Istio DestinationRule在标头之前给出上游连接错误或断开连接/重置

时间:2018-11-01 15:07:14

标签: kubernetes google-kubernetes-engine istio

我尝试以lb的比率获得在部署在Google Cloud Kubernetes集群上的2个应用之间的一些基本路由,并且我有以下配置:

apiVersion: v1
kind: Service
metadata:
  name: kubeapp
  labels:
    app: kubeapp
spec:
  ports:
  - port: 8080
    name: http
  selector:
    app: kubeapp
---
apiVersion: extensions/v1beta1
kind: Deployment
metadata:
  name: kubeapp-v1
spec:
  replicas: 1
  template:
    metadata:
      labels:
        app: kubeapp
        version: kubeapp-v1
    spec:
      containers:
      - name: kubeapp-v1
        image: .......
        ports:
        - name: kubeapp-v1
          containerPort: 8080
---
apiVersion: extensions/v1beta1
kind: Deployment
metadata:
  name: kubeapp-v2
spec:
  replicas: 1
  template:
    metadata:
      labels:
        app: kubeapp
        version: kubeapp-v2
    spec:
      containers:
      - name: kubeapp-v2
        image: .......
        ports:
        - name: kubeapp-v2
          containerPort: 8080
---
apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name: kubeapp-gateway
spec:
  selector:
    istio: ingressgateway # use istio default controller
  servers:
  - port:
      number: 80
      name: http
      protocol: HTTP
    hosts:
    - "*"
---
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: kubeapp
spec:
  hosts:
  - "*"
  gateways:
  - kubeapp-gateway
  http:
  - route:
    - destination:
        host: kubeapp
        port: 8080

效果很好,流量达到50/50,但是当我尝试为lb添加一些基本规则时,例如:

apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: kubeapp
spec:
  hosts:
  - "*"
  gateways:
  - kubeapp-gateway
  http:
  - route:
    - destination:
        host: kubeapp
        port:
          number: 8080
        subset: kubeapp-v1
      weight: 90
    - destination:
        host: kubeapp
        port:
          number: 8080
        subset: kubeapp-v2
      weight: 10
---
apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
  name: kubeapp
spec:
  host: kubeapp
  subsets:
  - name: kubeapp-v1
    labels:
      version: kubeapp-v1
  - name: kubeapp-v2
    labels:
      version: kubeapp-v2

我得到了upstream connect error or disconnect/reset before headers

我尝试以所有3种模式安装Istio,并将其部署在不同的群集节点大小上(我发现有时Istio在某些特定群集大小上存在一些错误),但没有成功。

1 个答案:

答案 0 :(得分:2)

此类问题的一个很常见的原因是DestinationRule导致了mTLS冲突。该问题已记录在here中。