mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-10-11 12:26:04 +00:00
26 lines
33 KiB
HTML
26 lines
33 KiB
HTML
<!doctype html>
|
||
<html lang="zh" dir="ltr" class="docs-wrapper docs-doc-page docs-version-current plugin-docs plugin-id-default docs-doc-id-pages-for-subheaders/istio">
|
||
<head>
|
||
<meta charset="UTF-8">
|
||
<meta name="generator" content="Docusaurus v2.3.1">
|
||
<title data-rh="true">Istio | Rancher</title><meta data-rh="true" name="viewport" content="width=device-width,initial-scale=1"><meta data-rh="true" name="twitter:card" content="summary_large_image"><meta data-rh="true" property="og:url" content="https://ranchermanager.docs.rancher.com/zh/pages-for-subheaders/istio"><meta data-rh="true" name="docusaurus_locale" content="zh"><meta data-rh="true" name="docsearch:language" content="zh"><meta data-rh="true" name="docusaurus_version" content="current"><meta data-rh="true" name="docusaurus_tag" content="docs-default-current"><meta data-rh="true" name="docsearch:version" content="current"><meta data-rh="true" name="docsearch:docusaurus_tag" content="docs-default-current"><meta data-rh="true" property="og:title" content="Istio | Rancher"><meta data-rh="true" name="description" content="Istio 是一种开源工具,可以让 DevOps 团队更轻松地观察、控制、排查并保护复杂的微服务网络中的流量。"><meta data-rh="true" property="og:description" content="Istio 是一种开源工具,可以让 DevOps 团队更轻松地观察、控制、排查并保护复杂的微服务网络中的流量。"><link data-rh="true" rel="icon" href="/zh/img/favicon.png"><link data-rh="true" rel="canonical" href="https://ranchermanager.docs.rancher.com/zh/pages-for-subheaders/istio"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/pages-for-subheaders/istio" hreflang="en"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/zh/pages-for-subheaders/istio" hreflang="zh"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/pages-for-subheaders/istio" hreflang="x-default"><link data-rh="true" rel="preconnect" href="https://30NEY6C9UY-dsn.algolia.net" crossorigin="anonymous"><link rel="preconnect" href="https://www.googletagmanager.com">
|
||
<script>window.dataLayer=window.dataLayer||[]</script>
|
||
<script>!function(e,t,a,n,g){e[n]=e[n]||[],e[n].push({"gtm.start":(new Date).getTime(),event:"gtm.js"});var m=t.getElementsByTagName(a)[0],r=t.createElement(a);r.async=!0,r.src="https://www.googletagmanager.com/gtm.js?id=GTM-57KS2MW",m.parentNode.insertBefore(r,m)}(window,document,"script","dataLayer")</script>
|
||
|
||
|
||
<link rel="search" type="application/opensearchdescription+xml" title="Rancher" href="/zh/opensearch.xml">
|
||
|
||
<script src="https://cdn.cookielaw.org/scripttemplates/otSDKStub.js" charset="UTF-8" data-domain-script="0f98beb0-fc4c-417d-a42e-564e2cae42d2" async></script>
|
||
<script src="/scripts/optanonwrapper.js" async></script><link rel="stylesheet" href="/zh/assets/css/styles.10402cb5.css">
|
||
<link rel="preload" href="/zh/assets/js/runtime~main.9a7dea44.js" as="script">
|
||
<link rel="preload" href="/zh/assets/js/main.50802f1f.js" as="script">
|
||
</head>
|
||
<body class="navigation-with-keyboard">
|
||
<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-57KS2MW" height="0" width="0" style="display:none;visibility:hidden"></iframe></noscript>
|
||
|
||
<script>!function(){function t(t){document.documentElement.setAttribute("data-theme",t)}var e=function(){var t=null;try{t=localStorage.getItem("theme")}catch(t){}return t}();t(null!==e?e:"light")}()</script><div id="__docusaurus">
|
||
<div role="region" aria-label="跳到主要内容"><a class="skipToContent_fXgn" href="#docusaurus_skipToContent_fallback">跳到主要内容</a></div><nav aria-label="主导航" class="navbar navbar--fixed-top"><div class="navbar__inner"><div class="navbar__items"><button aria-label="切换导航栏" aria-expanded="false" class="navbar__toggle clean-btn" type="button"><svg width="30" height="30" viewBox="0 0 30 30" aria-hidden="true"><path stroke="currentColor" stroke-linecap="round" stroke-miterlimit="10" stroke-width="2" d="M4 7h22M4 15h22M4 23h22"></path></svg></button><a class="navbar__brand" href="/zh/"><div class="navbar__logo"><img src="/zh/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--light_HNdA"><img src="/zh/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--dark_i4oU"></div><b class="navbar__title text--truncate"></b></a><div class="navbar__item dropdown dropdown--hoverable"><a aria-current="page" class="navbar__link active" aria-haspopup="true" aria-expanded="false" role="button" href="/zh/">Latest</a><ul class="dropdown__menu"><li><a aria-current="page" class="dropdown__link dropdown__link--active" href="/zh/pages-for-subheaders/istio">Latest</a></li><li><a class="dropdown__link" href="/zh/v2.7/pages-for-subheaders/istio">v2.7</a></li><li><a class="dropdown__link" href="/zh/v2.6/pages-for-subheaders/istio">v2.6</a></li><li><a class="dropdown__link" href="/zh/v2.5/pages-for-subheaders/istio">v2.5</a></li><li><a class="dropdown__link" href="/zh/v2.0-v2.4/pages-for-subheaders/istio">v2.0-v2.4</a></li><li><a class="dropdown__link" href="/zh/versions">All versions</a></li></ul></div></div><div class="navbar__items navbar__items--right"><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link"><svg viewBox="0 0 24 24" width="20" height="20" aria-hidden="true" class="iconLanguage_nlXk"><path fill="currentColor" d="M12.87 15.07l-2.54-2.51.03-.03c1.74-1.94 2.98-4.17 3.71-6.53H17V4h-7V2H8v2H1v1.99h11.17C11.5 7.92 10.44 9.75 9 11.35 8.07 10.32 7.3 9.19 6.69 8h-2c.73 1.63 1.73 3.17 2.98 4.56l-5.09 5.02L4 19l5-5 3.11 3.11.76-2.04zM18.5 10h-2L12 22h2l1.12-3h4.75L21 22h2l-4.5-12zm-2.62 7l1.62-4.33L19.12 17h-3.24z"></path></svg>简体中文</a><ul class="dropdown__menu"><li><a href="/pages-for-subheaders/istio" target="_self" rel="noopener noreferrer" class="dropdown__link" lang="en">English</a></li><li><a href="/zh/pages-for-subheaders/istio" target="_self" rel="noopener noreferrer" class="dropdown__link dropdown__link--active" lang="zh">简体中文</a></li></ul></div><a href="https://github.com/rancher/rancher-docs" target="_blank" rel="noopener noreferrer" class="navbar__item navbar__link navbar__github">GitHub<svg width="13.5" height="13.5" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a><a href="https://www.rancher.com" target="_blank" rel="noopener noreferrer" class="navbar__item navbar__link">Rancher 主页<svg width="13.5" height="13.5" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a><div class="searchBox_ZlJk"><button type="button" class="DocSearch DocSearch-Button" aria-label="搜索"><span class="DocSearch-Button-Container"><svg width="20" height="20" class="DocSearch-Search-Icon" viewBox="0 0 20 20"><path d="M14.386 14.386l4.0877 4.0877-4.0877-4.0877c-2.9418 2.9419-7.7115 2.9419-10.6533 0-2.9419-2.9418-2.9419-7.7115 0-10.6533 2.9418-2.9419 7.7115-2.9419 10.6533 0 2.9419 2.9418 2.9419 7.7115 0 10.6533z" stroke="currentColor" fill="none" fill-rule="evenodd" stroke-linecap="round" stroke-linejoin="round"></path></svg><span class="DocSearch-Button-Placeholder">搜索</span></span><span class="DocSearch-Button-Keys"></span></button></div></div></div><div role="presentation" class="navbar-sidebar__backdrop"></div></nav><div id="docusaurus_skipToContent_fallback" class="main-wrapper mainWrapper_z2l0 docsWrapper_BCFX"><button aria-label="回到顶部" class="clean-btn theme-back-to-top-button backToTopButton_sjWU" type="button"></button><div class="docPage__5DB"><aside class="theme-doc-sidebar-container docSidebarContainer_b6E3"><div class="sidebarViewport_Xe31"><div class="sidebar_njMd"><nav aria-label="文档侧边栏" class="menu thin-scrollbar menu_SIkG"><ul class="theme-doc-sidebar-menu menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/zh/">什么是 Rancher?</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/zh/getting-started/overview">开始使用</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/zh/pages-for-subheaders/new-user-guides">操作指南</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/zh/pages-for-subheaders/best-practices">参考指南</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret menu__link--active" aria-expanded="true" href="/zh/pages-for-subheaders/cloud-marketplace">Rancher 中的集成</a></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/pages-for-subheaders/cloud-marketplace">云市场集成</a><button aria-label="打开/收起侧边栏菜单「云市场集成」" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/pages-for-subheaders/cis-scans">CIS 扫描</a><button aria-label="打开/收起侧边栏菜单「CIS 扫描」" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/pages-for-subheaders/fleet-gitops-at-scale">使用 Fleet 进行持续交付</a><button aria-label="打开/收起侧边栏菜单「使用 Fleet 进行持续交付」" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/zh/integrations-in-rancher/harvester">Harvester 集成</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item"><div class="menu__list-item-collapsible menu__list-item-collapsible--active"><a class="menu__link menu__link--sublist menu__link--active" aria-current="page" aria-expanded="true" tabindex="0" href="/zh/pages-for-subheaders/istio">Istio</a><button aria-label="打开/收起侧边栏菜单「Istio」" type="button" class="clean-btn menu__caret"></button></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/zh/integrations-in-rancher/istio/cpu-and-memory-allocations">CPU 和内存分配</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/zh/integrations-in-rancher/istio/rbac-for-istio">RBAC</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/zh/integrations-in-rancher/istio/disable-istio">禁用 Istio</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-3 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/pages-for-subheaders/configuration-options">配置选项</a><button aria-label="打开/收起侧边栏菜单「配置选项」" type="button" class="clean-btn menu__caret"></button></div></li></ul></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/zh/integrations-in-rancher/longhorn">Longhorn - Kubernetes 的云原生分布式块存储</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/pages-for-subheaders/logging">Logging</a><button aria-label="打开/收起侧边栏菜单「Logging」" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/zh/pages-for-subheaders/monitoring-and-alerting">监控和告警</a><button aria-label="打开/收起侧边栏菜单「监控和告警」" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/zh/integrations-in-rancher/neuvector">NeuVector 集成</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/zh/integrations-in-rancher/opa-gatekeeper">OPA Gatekeeper</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/zh/integrations-in-rancher/rancher-extensions">Rancher 扩展</a></li></ul></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/zh/faq/general-faq">常见问题</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/zh/troubleshooting/general-troubleshooting">故障排除</a></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/zh/contribute-to-rancher">参与 Rancher 社区贡献</a></li></ul></nav></div></div></aside><main class="docMainContainer_gTbr"><div class="container padding-top--md padding-bottom--lg"><div class="row"><div class="col docItemCol_VOVn"><div class="docItemContainer_Djhp"><article><nav class="theme-doc-breadcrumbs breadcrumbsContainer_Z_bl" aria-label="页面路径"><ul class="breadcrumbs" itemscope="" itemtype="https://schema.org/BreadcrumbList"><li class="breadcrumbs__item"><a aria-label="主页面" class="breadcrumbs__link" href="/zh/"><svg viewBox="0 0 24 24" class="breadcrumbHomeIcon_YNFT"><path d="M10 19v-5h4v5c0 .55.45 1 1 1h3c.55 0 1-.45 1-1v-7h1.7c.46 0 .68-.57.33-.87L12.67 3.6c-.38-.34-.96-.34-1.34 0l-8.36 7.53c-.34.3-.13.87.33.87H5v7c0 .55.45 1 1 1h3c.55 0 1-.45 1-1z" fill="currentColor"></path></svg></a></li><li class="breadcrumbs__item"><span class="breadcrumbs__link">Rancher 中的集成</span><meta itemprop="position" content="1"></li><li itemscope="" itemprop="itemListElement" itemtype="https://schema.org/ListItem" class="breadcrumbs__item breadcrumbs__item--active"><span class="breadcrumbs__link" itemprop="name">Istio</span><meta itemprop="position" content="2"></li></ul></nav><span class="theme-doc-version-badge badge badge--secondary">版本:Latest</span><div class="tocCollapsible_ETCw theme-doc-toc-mobile tocMobile_ITEo"><button type="button" class="clean-btn tocCollapsibleButton_TO0P">本页总览</button></div><div class="theme-doc-markdown markdown"><header><h1>Istio</h1></header><p><a href="https://istio.io/" target="_blank" rel="noopener noreferrer">Istio</a> 是一种开源工具,可以让 DevOps 团队更轻松地观察、控制、排查并保护复杂的微服务网络中的流量。</p><p>随着微服务网络的变化和增长,微服务网络之间的交互变得越来越难以管理和理解。在这种情况下,将服务网格作为单独的基础设施层是非常有用的。Istio 的服务网格可以让你在不直接更改微服务的情况下控制微服务之间的流量。</p><p>Rancher 与 Istio 集成,使得管理员或集群所有者可以将 Istio 交给开发者团队,然后开发者使用 Istio 执行安全策略,排查问题,或为蓝绿部署,金丝雀部署,和 A/B 测试进行流量管理。</p><p>此核心服务网格支持但不限于以下功能:</p><ul><li><strong>管理流量</strong>:例如入口和出口路由、断路、镜像。</li><li><strong>安全</strong>:具有用于验证和授权流量和用户的资源,包括 mTLS。</li><li><strong>可观察性</strong>:观察日志、指标和分布式流量。</li></ul><p><a href="/zh/pages-for-subheaders/istio-setup-guide">设置 Istio</a> 后,你可以通过 Rancher UI、<code>kubectl</code> 或 <code> Istioctl</code> 来使用 Istio 的 controlplane 功能。</p><p>Istio 需要由 <code>cluster-admin</code> 设置后才能在项目中使用。</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="rancher-25-的新功能">Rancher 2.5 的新功能<a href="#rancher-25-的新功能" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接"></a></h2><p>Istio 已简化了整体架构。结合 Pilot、Citadel、Galley 和 sidecar injector 创建了一个单独的组件 Istiod。Node Agent 功能也已合并到 istio-agent 中。</p><p>以前由 Istio 安装的插件(cert-manager、Grafana、Jaeger、Kiali、Prometheus、Zipkin)现在需要单独安装。Istio 支持安装来自 Istio 项目的集成,并保持与非 Istio 项目的兼容性。</p><p>你仍然可以通过安装 <a href="/zh/pages-for-subheaders/monitoring-and-alerting">Rancher Monitoring</a> 或安装你自己的 Prometheus operator 来使用 Prometheus 集成。Rancher 的 Istio chart 还默认安装 Kiali,确保你可以开箱即用地全面了解微服务。</p><p>Istio 已经脱离了使用 Helm 安装的方式,现在通过 Istioctl 二进制文件或 Istio Operator 进行安装。为了使用最简单的方式与 Istio 交互,Rancher 的 Istio 会维护一个 Helm Chart,该 Chart 使用 Istioctl 二进制文件来管理你的 Istio 安装。</p><p>此 Helm Chart 将在 UI 的<strong>应用 & 市场市场</strong>中提供。有权访问 Rancher Chart 应用商店的用户需要先设置 Istio,然后才能在项目中使用它。</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="istio-附带的工具">Istio 附带的工具<a href="#istio-附带的工具" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接"></a></h2><p>我们的 <a href="https://istio.io/" target="_blank" rel="noopener noreferrer">Istio</a> 安装程序将 istioctl 二进制命令包装在一个 Helm chart 中,其中包括一个覆盖文件的选项,用来支持复杂的自定义配置。</p><p>它还包括以下内容。</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="kiali">Kiali<a href="#kiali" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接"></a></h3><p>Kiali 是一个全面的可视化辅助工具,用于绘制整个服务网格中的流量图。它允许你查看它们的连接方式,包括它们之间的流量速率和延迟。</p><p>你可以检查服务网格的运行状况,或深入查看单个组件的传入和传出请求。</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="jaeger">Jaeger<a href="#jaeger" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接"></a></h3><p>Jaeger 是用于跟踪分布式系统的工具。我们的 Istio 安装程序包括能快速启动的一体化 <a href="https://www.jaegertracing.io/" target="_blank" rel="noopener noreferrer">Jaeger</a> 安装。</p><p>请注意,这不是符合 Jaeger 生产要求的部署。此部署使用在内存中的存储组件,而 Jaeger 推荐在生产环境中使用持久存储组件。有关你所需的部署策略的更多信息,请参阅 <a href="https://www.jaegertracing.io/docs/latest/operator/#production-strategy" target="_blank" rel="noopener noreferrer">Jaeger 文档</a>。</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="先决条件">先决条件<a href="#先决条件" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接"></a></h2><p>在启用 Istio 之前,建议你先确认你的 Rancher worker 节点是否有足够的 <a href="/zh/integrations-in-rancher/istio/cpu-and-memory-allocations">CPU 和内存</a>来运行 Istio 的所有组件。</p><p>如果要在 RKE2 集群上安装 Istio,则需要执行一些额外的步骤。有关详细信息,请参阅<a href="#%E5%9C%A8-rke2-%E9%9B%86%E7%BE%A4%E4%B8%8A%E5%AE%89%E8%A3%85-istio-%E7%9A%84%E5%85%B6%E4%BB%96%E6%AD%A5%E9%AA%A4">本节</a>。</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="设置指南">设置指南<a href="#设置指南" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接"></a></h2><p>如需了解如何设置 Istio 并在项目中使用它,请参阅<a href="/zh/pages-for-subheaders/istio-setup-guide">设置指南</a>。</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="卸载-istio">卸载 Istio<a href="#卸载-istio" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接"></a></h2><p>要从集群、命名空间或工作负载中删除 Istio 组件,请参阅<a href="/zh/integrations-in-rancher/istio/disable-istio">卸载 Istio</a>。</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="访问可视化">访问可视化<a href="#访问可视化" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接"></a></h2><blockquote><p>默认情况下,只有 cluster-admin 可以访问 Kiali。有关如何允许具有管理员、编辑或查看权限的角色访问它们的说明,请参阅<a href="/zh/integrations-in-rancher/istio/rbac-for-istio">本节</a>。</p></blockquote><p>在集群中设置 Istio 后,你可以在 Rancher UI 中使用 Grafana、Prometheus 和 Kiali。</p><p>要访问 Grafana 和 Prometheus 可视化:</p><ol><li>在左上角,单击 <strong>☰ > 集群管理</strong>。</li><li>在<strong>集群</strong>页面上,转到要可视化的集群,然后单击 <strong>Explore</strong>。</li><li>在左侧导航栏中,单击<strong>监控</strong>。</li><li>点击 <strong>Grafana</strong> 或任何其他仪表板。</li></ol><p>要访问 Kiali 可视化:</p><ol><li>在左上角,单击 <strong>☰ > 集群管理</strong>。</li><li>在<strong>集群</strong>页面上,转到要查看 Kiali 的集群,然后单击 <strong>Explore</strong>。</li><li>在左侧导航栏中,单击 <strong>Istio</strong>。</li><li>单击 <strong>Kiali</strong>。从这里,你可以访问<strong>流量图</strong>或<strong>流量指标</strong>选项卡,从而可视化网络指标。</li></ol><p>默认情况下,prometheus 会拾取所有命名空间,并将数据用于 Kiali 图。如果你想使用不同的配置进行 prometheus 数据抓取,请参阅<a href="/zh/integrations-in-rancher/istio/configuration-options/selectors-and-scrape-configurations">选择器/抓取配置</a>。</p><p>你的角色决定了你对可视化的访问。只有 <code>cluster-admin</code> 角色可以使用 Grafana 和 Prometheus。默认情况下,只有 <code>cluster-admin</code> 可以使用 Kiali UI,但是 <code>cluster-admin</code> 可以通过编辑 Istio values.yaml 来允许其他角色进行访问。</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="架构">架构<a href="#架构" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接"></a></h2><p>Istio 安装了一个服务网格,它使用 <a href="https://www.envoyproxy.io" target="_blank" rel="noopener noreferrer">Envoy</a> Sidecar 代理来拦截到每个工作负载的流量。这些 sidecar 拦截并管理服务之间的通信,从而实现精细化观察并控制集群内的流量。</p><p>只有注入了 Istio sidecar 的工作负载可以通过 Istio 进行跟踪和控制。</p><p>如果命名空间启用了 Istio,部署到命名空间的新工作负载会自动具有 Istio sidecar。你需要为之前的工作负载手动启用 Istio。</p><p>有关 Istio sidecar 的更多信息,请参阅 <a href="https://istio.io/docs/setup/kubernetes/additional-setup/sidecar-injection/" target="_blank" rel="noopener noreferrer">Istio sidecare-injection 文档</a>。有关 Istio 架构的更多信息,请参阅 <a href="https://istio.io/latest/docs/ops/deployment/architecture/" target="_blank" rel="noopener noreferrer">Istio 架构文档</a>。</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="多个-ingress">多个 Ingress<a href="#多个-ingress" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接"></a></h3><p>默认情况下,每个 Rancher 配置的集群都有一个 NGINX Ingress Controller 来允许流量进入集群。Istio 还在 <code>istio-system</code> 命名空间中默认安装一个 Ingress Gateway。因此,你的集群将有两个 ingress。</p><p><img loading="lazy" alt="启用 Istio 的集群可以有两个 ingress,分别是默认的 Nginx ingress 和默认的 Istio controller" src="/zh/assets/images/istio-ingress-3ca2b3bfa19fe1f0d38b74966b383ac0.svg" width="691" height="572" class="img_ev3q"></p><p>可以通过<a href="/zh/pages-for-subheaders/configuration-options#%E8%A6%86%E7%9B%96%E6%96%87%E4%BB%B6">覆盖文件</a>来启用其他 Istio Ingress Gateway。</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="egress-支持">Egress 支持<a href="#egress-支持" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接"></a></h3><p>默认情况下,Egress 网关是禁用的,但你可以在安装或升级时使用 values.yaml 或<a href="/zh/pages-for-subheaders/configuration-options#%E8%A6%86%E7%9B%96%E6%96%87%E4%BB%B6">覆盖文件</a>启用它。</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="在-rke2-集群上安装-istio-的其他步骤">在 RKE2 集群上安装 Istio 的其他步骤<a href="#在-rke2-集群上安装-istio-的其他步骤" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接"></a></h2><p>要在 RKE2 集群上安装 Istio,请按照<a href="/zh/integrations-in-rancher/istio/configuration-options/install-istio-on-rke2-cluster">步骤</a>进行操作。</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="在离线环境中升级-istio">在离线环境中升级 Istio<a href="#在离线环境中升级-istio" class="hash-link" aria-label="标题的直接链接" title="标题的直接链接"></a></h2><p>现在,Istio Pod 安全策略默认启用。新值 <code>installer.releaseMirror.enabled</code> 已添加到 rancher-istio Chart 中,以启用和禁用支持离线升级的 Server。请注意,<code>installer.releaseMirror.enabled</code> 默认设置为 <code>false</code>。你可以在安装或升级时根据需要设置该值。按照以下步骤执行:</p><ol><li>在 Rancher UI 中配置离线 Rancher 实例和离线自定义集群。</li><li>在集群中安装 Monitoring:<strong>Cluster Explorer > Apps & Marketplace > Charts > Monitoring</strong>。</li><li>将 Istio 所需的所有镜像拉入在离线环境中使用的私有镜像仓库。</li><li>在集群中安装 Istio:<strong>Cluster Explorer > Apps & Marketplace > Charts > Istio</strong>。</li></ol><div class="theme-admonition theme-admonition-note alert alert--secondary admonition_LlT9"><div class="admonitionHeading_tbUL"><span class="admonitionIcon_kALy"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M6.3 5.69a.942.942 0 0 1-.28-.7c0-.28.09-.52.28-.7.19-.18.42-.28.7-.28.28 0 .52.09.7.28.18.19.28.42.28.7 0 .28-.09.52-.28.7a1 1 0 0 1-.7.3c-.28 0-.52-.11-.7-.3zM8 7.99c-.02-.25-.11-.48-.31-.69-.2-.19-.42-.3-.69-.31H6c-.27.02-.48.13-.69.31-.2.2-.3.44-.31.69h1v3c.02.27.11.5.31.69.2.2.42.31.69.31h1c.27 0 .48-.11.69-.31.2-.19.3-.42.31-.69H8V7.98v.01zM7 2.3c-3.14 0-5.7 2.54-5.7 5.68 0 3.14 2.56 5.7 5.7 5.7s5.7-2.55 5.7-5.7c0-3.15-2.56-5.69-5.7-5.69v.01zM7 .98c3.86 0 7 3.14 7 7s-3.14 7-7 7-7-3.12-7-7 3.14-7 7-7z"></path></svg></span>备注</div><div class="admonitionContent_S0QG"><p>你可以在新安装的 Istio 上启用 <a href="https://www.jaegertracing.io/" target="_blank" rel="noopener noreferrer">Jaeger</a> 和 <a href="https://kiali.io/" target="_blank" rel="noopener noreferrer">Kiali</a>。为确保 Jaeger 和 Kiali 正常工作,请在安装期间将 <code>values.yaml</code> 中的 <code>installer.releaseMirror.enabled</code> 设置为 <code>true</code>。</p></div></div><ol start="5"><li>升级 Istio。</li></ol><div class="theme-admonition theme-admonition-caution alert alert--warning admonition_LlT9"><div class="admonitionHeading_tbUL"><span class="admonitionIcon_kALy"><svg viewBox="0 0 16 16"><path fill-rule="evenodd" d="M8.893 1.5c-.183-.31-.52-.5-.887-.5s-.703.19-.886.5L.138 13.499a.98.98 0 0 0 0 1.001c.193.31.53.501.886.501h13.964c.367 0 .704-.19.877-.5a1.03 1.03 0 0 0 .01-1.002L8.893 1.5zm.133 11.497H6.987v-2.003h2.039v2.003zm0-3.004H6.987V5.987h2.039v4.006z"></path></svg></span>警告</div><div class="admonitionContent_S0QG"><p>如果你还没有执行操作,请设置 <code>installer.releaseMirror.enabled=true</code> 以升级 Istio。</p></div></div></div><footer class="theme-doc-footer docusaurus-mt-lg"><div class="theme-doc-footer-edit-meta-row row"><div class="col"><a href="https://github.com/rancher/rancher-docs/edit/main/docs/pages-for-subheaders/istio.md" target="_blank" rel="noreferrer noopener" class="theme-edit-this-page"><svg fill="currentColor" height="20" width="20" viewBox="0 0 40 40" class="iconEdit_Z9Sw" aria-hidden="true"><g><path d="m34.5 11.7l-3 3.1-6.3-6.3 3.1-3q0.5-0.5 1.2-0.5t1.1 0.5l3.9 3.9q0.5 0.4 0.5 1.1t-0.5 1.2z m-29.5 17.1l18.4-18.5 6.3 6.3-18.4 18.4h-6.3v-6.2z"></path></g></svg>编辑此页</a></div><div class="col lastUpdated_vwxv"><span class="theme-last-updated">最后<!-- -->于 <b><time datetime="2023-06-01T21:18:49.000Z">2023年6月1日</time></b> <!-- -->更新</span></div></div></footer></article><nav class="pagination-nav docusaurus-mt-lg" aria-label="文档分页导航"><a class="pagination-nav__link pagination-nav__link--prev" href="/zh/integrations-in-rancher/harvester"><div class="pagination-nav__sublabel">上一页</div><div class="pagination-nav__label">Harvester 集成</div></a><a class="pagination-nav__link pagination-nav__link--next" href="/zh/integrations-in-rancher/istio/cpu-and-memory-allocations"><div class="pagination-nav__sublabel">下一页</div><div class="pagination-nav__label">CPU 和内存分配</div></a></nav></div></div><div class="col col--3"><div class="tableOfContents_bqdL thin-scrollbar theme-doc-toc-desktop"><ul class="table-of-contents table-of-contents__left-border"><li><a href="#rancher-25-的新功能" class="table-of-contents__link toc-highlight">Rancher 2.5 的新功能</a></li><li><a href="#istio-附带的工具" class="table-of-contents__link toc-highlight">Istio 附带的工具</a><ul><li><a href="#kiali" class="table-of-contents__link toc-highlight">Kiali</a></li><li><a href="#jaeger" class="table-of-contents__link toc-highlight">Jaeger</a></li></ul></li><li><a href="#先决条件" class="table-of-contents__link toc-highlight">先决条件</a></li><li><a href="#设置指南" class="table-of-contents__link toc-highlight">设置指南</a></li><li><a href="#卸载-istio" class="table-of-contents__link toc-highlight">卸载 Istio</a></li><li><a href="#访问可视化" class="table-of-contents__link toc-highlight">访问可视化</a></li><li><a href="#架构" class="table-of-contents__link toc-highlight">架构</a><ul><li><a href="#多个-ingress" class="table-of-contents__link toc-highlight">多个 Ingress</a></li><li><a href="#egress-支持" class="table-of-contents__link toc-highlight">Egress 支持</a></li></ul></li><li><a href="#在-rke2-集群上安装-istio-的其他步骤" class="table-of-contents__link toc-highlight">在 RKE2 集群上安装 Istio 的其他步骤</a></li><li><a href="#在离线环境中升级-istio" class="table-of-contents__link toc-highlight">在离线环境中升级 Istio</a></li></ul></div></div></div></div></main></div></div><footer class="footer footer--dark"><div class="container container-fluid"><div class="footer__bottom text--center"><div class="footer__copyright">Copyright © 2023 SUSE Rancher. All Rights Reserved.</div></div></div></footer></div>
|
||
<script src="/zh/assets/js/runtime~main.9a7dea44.js"></script>
|
||
<script src="/zh/assets/js/main.50802f1f.js"></script>
|
||
</body>
|
||
</html> |