如何使用 Istio 服务网格从 Kubernetes 集群内部访问外部 SMTP 服务器

How to access external SMTP server from within Kubernetes cluster with Istio Service Mesh

我有一个 kubernetes 集群,它在 Istio 服务网格中有应用程序 运行。在一个应用程序中,我尝试使用 SMTP 发送电子邮件。如何设置 Istio 规则以允许我的应用程序使用我的外部 SMTP 服务器?

最初我得到了一个异常"Could not connect to SMTP host: in-v3.mailjet.com, port: 587, response: -1.",详情here。访问这个网站后,我意识到我需要提供出口规则,我按照下面的方式做了

apiVersion: networking.istio.io/v1alpha3
kind: ServiceEntry
metadata:
  name: mailjet
spec:
  hosts:
  - "in-v3.mailjet.com"
  location: MESH_EXTERNAL
  ports:
  - number: 587
    name: tls
    protocol: TLS
  resolution: DNS
---
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: mailjet
spec:
  hosts:
  - "*.mailjet.com"
  tls:
  - match:
    - port: 587
      sni_hosts:
      - "*.mailjet.com"
    route:
    - destination:
        host: "*.mailjet.com"
        port:
          number: 587
      weight: 100

我不再收到 "Could not connect to SMTP host" 异常,但收到 SocketTieoutException

[0m[31m06:56:39,048 ERROR [stderr] (default task-55)  at org.jboss.threads.EnhancedQueueExecutor$ThreadBody.doRunTask(EnhancedQueueExecutor.java:1487)
[0m[31m06:56:39,048 ERROR [stderr] (default task-55)  at org.jboss.threads.EnhancedQueueExecutor$ThreadBody.run(EnhancedQueueExecutor.java:1378)
[0m[31m06:56:39,048 ERROR [stderr] (default task-55)  at java.lang.Thread.run(Thread.java:748)
[0m[31m06:56:39,048 ERROR [stderr] (default task-55) Caused by: javax.mail.MessagingException: Exception reading response;
[0m[31m06:56:39,048 ERROR [stderr] (default task-55)   nested exception is:
[0m[31m06:56:39,048 ERROR [stderr] (default task-55)  java.net.SocketTimeoutException: Read timed out
[0m[31m06:56:39,048 ERROR [stderr] (default task-55)  at com.sun.mail.smtp.SMTPTransport.readServerResponse(SMTPTransport.java:2460)
[0m[31m06:56:39,048 ERROR [stderr] (default task-55)  at com.sun.mail.smtp.SMTPTransport.openServer(SMTPTransport.java:2187)
[0m[31m06:56:39,048 ERROR [stderr] (default task-55)  at com.sun.mail.smtp.SMTPTransport.protocolConnect(SMTPTransport.java:740)
[0m[31m06:56:39,048 ERROR [stderr] (default task-55)  at javax.mail.Service.connect(Service.java:366)
[0m[31m06:56:39,049 ERROR [stderr] (default task-55)  at javax.mail.Service.connect(Service.java:246)
[0m[31m06:56:39,049 ERROR [stderr] (default task-55)  at javax.mail.Service.connect(Service.java:267)
[0m[31m06:56:39,049 ERROR [stderr] (default task-55)  at org.keycloak.email.DefaultEmailSenderProvider.send(DefaultEmailSenderProvider.java:138)
[0m[31m06:56:39,049 ERROR [stderr] (default task-55)  ... 73 more
[0m[31m06:56:39,049 ERROR [stderr] (default task-55) Caused by: java.net.SocketTimeoutException: Read timed out
[0m[31m06:56:39,049 ERROR [stderr] (default task-55)  at java.net.SocketInputStream.socketRead0(Native Method)
[0m[31m06:56:39,049 ERROR [stderr] (default task-55)  at java.net.SocketInputStream.socketRead(SocketInputStream.java:116)
[0m[31m06:56:39,049 ERROR [stderr] (default task-55)  at java.net.SocketInputStream.read(SocketInputStream.java:171)
[0m[31m06:56:39,049 ERROR [stderr] (default task-55)  at java.net.SocketInputStream.read(SocketInputStream.java:141)
[0m[31m06:56:39,049 ERROR [stderr] (default task-55)  at com.sun.mail.util.TraceInputStream.read(TraceInputStream.java:126)
[0m[31m06:56:39,049 ERROR [stderr] (default task-55)  at java.io.BufferedInputStream.fill(BufferedInputStream.java:246)
[0m[31m06:56:39,049 ERROR [stderr] (default task-55)  at java.io.BufferedInputStream.read(BufferedInputStream.java:265)
[0m[31m06:56:39,049 ERROR [stderr] (default task-55)  at com.sun.mail.util.LineInputStream.readLine(LineInputStream.java:106)
[0m[31m06:56:39,049 ERROR [stderr] (default task-55)  at com.sun.mail.smtp.SMTPTransport.readServerResponse(SMTPTransport.java:2440)
[0m[31m06:56:39,049 ERROR [stderr] (default task-55)  ... 79 more
[0m[31m06:56:39,049 ERROR [org.keycloak.services.resources.admin.RealmAdminResource] (default task-55) Failed to send email
 javax.mail.MessagingException: Exception reading response;
  nested exception is:
        java.net.SocketTimeoutException: Read timed out

我需要做什么才能在具有 Istio 服务网格的 Kubernetes 集群中成功发送电子邮件?

在与 Mesh-external service entry for an external MySQL instance 进行比较后,我设法使用 TCP 如下所示使其正常工作。我尝试使用 IP 地址进行 TLS,但没有成功。但是,如果我不必指定 IP 地址,那就太好了

apiVersion: networking.istio.io/v1alpha3
kind: ServiceEntry
metadata:
  name: mailjet
spec:
  hosts:
  - in-v3.mailjet.com
  addresses:
  - 104.199.96.85/32
  ports:
  - name: tls
    number: 587
    protocol: tcp
  location: MESH_EXTERNAL
---
apiVersion: networking.istio.io/v1alpha3
kind: VirtualService
metadata:
  name: mailjet
spec:
  hosts:
  - in-v3.mailjet.com
  tcp:
  - match:
    - port: 587
    route:
    - destination:
        host: in-v3.mailjet.com
        port:
          number: 587 
---