Istio?訪問外部服務(wù)流量控制最常用的5個(gè)技巧示例
環(huán)境準(zhǔn)備
5 個(gè) Istio 訪問外部服務(wù)的流量控制常用例子,強(qiáng)烈建議收藏起來,以備不時(shí)之需。
部署 sleep 服務(wù),作為發(fā)送請求的測試源:
kubectl apply -f samples/sleep/sleep.yaml
在 Istio 外部,使用 Nginx 搭建 duckling 服務(wù)的v1和v2兩個(gè)版本,訪問時(shí)顯示簡單的文本:
> curl -s http://192.168.1.118/ This is the v1 version of duckling. > curl -s http://192.168.1.119/ This is the v2 version of duckling.
訪問外部服務(wù)
執(zhí)行如下命名訪問外部服務(wù) httpbin.org :
export SLEEP_POD=$(kubectl get pods -l app=sleep -o 'jsonpath={.items[0].metadata.name}')
kubectl exec "$SLEEP_POD" -c sleep -- curl -s http://httpbin.org/headers返回結(jié)果如下:
{
"headers": {
"Accept": "*/*",
"Host": "httpbin.org",
"User-Agent": "curl/7.81.0-DEV",
"X-Amzn-Trace-Id": "Root=1-62bbfa10-3237e3b9662c65ae005148ab",
"X-B3-Sampled": "0",
"X-B3-Spanid": "9e650093bf7ae862",
"X-B3-Traceid": "1da46d7fafa5d71c9e650093bf7ae862",
"X-Envoy-Attempt-Count": "1",
"X-Envoy-Peer-Metadata": "......",
"X-Envoy-Peer-Metadata-Id": "sidecar~......"
}
}
此時(shí)的方法,沒有通過Service Entry,沒有 Istio 的流量監(jiān)控和控制特性。創(chuàng)建 Service Entry :
kubectl apply -f - <<EOF
apiVersion: networking.istio.io/v1alpha3
kind: ServiceEntry
metadata:
name: httpbin-ext
spec:
hosts:
- httpbin.org
ports:
- number: 80
name: http
protocol: HTTP
resolution: DNS
location: MESH_EXTERNAL
EOF再此次訪問,返回結(jié)果如下:
{
"headers": {
"Accept": "*/*",
"Host": "httpbin.org",
"User-Agent": "curl/7.81.0-DEV",
"X-Amzn-Trace-Id": "Root=1-62bbfbd6-254b05344b3cde2c0c41b3b8",
"X-B3-Sampled": "0",
"X-B3-Spanid": "307c0b106c8b262e",
"X-B3-Traceid": "f684a50776c088ac307c0b106c8b262e",
"X-Envoy-Attempt-Count": "1",
"X-Envoy-Decorator-Operation": "httpbin.org:80/*",
"X-Envoy-Peer-Metadata": "......",
"X-Envoy-Peer-Metadata-Id": "sidecar~......"
}
}
可以發(fā)現(xiàn)由 Istio 邊車添加的請求頭:X-Envoy-Decorator-Operation。
設(shè)置請求超時(shí)
向外部服務(wù) httpbin.org 的 /delay 發(fā)出請求:
export SLEEP_POD=$(kubectl get pods -l app=sleep -o 'jsonpath={.items[0].metadata.name}')
kubectl exec "$SLEEP_POD" -c sleep -- time curl -o /dev/null -sS -w "%{http_code}\n" http://httpbin.org/delay/5返回結(jié)果如下:
200
real 0m 5.69s
user 0m 0.00s
sys 0m 0.00s
請求大約在 5 秒后返回 200 (OK)。
創(chuàng)建虛擬服務(wù),訪問外部服務(wù) httpbin.org 時(shí), 請求超時(shí)設(shè)置為 3 秒:
kubectl apply -f - <<EOF
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
name: httpbin-ext
spec:
hosts:
- httpbin.org
http:
- timeout: 3s
route:
- destination:
host: httpbin.org
weight: 100
EOF再此次訪問,返回結(jié)果如下:
504
real 0m 3.01s
user 0m 0.00s
sys 0m 0.00s
可以看出,在 3 秒后出現(xiàn)了 504 (Gateway Timeout)。 Istio 在 3 秒后切斷了響應(yīng)時(shí)間為 5 秒的 httpbin.org 服務(wù)。
注入 HTTP 延遲故障
向外部服務(wù) httpbin.org 的 /get 發(fā)出請求:
export SLEEP_POD=$(kubectl get pods -l app=sleep -o 'jsonpath={.items[0].metadata.name}')
kubectl exec "$SLEEP_POD" -c sleep -- time curl -o /dev/null -sS -w "%{http_code}\n" http://httpbin.org/get返回結(jié)果如下:
200
real 0m 0.45s
user 0m 0.00s
sys 0m 0.00s
請求不到 1 秒就返回 200 (OK)。
創(chuàng)建虛擬服務(wù),訪問外部服務(wù) httpbin.org 時(shí), 注入一個(gè) 3 秒的延遲:
kubectl apply -f - <<EOF
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
name: httpbin-ext
spec:
hosts:
- httpbin.org
http:
- fault:
delay:
fixedDelay: 3s
percentage:
value: 100
route:
- destination:
host: httpbin.org
EOF再此次訪問 httpbin.org 的 /get ,返回結(jié)果如下:
200
real 0m 3.43s
user 0m 0.00s
sys 0m 0.00s
可以看出,在 3 秒后出現(xiàn)了 200 (OK)。
流量轉(zhuǎn)移
訪問duckling服務(wù)時(shí),所有流量都路由到v1版本,具體配置如下:
kubectl apply -f - <<EOF
apiVersion: networking.istio.io/v1alpha3
kind: ServiceEntry
metadata:
name: duckling
spec:
hosts:
- duckling.com
ports:
- number: 80
name: http
protocol: HTTP
location: MESH_EXTERNAL
resolution: STATIC
endpoints:
- address: 172.24.29.118
ports:
http: 80
labels:
version: v1
- address: 172.24.29.119
ports:
http: 80
labels:
version: v2
---
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
name: duckling
spec:
hosts:
- duckling.com
http:
- route:
- destination:
host: duckling.com
subset: v1
---
apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
name: duckling
spec:
host: duckling.com
subsets:
- labels:
version: v1
name: v1
- labels:
version: v2
name: v2
EOF執(zhí)行如下命名訪問外部服務(wù) duckling.com :
export SLEEP_POD=$(kubectl get pods -l app=sleep -o 'jsonpath={.items[0].metadata.name}')
kubectl exec "$SLEEP_POD" -c sleep -- curl -s http://duckling.com/多次訪問后,返回結(jié)果一直是:This is the v1 version of duckling.
訪問duckling服務(wù)時(shí),把50%流量轉(zhuǎn)移到v2版本,具體配置如下:
kubectl apply -f - <<EOF
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
name: duckling
spec:
hosts:
- duckling.com
http:
- route:
- destination:
host: duckling.com
subset: v1
weight: 50
- destination:
host: duckling.com
subset: v2
weight: 50
EOF多次訪問外部服務(wù) duckling.com ,有時(shí)返回This is the v1 version of duckling.,有時(shí)返回This is the v2 version of duckling.。
訪問duckling服務(wù)時(shí),所有流量都路由到v2版本,具體配置如下:
kubectl apply -f - <<EOF
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
name: duckling
spec:
hosts:
- duckling.com
http:
- route:
- destination:
host: duckling.com
subset: v2
EOF多次訪問外部服務(wù) duckling.com ,一直返回This is the v2 version of duckling.。
基于請求頭的路由
請求頭end-user為OneMore的所有流量都路由到v2版本,其他流量都路由到v1版本,具體配置如下:
kubectl apply -f - <<EOF
apiVersion: networking.istio.io/v1alpha3
kind: ServiceEntry
metadata:
name: duckling
spec:
hosts:
- duckling.com
ports:
- number: 80
name: http
protocol: HTTP
location: MESH_EXTERNAL
resolution: STATIC
endpoints:
- address: 172.24.29.118
ports:
http: 80
labels:
version: v1
- address: 172.24.29.119
ports:
http: 80
labels:
version: v2
---
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
name: duckling
spec:
hosts:
- duckling.com
http:
- match:
- headers:
end-user:
exact: OneMore
route:
- destination:
host: duckling.com
subset: v2
- route:
- destination:
host: duckling.com
subset: v1
---
apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
name: duckling
spec:
host: duckling.com
subsets:
- labels:
version: v1
name: v1
- labels:
version: v2
name: v2
EOF執(zhí)行如下命名訪問外部服務(wù) duckling.com :
export SLEEP_POD=$(kubectl get pods -l app=sleep -o 'jsonpath={.items[0].metadata.name}')
kubectl exec "$SLEEP_POD" -c sleep -- curl -s http://duckling.com/多次訪問的返回結(jié)果一直是:This is the v1 version of duckling.
設(shè)置請求頭end-user為OneMore,訪問外部服務(wù) duckling.com :
kubectl exec "$SLEEP_POD" -c sleep -- curl -H "end-user:OneMore" -s http://duckling.com/
多次訪問的返回結(jié)果一直是:This is the v2 version of duckling.
以上就是5個(gè) Istio 訪問外部服務(wù)流量控制最常用的例子的詳細(xì)內(nèi)容,更多關(guān)于Istio 訪問外部服務(wù)流量控制的資料請關(guān)注腳本之家其它相關(guān)文章!
相關(guān)文章
詳解git使用小結(jié)(本地分支與遠(yuǎn)程分支、git命令)
這篇文章主要介紹了git使用小結(jié)(本地分支與遠(yuǎn)程分支、git命令),本文給大家介紹的非常詳細(xì),對大家的學(xué)習(xí)或工作具有一定的參考借鑒價(jià)值,需要的朋友可以參考下2020-08-08
如何解決vscode中ESLint和prettier沖突問題
這篇文章主要給大家介紹了關(guān)于如何解決vscode中ESLint和prettier沖突問題的相關(guān)資料,ESLint和Prettier之間可能會(huì)發(fā)生沖突,因?yàn)樗鼈兌际怯糜诖a規(guī)范化的工具,但它們的規(guī)則和格式化方式可能不同,需要的朋友可以參考下2023-11-11
使用Git Hook技術(shù)定義和校驗(yàn)代碼提交模板方式
這篇文章主要介紹了使用Git Hook技術(shù)定義和校驗(yàn)代碼提交模板方式,具有很好的參考價(jià)值,希望對大家有所幫助,如有錯(cuò)誤或未考慮完全的地方,望不吝賜教2023-11-11

