envoy作为南北向汇聚端时,必须禁用cds和lds,仅启用rds与eds;static_resources显式定义clusters/listeners,dynamic_resources中cds/lds设为disabled,rds指向稳定grpc端点,eds对接kubernetes endpoints或自建eds server,路由host匹配须用exact_match并严格校验cluster name与健康检查参数。

Envoy 作为南北向汇聚端时,必须禁用 xDS 的集群发现(CDS)和监听器发现(LDS)
直接复用 Istio 默认的 xDS 配置会让 Envoy 持续轮询控制平面,但你并不需要它动态管理内部服务集群——微服务间调用走的是东西向 mTLS mesh,而南北向(即外部流量进入网格)才需要 Envoy 做统一入口。此时应关闭 CDS/LDS,只启用 RDS(路由发现)和 EDS(端点发现),让路由规则由控制平面下发,后端实例列表则通过 EDS 从 Kubernetes endpoints 或 Consul 获取。
-
static_resources中显式定义clusters和listeners,避免依赖 xDS 动态加载 - 在
dynamic_resources中只保留ads_config+cds_config设为DISABLED、lds_config同样设为DISABLED - RDS 需指向一个稳定的 gRPC endpoint(如自建的 RDS server 或轻量级 control plane),EDS 则推荐对接
kubernetes://或eds_cluster类型 cluster
HTTP 路由配置里,host 匹配必须用 exact_match 而非 prefix_match
当多个微服务共用同一个 VIP/域名(如 api.example.com),靠 Host 头区分后端时,prefix_match 容易引发意外交叉路由。比如 prefix_match: "api." 会同时匹配 api.example.com 和 api-admin.example.com,后者本该走另一条链路。
- 所有
virtual_hosts的domains字段应写成完整域名,例如["api.example.com"],而非["*.example.com"] - 若需泛匹配,改用
regex_match并严格限定边界,如^api\.example\.com$ - 每个
route的cluster名必须与static_resources.clusters中定义的 name 完全一致,大小写敏感
健康检查失败导致 EDS 不返回任何端点?检查 cluster 的 outlier_detection 和 health_checks 配置冲突
常见现象是 Envoy 日志里反复出现 no healthy upstream hosts,但 kubectl get endpoints 显示正常。根本原因往往是 outlier_detection 的默认阈值(如 consecutive_5xx: 5)与 health_checks 的 timeout/failure_threshold 不匹配,导致端点刚上线就被驱逐。
- 关闭
outlier_detection(设为 empty object)或显式提高consecutive_gateway_failure至 10+ -
health_checks的timeout必须小于interval,且unhealthy_threshold≥healthy_threshold,否则 Envoy 无法稳定判定状态 - 若后端是 Go HTTP server,确保 handler 对
/healthz返回 200 且无中间件劫持(如 Gin 的 Recovery 中间件可能吞掉 panic 但不返回 200)
Go 微服务启动时如何主动注册到 Envoy 的 EDS?别依赖 annotation,用 xDS v3 API 主动上报
Kubernetes Service + Endpoints 机制延迟高、不可控,尤其在滚动发布时容易出现短暂 503。更可靠的方式是微服务启动后,通过 Envoy 的 EndpointDiscoveryService(EDS)v3 接口,将自身 IP:PORT 直接注册进指定 cluster。
- 使用
github.com/envoyproxy/go-control-plane提供的server.NewServer启一个轻量 control plane,仅暴露 EDS 接口 - Go 服务在
http.ListenAndServe前,调用edsClient.Fetch向该 control plane 发送DiscoveryRequest,携带本机 podIP 和 readiness port - Envoy 的 cluster 配置中,
type设为EDS,eds_cluster_config指向该 control plane 的 cluster name,而非service_name
这个路径绕开了 kube-apiserver 的 watch 延迟,也规避了 service mesh 控制平面的额外依赖,但要注意 EDS server 的可用性必须高于微服务本身——它挂了,整个南北向入口就不可用了。
golang免费学习笔记(深入):立即使用
在学习笔记中,你将探索golang的核心概念和高级技巧!











