Chuyển đến nội dung chính

BÀI 26: ISTIO GATEWAY VÀ INGRESS CHO PRODUCTION

Cấu hình Istio Gateway cho external access, TLS termination với cert-manager, multi-domain hosting, CORS, WebSocket support, và Kubernetes Gateway API.

🔒 DevSecOps — Bài 26 BÀI 26: ISTIO GATEWAY VÀ INGRESS CHO PRODUCTION

Deploy Microservices On-Premises với Kubernetes HA

Phần 6: Service Mesh & Ingress với Istio

xdev.asia

🎯 MỤC TIÊU BÀI HỌC

  • ✅ Cấu hình Istio Gateway cho external traffic
  • ✅ TLS termination với cert-manager (Let's Encrypt)
  • ✅ Multi-domain hosting
  • ✅ CORS, WebSocket, gRPC support
  • ✅ Kubernetes Gateway API (tương lai)

PHẦN 1: ISTIO GATEWAY


External Traffic Flow:

                   ┌──────────────┐
Internet ──────►   │  MetalLB     │
                   │  LoadBalancer │
                   └──────┬───────┘
                          │
                   ┌──────▼───────┐
                   │  Istio       │
                   │  Ingress     │
                   │  Gateway     │  ← Gateway CRD
                   └──────┬───────┘
                          │
              ┌───────────┼───────────┐
              │           │           │
       ┌──────▼──┐ ┌──────▼──┐ ┌─────▼───┐
       │  api.   │ │  web.   │ │ admin.  │
       │  app.com│ │ app.com │ │ app.com │
       └─────────┘ └─────────┘ └─────────┘
         (VirtualService routing per host)

1.1. Basic Gateway

# gateway.yaml:
apiVersion: networking.istio.io/v1
kind: Gateway
metadata:
  name: main-gateway
  namespace: istio-system
spec:
  selector:
    istio: ingressgateway        # Matches Istio ingress gateway pods
  servers:
    # HTTPS (port 443):
    - port:
        number: 443
        name: https
        protocol: HTTPS
      tls:
        mode: SIMPLE
        credentialName: main-tls-cert  # K8s Secret (cert-manager)
      hosts:
        - "api.myapp.com"
        - "web.myapp.com"
        - "admin.myapp.com"
# HTTP → HTTPS redirect:
- port:
    number: 80
    name: http
    protocol: HTTP
  tls:
    httpsRedirect: true
  hosts:
    - "api.myapp.com"
    - "web.myapp.com"
    - "admin.myapp.com"

1.2. VirtualService cho Gateway

# vs-api.yaml:
apiVersion: networking.istio.io/v1
kind: VirtualService
metadata:
  name: api-routes
  namespace: default
spec:
  hosts:
    - "api.myapp.com"
  gateways:
    - istio-system/main-gateway
  http:
    - match:
        - uri:
            prefix: /api/v1/orders
      route:
        - destination:
            host: order-service
            port:
              number: 8080
      corsPolicy:
        allowOrigins:
          - exact: "https://web.myapp.com"
        allowMethods:
          - GET
          - POST
          - PUT
          - DELETE
        allowHeaders:
          - Authorization
          - Content-Type
        maxAge: "24h"
- match:
    - uri:
        prefix: /api/v1/payments
  route:
    - destination:
        host: payment-service
        port:
          number: 8080

- match:
    - uri:
        prefix: /api/v1/users
  route:
    - destination:
        host: user-service
        port:
          number: 8080

vs-web.yaml:

apiVersion: networking.istio.io/v1 kind: VirtualService metadata: name: web-routes namespace: default spec: hosts: - "web.myapp.com" gateways: - istio-system/main-gateway http: - route: - destination: host: frontend port: number: 3000


PHẦN 2: TLS VỚI CERT-MANAGER

2.1. Install cert-manager

# Install cert-manager:
helm repo add jetstack https://charts.jetstack.io
helm repo update

helm install cert-manager jetstack/cert-manager
--namespace cert-manager
--create-namespace
--set crds.enabled=true
--set prometheus.enabled=true

2.2. ClusterIssuer (Let's Encrypt)

# cluster-issuer.yaml:
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
  name: letsencrypt-prod
spec:
  acme:
    server: https://acme-v02.api.letsencrypt.org/directory
    email: [email protected]
    privateKeySecretRef:
      name: letsencrypt-prod-key
    solvers:
      - http01:
          ingress:
            class: istio
---
# Self-signed CA (for internal services):
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
  name: cluster-ca-issuer
spec:
  selfSigned: {}

2.3. Certificate cho Gateway

# certificate.yaml:
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
  name: main-tls-cert
  namespace: istio-system           # Same namespace as Gateway
spec:
  secretName: main-tls-cert         # Referenced in Gateway credentialName
  issuerRef:
    name: letsencrypt-prod
    kind: ClusterIssuer
  commonName: myapp.com
  dnsNames:
    - "api.myapp.com"
    - "web.myapp.com"
    - "admin.myapp.com"
    - "*.myapp.com"                  # Wildcard
  duration: 2160h                    # 90 days
  renewBefore: 360h                  # Renew 15 days before expiry
# Verify certificate:
kubectl -n istio-system get certificate
# NAME            READY   SECRET           AGE
# main-tls-cert   True    main-tls-cert    5m

kubectl -n istio-system describe certificate main-tls-cert
# Status: True
# Not After: 2024-xx-xx

PHẦN 3: WEBSOCKET & gRPC

3.1. WebSocket Support

# WebSocket qua Istio Gateway:
apiVersion: networking.istio.io/v1
kind: VirtualService
metadata:
  name: websocket-routes
  namespace: default
spec:
  hosts:
    - "ws.myapp.com"
  gateways:
    - istio-system/main-gateway
  http:
    - match:
        - uri:
            prefix: /ws
          headers:
            upgrade:
              exact: websocket
      route:
        - destination:
            host: notification-service
            port:
              number: 8080
      timeout: 0s                    # No timeout for WebSocket

3.2. gRPC Support

# gRPC routing:
apiVersion: networking.istio.io/v1
kind: Gateway
metadata:
  name: grpc-gateway
  namespace: istio-system
spec:
  selector:
    istio: ingressgateway
  servers:
    - port:
        number: 443
        name: grpc-tls
        protocol: HTTPS
      tls:
        mode: SIMPLE
        credentialName: grpc-tls-cert
      hosts:
        - "grpc.myapp.com"
---
apiVersion: networking.istio.io/v1
kind: VirtualService
metadata:
  name: grpc-routes
spec:
  hosts:
    - "grpc.myapp.com"
  gateways:
    - istio-system/grpc-gateway
  http:
    - match:
        - uri:
            prefix: /order.OrderService
      route:
        - destination:
            host: order-grpc-service
            port:
              number: 50051

PHẦN 4: KUBERNETES GATEWAY API (TƯƠNG LAI)

# Gateway API (replacing Ingress & Istio Gateway):
# More standardized, portable across mesh implementations

apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
  name: main-gateway
  namespace: default
spec:
  gatewayClassName: istio           # Istio implementation
  listeners:
    - name: https
      port: 443
      protocol: HTTPS
      tls:
        mode: Terminate
        certificateRefs:
          - name: main-tls-cert
      allowedRoutes:
        namespaces:
          from: All
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: api-routes
spec:
  parentRefs:
    - name: main-gateway
  hostnames:
    - "api.myapp.com"
  rules:
    - matches:
        - path:
            type: PathPrefix
            value: /api/v1/orders
      backendRefs:
        - name: order-service
          port: 8080

💡 KEY TAKEAWAYS

  1. Gateway: Entry point cho external traffic, TLS termination
  2. VirtualService: Route traffic từ Gateway → backend services
  3. cert-manager: Auto-provision & renew TLS certificates
  4. Multi-domain: Single Gateway, multiple VirtualServices
  5. Gateway API: Future standard, replacing both Ingress and Istio Gateway

🎯 BÀI TẬP

Bài tập 1: Production Gateway

  • Configure Gateway with TLS (cert-manager)
  • Route 3 domains to different services
  • Test HTTPS redirect

Bài tập 2: CORS & Security Headers

  • Configure CORS policy cho API
  • Add security headers (HSTS, CSP, X-Frame-Options)

📚 BÀI TIẾP THEO

Trong Bài 27: Istio Security — AuthorizationPolicy và RequestAuthentication, chúng ta sẽ cấu hình security policies, JWT validation, và network segmentation.