Acessing an external proxy from the Istio egress gateway

Viewed 493

I'd need to tightly control all traffic to external sites from the applications in the K8S namespace. As the K8S NetworkPolicy objects allow specifying target IP addresses only we'd prefer using Istio to mange the outgoing traffic so that we can use hostnames instead of CIDRs to configure our external services. Furthermore we have an enterprise wide proxy which must be used for all traffic to the internet.

Following https://istio.io/latest/docs/tasks/traffic-management/egress/http-proxy/ we could manage that the sidecar of the pod (with the proper environment variables HTTP_PROXY etc. set) can access the internet via the corporate proxy. This means that the communication POD --> sidecar --> proxy --> external site works. However in this case the Istio egress gateway is bypassed.

What we'd however need is the following communication path: POD --> sidecar --> Istio egress gateway --> proxy --> external site.

Out current setup is the following:

  • The PODs have the HTTP_PROXY env. variable set to proxy.int.xxx.zz:8080
  • We have the following yamls applied:
apiVersion: networking.istio.io/v1beta1
kind: ServiceEntry
metadata:
  name: proxylb
spec:
  hosts:
    - proxy.int.xxx.zz
  ports:
    - number: 8080
      name: tcp
      protocol: TCP
  location: MESH_EXTERNAL
  resolution: DNS
---
apiVersion: networking.istio.io/v1alpha3
kind: ServiceEntry
metadata:
  name: cnn
spec:
  hosts:
    - edition.cnn.com
  ports:
    - number: 80
      name: http-port
      protocol: HTTP
    - number: 443
      name: tls
      protocol: TLS
  resolution: DNS
---
apiVersion: networking.istio.io/v1alpha3
kind: ServiceEntry
metadata:
  name: orf
spec:
  hosts:
    - www.orf.at
  ports:
    - number: 80
      name: http-port
      protocol: HTTP
    - number: 443
      name: tls
      protocol: TLS
  resolution: DNS
---
apiVersion: networking.istio.io/v1alpha3
kind: Gateway
metadata:
  name: istio-egressgateway
spec:
  selector:
    istio: egressgateway
  servers:
    - port:
        number: 80
        name: http
        protocol: HTTP
      hosts:
        - edition.cnn.com
        - www.orf.at
    - port:
        number: 443
        name: tls
        protocol: TLS
      hosts:
        - edition.cnn.com
        - www.orf.at
      tls:
        mode: PASSTHROUGH
    - port:
        number: 8080
        name: tcp
        protocol: TCP
      hosts:
        - proxy.int.xxx.zz
---
apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
  name: istio-egressgateway
spec:
  host: istio-egressgateway.istio-system.svc.cluster.local
  subsets:
    - name: cnn
    - name: orf
    - name: proxylb
---
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: direct-cnn-through-egress-gateway
spec:
  hosts:
    - edition.cnn.com
  gateways:
    - mesh
    - istio-egressgateway
  tls:
    - match:
        - gateways:
            - mesh
          port: 443
          sniHosts:
            - edition.cnn.com
      route:
        - destination:
            host: istio-egressgateway.istio-system.svc.cluster.local
            subset: cnn
            port:
              number: 443
    - match:
        - gateways:
            - istio-egressgateway
          port: 443
          sniHosts:
            - edition.cnn.com
      route:
        - destination:
            host: edition.cnn.com
            port:
              number: 443
          weight: 100
  http:
    - match:
        - gateways:
            - mesh
          port: 80
      route:
        - destination:
            host: istio-egressgateway.istio-system.svc.cluster.local
            subset: cnn
            port:
              number: 80
          weight: 100
    - match:
        - gateways:
            - istio-egressgateway
          port: 80
      route:
        - destination:
            host: edition.cnn.com
            port:
              number: 80
          weight: 100
---
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: direct-orf-through-egress-gateway
spec:
  hosts:
    - www.orf.at
  gateways:
    - mesh
    - istio-egressgateway
  tls:
    - match:
        - gateways:
            - mesh
          port: 443
          sniHosts:
            - www.orf.at
      route:
        - destination:
            host: istio-egressgateway.istio-system.svc.cluster.local
            subset: orf
            port:
              number: 443
    - match:
        - gateways:
            - istio-egressgateway
          port: 443
          sniHosts:
            - www.orf.at
      route:
        - destination:
            host: www.orf.at
            port:
              number: 443
          weight: 100
  http:
    - match:
        - gateways:
            - mesh
          port: 80
      route:
        - destination:
            host: istio-egressgateway.istio-system.svc.cluster.local
            subset: orf
            port:
              number: 80
          weight: 100
    - match:
        - gateways:
            - istio-egressgateway
          port: 80
      route:
        - destination:
            host: www.orf.at
            port:
              number: 80
          weight: 100
---
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: direct-proxylb-through-egress-gateway
spec:
  hosts:
    - proxy.int.xxx.zz
  gateways:
    - mesh
    - istio-egressgateway
  tcp:
    - match:
        - gateways:
            - mesh
          port: 8080
      route:
        - destination:
            host: istio-egressgateway.istio-system.svc.cluster.local
            subset: proxylb
            port:
              number: 8080
          weight: 100
    - match:
        - gateways:
            - istio-egressgateway
          port: 8080
      route:
        - destination:
            host: proxy.int.xxx.zz
            port:
              number: 8080
          weight: 100

---
apiVersion: networking.istio.io/v1alpha3
kind: Sidecar
metadata:
  name: trilateral
spec:
  egress:
    - hosts:
        - "./*"
  outboundTrafficPolicy:
    mode: REGISTRY_ONLY

However when running a curl we get:

 curl -k -I https://istio.io
curl: (56) Recv failure: Connection reset by peer

Should this setup work? What is missing?

Thanks a lot in advance for any hint.

0 Answers
Related