'Duplicate entries for key' error when creating an Istio IngrressGateway on EKS

Viewed 425

I'm trying to create an Istio ingress gateway (istio: 1.9.1, EKS: 1.18) with a duplicate targetPort like this:

apiVersion: install.istio.io/v1alpha1
kind: IstioOperator
metadata:
  name: istio
spec:
  components:
    ingressGateways:
      - name: ingressgateway
        k8s:
          service:
            ports:
              - port: 80
                targetPort: 8080
                name: http2
              - port: 443
                name: https
                targetPort: 8080

but I get the error:

- Processing resources for Ingress gateways.
✘ Ingress gateways encountered an error: failed to update resource with server-side apply for obj Deployment/istio-system/istio: failed to create typed patch object: errors:
.spec.template.spec.containers[name="istio-proxy"].ports: duplicate entries for key [containerPort=8080,protocol="TCP"]

I am running Istio in EKS so we terminate TLS at the NLB, so all traffic (http and https) should go to the pod on the same port (8080)

Any ideas how I can solve this issue?

2 Answers

Had to use different targetPorts in the end to get this working

Until the istio 1.8 version, this type of configuration worked (although with initial problems) - github #53526.

As of version 1.9 an error is generated and you can no longer use two of the same ports in one definition. There have also been created (or reopened) reports on github:

However, the issue is with an outdated version of Kubernetes and Istio at the time of writing the response.

Possible workarounds:

  • Use different targetPort
  • Upgrade Kubernetes and Istio to newest versions.
Related