GetValueOrDefault("Operation-Location", "")
                .Replace("http://layout.myservices.mydomain.com:5000", "https://my-apim.azure-api.net/doc-intel/layout")
                .Replace("http://invoice.myservices.mydomain.com:5000", "https://my-apim.azure-api.net/doc-intel/invoice")
                .Replace("http://id.myservices.mydomain.com:5000", "https://my-apim.azure-api.net/doc-intel/id"))</value>
        </set-header>
    </outbound>
    <on-error>
        <base />
    </on-error>
</policies>

策略关键点说明

  1. 动态路由适配Istio:

    • 提取路径中的{model}参数构造对应服务的FQDN
    • 显式设置Host头为Istio服务的FQDN,避免<set-backend-service>默认修改Host头导致Istio路由失败
    • 重写URI移除APIM的API前缀,确保后端服务收到正确的请求路径
  2. 响应头重写:

    • 先用正则表达式批量匹配替换内部URL格式
    • 再用逐个替换做兜底,覆盖所有可能的模型服务地址,确保Operation-Location完全转换为APIM公共地址

内容的提问来源于stack exchange,提问作者Vowneee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.11 20:12:38