InvalidExternalControlPlaneConfig

消息名称InvalidExternalControlPlaneConfig
消息代码IST0163
描述Address for the ingress gateway on the external control plane is not valid
等级Warning

当为外部控制平面上的入口网关提供的地址无效时,会出现此消息。 该地址可能因多种原因而无效,包括:主机名地址格式错误、 主机名无法通过 DNS 查询解析为 IP 地址或者主机名解析出的 IP 地址数为零。

示例

当集群的 ValidatingWebhookConfigurationMutatingWebhookConfiguration (为清楚起见而缩短)缺少 Webhook URL 时:

  1. apiVersion: admissionregistration.k8s.io/v1
  2. kind: ValidatingWebhookConfiguration
  3. metadata:
  4. name: istio-validator-external-istiod
  5. webhooks:
  6. - admissionReviewVersions:
  7. - v1beta1
  8. - v1
  9. clientConfig:
  10. url:
  11. name: rev.validation.istio.io
  12. ---
  13. apiVersion: admissionregistration.k8s.io/v1
  14. kind: ValidatingWebhookConfiguration
  15. metadata:
  16. name: istiod-default-validator
  17. webhooks:
  18. - admissionReviewVersions:
  19. - v1beta1
  20. - v1
  21. clientConfig:
  22. url: https://test.com:15017/validate
  23. failurePolicy: Ignore
  24. name: validation.istio.io
  25. ---
  26. apiVersion: admissionregistration.k8s.io/v1
  27. kind: MutatingWebhookConfiguration
  28. metadata:
  29. name: istio-sidecar-injector-external-istiod
  30. webhooks:
  31. - admissionReviewVersions:
  32. - v1beta1
  33. - v1
  34. clientConfig:
  35. url:
  36. failurePolicy: Fail
  37. name: rev.namespace.sidecar-injector.istio.io
  38. - admissionReviewVersions:
  39. - v1beta1
  40. - v1
  41. clientConfig:
  42. url: https://test.com/inject/cluster/your-cluster-name/net/network1
  43. failurePolicy: Fail
  44. name: rev.object.sidecar-injector.istio.io
  45. - admissionReviewVersions:
  46. - v1beta1
  47. - v1
  48. clientConfig:
  49. url: https://test.com/inject/cluster/your-cluster-name/net/network1
  50. failurePolicy: Fail
  51. name: namespace.sidecar-injector.istio.io
  52. - admissionReviewVersions:
  53. - v1beta1
  54. - v1
  55. clientConfig:
  56. url: https://test.com/inject/cluster/your-cluster-name/net/network1
  57. failurePolicy: Fail
  58. name: object.sidecar-injector.istio.io

您将收到此消息:

  1. Warning [IST0163] (MutatingWebhookConfiguration istio-sidecar-injector-external-istiod testing.yml:28) The hostname () that was provided for the webhook (rev.namespace.sidecar-injector.istio.io) to reach the ingress gateway on the external control plane cluster is blank. Traffic may not flow properly.
  2. Warning [IST0163] (ValidatingWebhookConfiguration istio-validator-external-istiod testing.yml:1) The hostname () that was provided for the webhook (rev.validation.istio.io) to reach the ingress gateway on the external control plane cluster is blank. Traffic may not flow properly.

当集群的 ValidatingWebhookConfigurationMutatingWebhookConfiguration (为清楚起见而缩短)所使用的主机名在 DNS 查询期间无法被解析时:

  1. apiVersion: admissionregistration.k8s.io/v1
  2. kind: ValidatingWebhookConfiguration
  3. metadata:
  4. name: istio-validator-external-istiod
  5. webhooks:
  6. - admissionReviewVersions:
  7. - v1beta1
  8. - v1
  9. clientConfig:
  10. url: https://thisisnotarealdomainname.com:15017/validate
  11. name: rev.validation.istio.io
  12. ---
  13. apiVersion: admissionregistration.k8s.io/v1
  14. kind: ValidatingWebhookConfiguration
  15. metadata:
  16. name: istiod-default-validator
  17. webhooks:
  18. - admissionReviewVersions:
  19. - v1beta1
  20. - v1
  21. clientConfig:
  22. url: https://test.com:15017/validate
  23. failurePolicy: Ignore
  24. name: validation.istio.io
  25. ---
  26. apiVersion: admissionregistration.k8s.io/v1
  27. kind: MutatingWebhookConfiguration
  28. metadata:
  29. name: istio-sidecar-injector-external-istiod
  30. webhooks:
  31. - admissionReviewVersions:
  32. - v1beta1
  33. - v1
  34. clientConfig:
  35. url: https://test.com/inject/cluster/your-cluster-name/net/network1
  36. failurePolicy: Fail
  37. name: rev.namespace.sidecar-injector.istio.io
  38. - admissionReviewVersions:
  39. - v1beta1
  40. - v1
  41. clientConfig:
  42. url: https://test.com/inject/cluster/your-cluster-name/net/network1
  43. failurePolicy: Fail
  44. name: rev.object.sidecar-injector.istio.io
  45. - admissionReviewVersions:
  46. - v1beta1
  47. - v1
  48. clientConfig:
  49. url: https://test.com/inject/cluster/your-cluster-name/net/network1
  50. failurePolicy: Fail
  51. name: namespace.sidecar-injector.istio.io
  52. - admissionReviewVersions:
  53. - v1beta1
  54. - v1
  55. clientConfig:
  56. url: https://test.com/inject/cluster/your-cluster-name/net/network1
  57. failurePolicy: Fail
  58. name: object.sidecar-injector.istio.io

您将收到此消息:

  1. Warning [IST0163] (ValidatingWebhookConfiguration istio-validator-external-istiod testing.yml:1) The hostname (https://thisisnotarealdomainname.com:15017/validate) that was provided for the webhook (rev.validation.istio.io) to reach the ingress gateway on the external control plane cluster cannot be resolved via a DNS lookup. Traffic may not flow properly.

如何修复

有多种方法可以解决这些无效配置,具体取决于配置无效的原因。

如果您的 Webhook 配置未定义 URL, 则添加使用主机名的有效 URL 将解决此警告消息。 有关如何执行此操作的说明可以在此处找到。

如果您的主机名无法通过 DNS 查找解析为 IP 地址, 您可以尝试在本地计算机上运行 dig <your-hostname> 来查看是否触发 DNS 解析。如果您的本地计算机可以通过 DNS 查询来解析主机名, 那可能是您的集群不能解析此主机名。任何阻止 DNS 流量的安全规则都可能导致解析查询失败。 新的 DNS 记录可能需要长达 72 小时才能在网络上传播, 具体取决于您的 DNS 提供商和具体配置。

如果您的主机名解析为 0 个 IP 地址,请检查 Webhook URL 是否使用正确的主机名,以及您的 DNS 提供商是否正确地拥有至少一个可供您的主机名解析的 IP 地址。