问题描述
我正在尝试在Ingressgateway的端口443上设置SSL。我可以使用非常基本的设置持续进行复制。我知道这可能是我做错了,但还没弄清楚。
我的k8s集群在EKS上运行。 k version 1.19
我使用AWS Certificate Manager为域api.foo.com
和其他名称*.api.foo.com
创建了一个证书
证书已成功创建,并且具有ARN arn:aws:acm:us-west-2:<some-numbers>:certificate/<id>
然后,我进行了istio的原始安装:
istioctl install --set meshConfig.accessLogFile=/dev/stdout
使用版本:
client version: 1.7.0
control plane version: 1.7.0
这是我的网关定义:
apiVersion: networking.istio.io/v1alpha3
kind: Gateway
Metadata:
name: foo-gateway
annotations:
service.beta.kubernetes.io/aws-load-balancer-ssl-cert: "arn:aws:acm:us-west-2:<some-numbers>:certificate/<id>"
service.beta.kubernetes.io/aws-load-balancer-backend-protocol: tcp
service.beta.kubernetes.io/aws-load-balancer-ssl-ports: "https"
service.beta.kubernetes.io/aws-load-balancer-connection-idle-timeout: "60"
service.beta.kubernetes.io/aws-load-balancer-type: "elb"
spec:
selector:
istio: ingressgateway
servers:
- port:
number: 80
name: http
protocol: HTTP
hosts:
- "*"
- port:
number: 443
name: https-443
protocol: HTTP
hosts:
- "*"
请注意,端口443具有HTTP协议,我不认为这是问题所在(因为我想使用SSL终止)。另外,即使我将其更改为HTTPS,也可以得到此信息:
Resource: "networking.istio.io/v1alpha3,Resource=gateways",GroupVersionKind: "networking.istio.io/v1alpha3,Kind=Gateway"
Name: "foo-gateway",Namespace: "default"
for: "foo-gateway.yaml": admission webhook "validation.istio.io" denied the request: configuration is invalid: server must have TLS settings for HTTPS/TLS protocols
但是,tls设置是什么?我需要通过未放在/etc
中的注释(从AWS CM)中获取证书密钥。顺便说一句,有没有办法在没有ssl终止的情况下做到这一点?
我的VirtualService定义是这样的:
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
Metadata:
name: foo-api
spec:
hosts:
- "*"
gateways:
- foo-gateway
http:
- match:
- uri:
prefix: /users
route:
- destination:
host: https-user-manager
port:
number: 7070
然后,我在端口7070上k apply -f
一个名为https-user-manager
的超简单REST服务。然后,我从k get svc -n istio-system
找到负载均衡器的主机名,结果为:
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
istio-ingressgateway LoadBalancer <cluster-ip> blahblahblah.us-west-2.elb.amazonaws.com 15021:30048/TCP,80:30210/TCP,443:31349/TCP,15443:32587/TCP 32m
我可以像这样成功使用http:
curl http://blahblahblah.us-west-2.elb.amazonaws.com/users
并获得有效的回复
但是如果我这样做:
curl -vi https://blahblahblah.us-west-2.elb.amazonaws.com/users
我得到以下信息:
* Trying <ip>...
* TCP_NODELAY set
* Connected to api.foo.com (<ip>) port 443 (#0)
* ALPN,offering h2
* ALPN,offering http/1.1
* successfully set certificate verify locations:
* CAfile: /etc/ssl/cert.pem
CApath: none
* TLSv1.2 (OUT),TLS handshake,Client hello (1):
* error:1400410B:SSL routines:CONNECT_CR_SRVR_HELLO:wrong version number
* Closing connection 0
curl: (35) error:1400410B:SSL routines:CONNECT_CR_SRVR_HELLO:wrong version number
我在做什么错?我看过这些https://medium.com/faun/managing-tls-keys-and-certs-in-istio-using-amazons-acm-8ff9a0b99033,Istio-ingressgateway with https - Connection refused,Setting up istio ingressgateway,SSL Error - wrong version number (HTTPS to HTTP),Updating Istio-IngressGateway TLS Cert,https://github.com/kubernetes/ingress-nginx/issues/3556,https://github.com/istio/istio/issues/14264,{{3} },https://preliminary.istio.io/latest/docs/tasks/traffic-management/ingress/secure-ingress/等许多我什至不记得的内容。不胜感激!
解决方法
暂无找到可以解决该程序问题的有效方法,小编努力寻找整理中!
如果你已经找到好的解决方法,欢迎将解决方案带上本链接一起发送给小编。
小编邮箱:dio#foxmail.com (将#修改为@)