Istio - load balance mesh internal HTTP2 traffic to non-standard port

Viewed 176

I want to load balance per request a mesh internal HTTP2 traffic coming to my ClusterIP Service over all its available replicas, using Istio; the first iteration is intended to work between two deployments within a single namespace, but I can't quite get there. I need to load balance on a non-standard port, I'm using standard port as a control group.

I was able to configure Istio so that requests from one long-lived connection to the service FQDN to standard port 80 are round robin'd correctly, but long-lived connection to a non-standard port such as 13080 will not round robin, instead a single pod will get all the requests (the behaviour looks like the K8s "iptables random" approach used in Service which only balances per connection, not per request).

Here's my most successful VirtualService definition yet:

apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: vs
  namespace: example
spec:
  gateways:
  - mesh
  hosts:
  - "*.example.com"
  http:
  - match:
    - authority:
        regex: "(.*.)?pods.example.com(:80)?"
    route:
    - destination:
        host: pods.example.svc.cluster.local
        port:
          number: 80
  - match:
    - authority:
        regex: "(.*.)?pods.example.com:13080"
    route:
    - destination:
        host: pods.example.svc.cluster.local
        port:
          number: 13080

Ports are defined in the Service like this:

  - name: http2
    port: 80
    protocol: TCP
    targetPort: 80
  - name: http2-nonstd
    port: 13080
    protocol: TCP
    targetPort: 13080

Using Istio 1.6.2. What am I missing?

EDIT: The original question had a typo in the VirtualService definition authority match for the port 13080 - there was exact instead of regex. Nothing changed, however. This supports the hypothesis that for some reason Istio ignores the non-standard port.

0 Answers
Related