查看Istio容器日志信息

pod内容器

➜  ~kubectl logs productpage-v1-65576bb7bf-rcnfr 

error: a container name must be specified for pod productpage-v1-65576bb7bf-rcnfr, choose one of: [productpage istio-proxy] or one of the init containers: [istio-init]

istio-proxy 

➜  ~ kubectl logs productpage-v1-65576bb7bf-rcnfr -c istio-proxy
2021-09-23T02:52:11.293116Z	info	FLAG: --concurrency="2"
2021-09-23T02:52:11.293140Z	info	FLAG: --domain="default.svc.cluster.local"
2021-09-23T02:52:11.293145Z	info	FLAG: --help="false"
2021-09-23T02:52:11.293148Z	info	FLAG: --log_as_json="false"
2021-09-23T02:52:11.293150Z	info	FLAG: --log_caller=""
2021-09-23T02:52:11.293152Z	info	FLAG: --log_output_level="default:info"
2021-09-23T02:52:11.293155Z	info	FLAG: --log_rotate=""
2021-09-23T02:52:11.293157Z	info	FLAG: --log_rotate_max_age="30"
2021-09-23T02:52:11.293159Z	info	FLAG: --log_rotate_max_backups="1000"
2021-09-23T02:52:11.293162Z	info	FLAG: --log_rotate_max_size="104857600"
2021-09-23T02:52:11.293164Z	info	FLAG: --log_stacktrace_level="default:none"
2021-09-23T02:52:11.293169Z	info	FLAG: --log_target="[stdout]"
2021-09-23T02:52:11.293172Z	info	FLAG: --meshConfig="./etc/istio/config/mesh"
2021-09-23T02:52:11.293174Z	info	FLAG: --outlierLogPath=""
2021-09-23T02:52:11.293176Z	info	FLAG: --proxyComponentLogLevel="misc:error"
2021-09-23T02:52:11.293178Z	info	FLAG: --proxyLogLevel="warning"
2021-09-23T02:52:11.293181Z	info	FLAG: --serviceCluster="productpage.default"
2021-09-23T02:52:11.293183Z	info	FLAG: --stsPort="0"
2021-09-23T02:52:11.293185Z	info	FLAG: --templateFile=""
2021-09-23T02:52:11.293188Z	info	FLAG: --tokenManagerPlugin="GoogleTokenExchange"
2021-09-23T02:52:11.293205Z	info	Version 1.8.2-bfa8bcbc116a8736c301a5dfedc4ed2673e2bfa3-Clean
2021-09-23T02:52:11.293531Z	info	Obtained private IP [10.244.1.11 fe80::b4d3:afff:fea9:1988]
2021-09-23T02:52:11.293618Z	info	Apply proxy config from env {"proxyMetadata":{"DNS_AGENT":""}}

2021-09-23T02:52:11.295330Z	info	Effective config: binaryPath: /usr/local/bin/envoy
concurrency: 2
configPath: ./etc/istio/proxy
controlPlaneAuthPolicy: MUTUAL_TLS
discoveryAddress: istiod.istio-system.svc:15012
drainDuration: 45s
envoyAccessLogService: {}
envoyMetricsService: {}
parentShutdownDuration: 60s
proxyAdminPort: 15000
proxyMetadata:
  DNS_AGENT: ""
serviceCluster: productpage.default
statNameLength: 189
statusPort: 15020
terminationDrainDuration: 5s
tracing:
  zipkin:
    address: zipkin.istio-system:9411

2021-09-23T02:52:11.295396Z	info	Proxy role: &model.Proxy{RWMutex:sync.RWMutex{w:sync.Mutex{state:0, sema:0x0}, writerSem:0x0, readerSem:0x0, readerCount:0, readerWait:0}, Type:"sidecar", IPAddresses:[]string{"10.244.1.11", "fe80::b4d3:afff:fea9:1988"}, ID:"productpage-v1-65576bb7bf-rcnfr.default", Locality:(*envoy_config_core_v3.Locality)(nil), DNSDomain:"default.svc.cluster.local", ConfigNamespace:"", Metadata:(*model.NodeMetadata)(nil), SidecarScope:(*model.SidecarScope)(nil), PrevSidecarScope:(*model.SidecarScope)(nil), MergedGateway:(*model.MergedGateway)(nil), ServiceInstances:[]*model.ServiceInstance(nil), IstioVersion:(*model.IstioVersion)(nil), VerifiedIdentity:(*spiffe.Identity)(nil), ipv6Support:false, ipv4Support:false, GlobalUnicastIP:"", XdsResourceGenerator:model.XdsResourceGenerator(nil), WatchedResources:map[string]*model.WatchedResource(nil)}
2021-09-23T02:52:11.295414Z	info	JWT policy is third-party-jwt
2021-09-23T02:52:11.295442Z	info	PilotSAN []string{"istiod.istio-system.svc"}
2021-09-23T02:52:11.295495Z	info	sa.serverOptions.CAEndpoint == istiod.istio-system.svc:15012 Citadel
2021-09-23T02:52:11.295581Z	info	Using CA istiod.istio-system.svc:15012 cert with certs: var/run/secrets/istio/root-cert.pem
2021-09-23T02:52:11.295693Z	info	citadelclient	Citadel client using custom root: istiod.istio-system.svc:15012 -----BEGIN CERTIFICATE-----
MIIC/TCCAeWgAwIBAgIRAOYOpkjwEDCsYkyLt1JY6rkwDQYJKoZIhvcNAQELBQAw
GDEWMBQGA1UEChMNY2x1c3Rlci5sb2NhbDAeFw0yMTA5MTAxMzUzMThaFw0zMTA5
MDgxMzUzMThaMBgxFjAUBgNVBAoTDWNsdXN0ZXIubG9jYWwwggEiMA0GCSqGSIb3
DQEBAQUAA4IBDwAwggEKAoIBAQC2B2ql/f3tZqnyLJ86NYtcpkMWux379jCl3sUb
0Lf3hqd2wD6VtnQpAuHO42PXacS56hiNJGwdkhU/Z8zlhFc58vGWeOShT5C8jLrC
z//9TjTsfvGUS4REjQ13O4QGQyHtYnjJZx47HJr7m4estVOLbaqmjMNkD1cpGpHR
3tv3LRMuqPQERx2RxVBIp5P1UD7kgyzWb2dOFzqmE5gYeCfoxc6E003rXyd5u4UU
C9D5lwGmSPICLKXFBgegrEd1A1JdmQKHC5urrykVpn70mwMZzAY2PHNc353CJdSD
Zk3dvMvc0/3KJdeXZijx4B8VgyTJyBrSdunJZGDh/N7gVDqTAgMBAAGjQjBAMA4G
A1UdDwEB/wQEAwICBDAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBRkc4FW0Drr
w/ux1836u3Wv1agGYTANBgkqhkiG9w0BAQsFAAOCAQEAVJkrYH8hvditinreypWI
+hNJBMGk5BeeYZGAAyRVCgmA2tuMIvy6Pd0O/VtM6CZDJq1ChHm/oHk9i3ScdMS7
2qCN9Jvgr9OQ/hehESqCDPwP81FqhpWK4d0P+8WGwpVuQF0WRZFa8RvAr8rWypz5
ouTB6yZJ5wdlH8FG51YRSCgeHQ3+VpeCF8/CLu5RghGYGgArATjf+zicegCvIemI
1p7NdrcfptXmhUkqiax7ePJuj4D1svrcKAJtIZJ+ocgNhwl/Uhb9Cz5l7TXUKqhN
56iNXtTfotqodlbAtgu033aMAdFny461CxuKyBi80mZq5OAE6AHRbndM0PcYWWHy
7A==
-----END CERTIFICATE-----

2021-09-23T02:52:11.334052Z	info	sds	SDS gRPC server for workload UDS starts, listening on "./etc/istio/proxy/SDS" 

2021-09-23T02:52:11.334321Z	info	xdsproxy	Initializing with upstream address istiod.istio-system.svc:15012 and cluster Kubernetes
2021-09-23T02:52:11.334265Z	info	sds	Start SDS grpc server
2021-09-23T02:52:11.334695Z	info	xdsproxy	adding watcher for certificate var/run/secrets/istio/root-cert.pem
2021-09-23T02:52:11.334927Z	info	Starting proxy agent
2021-09-23T02:52:11.335076Z	info	Opening status port 15020

2021-09-23T02:52:11.335241Z	info	Received new config, creating new Envoy epoch 0
2021-09-23T02:52:11.335322Z	info	Epoch 0 starting
2021-09-23T02:52:11.343146Z	info	Envoy command: [-c etc/istio/proxy/envoy-rev0.json --restart-epoch 0 --drain-time-s 45 --parent-shutdown-time-s 60 --service-cluster productpage.default --service-node sidecar~10.244.1.11~productpage-v1-65576bb7bf-rcnfr.default~default.svc.cluster.local --local-address-ip-version v4 --bootstrap-version 3 --log-format-prefix-with-location 0 --log-format %Y-%m-%dT%T.%fZ	%l	envoy %n	%v -l warning --component-log-level misc:error --concurrency 2]
2021-09-23T02:52:11.412475Z	warning	envoy runtime	Unable to use runtime singleton for feature envoy.http.headermap.lazy_map_min_size
2021-09-23T02:52:11.412672Z	warning	envoy runtime	Unable to use runtime singleton for feature envoy.http.headermap.lazy_map_min_size
2021-09-23T02:52:11.413442Z	warning	envoy runtime	Unable to use runtime singleton for feature envoy.http.headermap.lazy_map_min_size
2021-09-23T02:52:11.413569Z	warning	envoy runtime	Unable to use runtime singleton for feature envoy.http.headermap.lazy_map_min_size
2021-09-23T02:52:11.454710Z	warning	envoy main	there is no configured limit to the number of allowed active connections. Set a limit via the runtime key overload.global_downstream_max_connections
2021-09-23T02:52:11.455704Z	info	xdsproxy	Envoy ADS stream established
2021-09-23T02:52:11.455949Z	info	xdsproxy	connecting to upstream XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:11.473271Z	error	xdsproxy	failed to create upstream grpc client: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:11.473379Z	info	xdsproxy	disconnected from XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:11.474501Z	warning	envoy config	StreamAggregatedResources gRPC config stream closed: 14, connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:11.795970Z	info	xdsproxy	Envoy ADS stream established
2021-09-23T02:52:11.796062Z	info	xdsproxy	connecting to upstream XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:11.805039Z	error	xdsproxy	failed to create upstream grpc client: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:11.805183Z	info	xdsproxy	disconnected from XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:11.805472Z	warning	envoy config	StreamAggregatedResources gRPC config stream closed: 14, connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:12.611766Z	info	xdsproxy	Envoy ADS stream established
2021-09-23T02:52:12.611860Z	info	xdsproxy	connecting to upstream XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:12.616565Z	warning	envoy config	StreamAggregatedResources gRPC config stream closed: 14, connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:12.616339Z	error	xdsproxy	failed to create upstream grpc client: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:12.616351Z	info	xdsproxy	disconnected from XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:14.603617Z	info	xdsproxy	Envoy ADS stream established
2021-09-23T02:52:14.604067Z	info	xdsproxy	connecting to upstream XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:14.636949Z	error	xdsproxy	failed to create upstream grpc client: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:14.636970Z	info	xdsproxy	disconnected from XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:14.637360Z	warning	envoy config	StreamAggregatedResources gRPC config stream closed: 14, connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:15.699301Z	info	xdsproxy	Envoy ADS stream established
2021-09-23T02:52:15.699514Z	info	xdsproxy	connecting to upstream XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:15.706515Z	error	xdsproxy	failed to create upstream grpc client: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:15.706534Z	info	xdsproxy	disconnected from XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:15.706709Z	warning	envoy config	StreamAggregatedResources gRPC config stream closed: 14, connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:20.503604Z	info	xdsproxy	Envoy ADS stream established
2021-09-23T02:52:20.503706Z	info	xdsproxy	connecting to upstream XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:20.586429Z	error	xdsproxy	failed to create upstream grpc client: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:20.586451Z	info	xdsproxy	disconnected from XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:20.598527Z	warning	envoy config	StreamAggregatedResources gRPC config stream closed: 14, connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:24.727314Z	info	xdsproxy	Envoy ADS stream established
2021-09-23T02:52:24.727920Z	info	xdsproxy	connecting to upstream XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:30.771217Z	error	xdsproxy	failed to create upstream grpc client: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial tcp 10.96.68.72:15012: connect: connection refused"
2021-09-23T02:52:30.771238Z	info	xdsproxy	disconnected from XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:30.774174Z	warning	envoy config	StreamAggregatedResources gRPC config stream closed: 14, connection error: desc = "transport: Error while dialing dial tcp 10.96.68.72:15012: connect: connection refused"
2021-09-23T02:52:42.907758Z	warn	Envoy proxy is NOT ready: config not received from Pilot (is Pilot running?): cds updates: 0 successful, 0 rejected; lds updates: 0 successful, 0 rejected
2021-09-23T02:52:44.913337Z	warn	Envoy proxy is NOT ready: config not received from Pilot (is Pilot running?): cds updates: 0 successful, 0 rejected; lds updates: 0 successful, 0 rejected
2021-09-23T02:52:46.905358Z	warn	Envoy proxy is NOT ready: config not received from Pilot (is Pilot running?): cds updates: 0 successful, 0 rejected; lds updates: 0 successful, 0 rejected
2021-09-23T02:52:48.907121Z	warn	Envoy proxy is NOT ready: config not received from Pilot (is Pilot running?): cds updates: 0 successful, 0 rejected; lds updates: 0 successful, 0 rejected
2021-09-23T02:52:50.920121Z	warn	Envoy proxy is NOT ready: config not received from Pilot (is Pilot running?): cds updates: 0 successful, 0 rejected; lds updates: 0 successful, 0 rejected
2021-09-23T02:52:52.059419Z	info	xdsproxy	Envoy ADS stream established
2021-09-23T02:52:52.059644Z	info	xdsproxy	connecting to upstream XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:52.117894Z	warning	envoy filter	mTLS PERMISSIVE mode is used, connection can be either plaintext or TLS, and client cert can be omitted. Please consider to upgrade to mTLS STRICT mode for more secure configuration that only allows TLS connection with client cert. See https://istio.io/docs/tasks/security/mtls-migration/
2021-09-23T02:52:52.119033Z	warning	envoy filter	mTLS PERMISSIVE mode is used, connection can be either plaintext or TLS, and client cert can be omitted. Please consider to upgrade to mTLS STRICT mode for more secure configuration that only allows TLS connection with client cert. See https://istio.io/docs/tasks/security/mtls-migration/
2021-09-23T02:52:52.124293Z	info	sds	resource:ROOTCA new connection
2021-09-23T02:52:52.124418Z	info	sds	Skipping waiting for gateway secret
2021-09-23T02:52:52.125335Z	info	sds	resource:default new connection
2021-09-23T02:52:52.125449Z	info	sds	Skipping waiting for gateway secret
2021-09-23T02:52:52.192179Z	info	cache	Root cert has changed, start rotating root cert for SDS clients
2021-09-23T02:52:52.192204Z	info	cache	GenerateSecret default
2021-09-23T02:52:52.197381Z	info	sds	resource:default pushed key/cert pair to proxy
2021-09-23T02:52:52.324549Z	info	cache	Loaded root cert from certificate ROOTCA
2021-09-23T02:52:52.324858Z	info	sds	resource:ROOTCA pushed root cert to proxy
2021-09-23T02:52:52.905575Z	info	Envoy proxy is ready
2021-09-23T03:24:59.695819Z	info	xdsproxy	disconnected from XDS server: istiod.istio-system.svc:15012
2021-09-23T03:24:59.696566Z	warning	envoy config	StreamAggregatedResources gRPC config stream closed: 0, 
2021-09-23T03:25:00.014333Z	info	xdsproxy	Envoy ADS stream established
2021-09-23T03:25:00.014561Z	info	xdsproxy	connecting to upstream XDS server: istiod.istio-system.svc:15012
[2021-09-23T03:37:25.147Z] "GET /details/0 HTTP/1.1" 503 UF "-" 0 91 90 - "-" "curl/7.52.1" "507f4f72-c53d-999a-864b-71c67c722717" "details:9080" "10.244.2.5:9080" outbound|9080||global-sidecar.default.svc.cluster.local - 10.96.206.167:9080 10.244.1.11:46772 - -
[2021-09-23T03:37:25.265Z] "GET /reviews/0 HTTP/1.1" 503 UF "-" 0 91 0 - "-" "curl/7.52.1" "507f4f72-c53d-999a-864b-71c67c722717" "reviews:9080" "10.244.2.5:9080" outbound|9080||global-sidecar.default.svc.cluster.local - 10.96.27.89:9080 10.244.1.11:42392 - -
[2021-09-23T03:37:25.274Z] "GET /reviews/0 HTTP/1.1" 503 UF "-" 0 91 0 - "-" "curl/7.52.1" "507f4f72-c53d-999a-864b-71c67c722717" "reviews:9080" "10.244.2.5:9080" outbound|9080||global-sidecar.default.svc.cluster.local - 10.96.27.89:9080 10.244.1.11:42396 - -
[2021-09-23T03:37:25.062Z] "GET /productpage HTTP/1.1" 200 - "-" 0 3769 247 227 "-" "curl/7.52.1" "507f4f72-c53d-999a-864b-71c67c722717" "productpage:9080" "127.0.0.1:9080" inbound|9080|| 127.0.0.1:54786 10.244.1.11:9080 10.244.2.12:57852 outbound_.9080_._.productpage.default.svc.cluster.local default

应用容器

➜  ~ kubectl logs productpage-v1-65576bb7bf-rcnfr -c productpage
INFO:root:start at port 9080

 * Serving Flask app "productpage" (lazy loading)
 * Environment: production
   WARNING: Do not use the development server in a production environment.
   Use a production WSGI server instead.
 * Debug mode: on
   INFO:werkzeug: * Running on http://0.0.0.0:9080/ (Press CTRL+C to quit)
   INFO:werkzeug: * Restarting with stat
   INFO:root:start at port 9080
   WARNING:werkzeug: * Debugger is active!
   INFO:werkzeug: * Debugger PIN: 305-281-729
   DEBUG:urllib3.connectionpool:Starting new HTTP connection (1): details:9080
   send: b'GET /details/0 HTTP/1.1\r\nHost: details:9080\r\nuser-agent: curl/7.52.1\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\nX-B3-TraceId: 3864470a4495b8d10216068955349927\r\nX-B3-SpanId: b88111f1d827040a\r\nX-B3-ParentSpanId: 0216068955349927\r\nX-B3-Sampled: 1\r\nx-request-id: 507f4f72-c53d-999a-864b-71c67c722717\r\n\r\n'
   reply: 'HTTP/1.1 503 Service Unavailable\r\n'
   header: content-length: 91
   header: content-type: text/plain
   header: date: Thu, 23 Sep 2021 03:37:24 GMT
   header: server: envoy
   DEBUG:urllib3.connectionpool:http://details:9080 "GET /details/0 HTTP/1.1" 503 91
   DEBUG:urllib3.connectionpool:Starting new HTTP connection (1): reviews:9080
   send: b'GET /reviews/0 HTTP/1.1\r\nHost: reviews:9080\r\nuser-agent: curl/7.52.1\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\nX-B3-TraceId: 3864470a4495b8d10216068955349927\r\nX-B3-SpanId: b88111f1d827040a\r\nX-B3-ParentSpanId: 0216068955349927\r\nX-B3-Sampled: 1\r\nx-request-id: 507f4f72-c53d-999a-864b-71c67c722717\r\n\r\n'
   reply: 'HTTP/1.1 503 Service Unavailable\r\n'
   header: content-length: 91
   header: content-type: text/plain
   header: date: Thu, 23 Sep 2021 03:37:24 GMT
   header: server: envoy
   DEBUG:urllib3.connectionpool:http://reviews:9080 "GET /reviews/0 HTTP/1.1" 503 91
   DEBUG:urllib3.connectionpool:Starting new HTTP connection (1): reviews:9080
   send: b'GET /reviews/0 HTTP/1.1\r\nHost: reviews:9080\r\nuser-agent: curl/7.52.1\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\nX-B3-TraceId: 3864470a4495b8d10216068955349927\r\nX-B3-SpanId: b88111f1d827040a\r\nX-B3-ParentSpanId: 0216068955349927\r\nX-B3-Sampled: 1\r\nx-request-id: 507f4f72-c53d-999a-864b-71c67c722717\r\n\r\n'
   reply: 'HTTP/1.1 503 Service Unavailable\r\n'
   header: content-length: 91
   header: content-type: text/plain
   header: date: Thu, 23 Sep 2021 03:37:24 GMT
   header: server: envoy
   DEBUG:urllib3.connectionpool:http://reviews:9080 "GET /reviews/0 HTTP/1.1" 503 91
   INFO:werkzeug:127.0.0.1 - - [23/Sep/2021 03:37:25] "GET /productpage HTTP/1.1" 200 -
  

istio-init 

➜  ~ kubectl logs productpage-v1-65576bb7bf-rcnfr -c istio-init 
   Environment:

------------

ENVOY_PORT=
INBOUND_CAPTURE_PORT=
ISTIO_INBOUND_INTERCEPTION_MODE=
ISTIO_INBOUND_TPROXY_MARK=
ISTIO_INBOUND_TPROXY_ROUTE_TABLE=
ISTIO_INBOUND_PORTS=
ISTIO_OUTBOUND_PORTS=
ISTIO_LOCAL_EXCLUDE_PORTS=
ISTIO_SERVICE_CIDR=
ISTIO_SERVICE_EXCLUDE_CIDR=

Variables:

PROXY_PORT=15001
PROXY_INBOUND_CAPTURE_PORT=15006
PROXY_TUNNEL_PORT=15008
PROXY_UID=1337
PROXY_GID=1337
INBOUND_INTERCEPTION_MODE=REDIRECT
INBOUND_TPROXY_MARK=1337
INBOUND_TPROXY_ROUTE_TABLE=133
INBOUND_PORTS_INCLUDE=*
INBOUND_PORTS_EXCLUDE=15090,15021,15020
OUTBOUND_IP_RANGES_INCLUDE=*
OUTBOUND_IP_RANGES_EXCLUDE=
OUTBOUND_PORTS_INCLUDE=
OUTBOUND_PORTS_EXCLUDE=
KUBEVIRT_INTERFACES=
ENABLE_INBOUND_IPV6=false

Writing following contents to rules file:  /tmp/iptables-rules-1632365525899234396.txt110258964

* nat
  -N ISTIO_INBOUND
  -N ISTIO_REDIRECT
  -N ISTIO_IN_REDIRECT
  -N ISTIO_OUTPUT
  -A ISTIO_INBOUND -p tcp --dport 15008 -j RETURN
  -A ISTIO_REDIRECT -p tcp -j REDIRECT --to-ports 15001
  -A ISTIO_IN_REDIRECT -p tcp -j REDIRECT --to-ports 15006
  -A PREROUTING -p tcp -j ISTIO_INBOUND
  -A ISTIO_INBOUND -p tcp --dport 22 -j RETURN
  -A ISTIO_INBOUND -p tcp --dport 15090 -j RETURN
  -A ISTIO_INBOUND -p tcp --dport 15021 -j RETURN
  -A ISTIO_INBOUND -p tcp --dport 15020 -j RETURN
  -A ISTIO_INBOUND -p tcp -j ISTIO_IN_REDIRECT
  -A OUTPUT -p tcp -j ISTIO_OUTPUT
  -A ISTIO_OUTPUT -o lo -s 127.0.0.6/32 -j RETURN
  -A ISTIO_OUTPUT -o lo ! -d 127.0.0.1/32 -m owner --uid-owner 1337 -j ISTIO_IN_REDIRECT
  -A ISTIO_OUTPUT -o lo -m owner ! --uid-owner 1337 -j RETURN
  -A ISTIO_OUTPUT -m owner --uid-owner 1337 -j RETURN
  -A ISTIO_OUTPUT -o lo ! -d 127.0.0.1/32 -m owner --gid-owner 1337 -j ISTIO_IN_REDIRECT
  -A ISTIO_OUTPUT -o lo -m owner ! --gid-owner 1337 -j RETURN
  -A ISTIO_OUTPUT -m owner --gid-owner 1337 -j RETURN
  -A ISTIO_OUTPUT -d 127.0.0.1/32 -j RETURN
  -A ISTIO_OUTPUT -j ISTIO_REDIRECT
  COMMIT

iptables-restore --noflush /tmp/iptables-rules-1632365525899234396.txt110258964
Writing following contents to rules file:  /tmp/ip6tables-rules-1632365526282819021.txt568430947

ip6tables-restore --noflush /tmp/ip6tables-rules-1632365526282819021.txt568430947
iptables-save 

Generated by iptables-save v1.6.1 on Thu Sep 23 02:52:06 2021

*nat
:PREROUTING ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
:ISTIO_INBOUND - [0:0]
:ISTIO_IN_REDIRECT - [0:0]
:ISTIO_OUTPUT - [0:0]
:ISTIO_REDIRECT - [0:0]
-A PREROUTING -p tcp -j ISTIO_INBOUND
-A OUTPUT -p tcp -j ISTIO_OUTPUT
-A ISTIO_INBOUND -p tcp -m tcp --dport 15008 -j RETURN
-A ISTIO_INBOUND -p tcp -m tcp --dport 22 -j RETURN
-A ISTIO_INBOUND -p tcp -m tcp --dport 15090 -j RETURN
-A ISTIO_INBOUND -p tcp -m tcp --dport 15021 -j RETURN
-A ISTIO_INBOUND -p tcp -m tcp --dport 15020 -j RETURN
-A ISTIO_INBOUND -p tcp -j ISTIO_IN_REDIRECT
-A ISTIO_IN_REDIRECT -p tcp -j REDIRECT --to-ports 15006
-A ISTIO_OUTPUT -s 127.0.0.6/32 -o lo -j RETURN
-A ISTIO_OUTPUT ! -d 127.0.0.1/32 -o lo -m owner --uid-owner 1337 -j ISTIO_IN_REDIRECT
-A ISTIO_OUTPUT -o lo -m owner ! --uid-owner 1337 -j RETURN
-A ISTIO_OUTPUT -m owner --uid-owner 1337 -j RETURN
-A ISTIO_OUTPUT ! -d 127.0.0.1/32 -o lo -m owner --gid-owner 1337 -j ISTIO_IN_REDIRECT
-A ISTIO_OUTPUT -o lo -m owner ! --gid-owner 1337 -j RETURN
-A ISTIO_OUTPUT -m owner --gid-owner 1337 -j RETURN
-A ISTIO_OUTPUT -d 127.0.0.1/32 -j RETURN
-A ISTIO_OUTPUT -j ISTIO_REDIRECT
-A ISTIO_REDIRECT -p tcp -j REDIRECT --to-ports 15001
COMMIT

#Completed on Thu Sep 23 02:52:06 2021

➜  ~ 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值