You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kind集群中APISIX Ingress Controller请求路由失败求助

在KIND集群中APISIX Ingress路由连接重置问题排查

环境与配置

已在本地KIND Kubernetes集群部署Spring Boot应用,集成APISIX网关Ingress Controller:

  • APISIX网关已安装配置,端口8090
  • Ingress已转换为APISIX路由,目标应用client-app Service端点正常

核心配置清单

Ingress YAML

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: httpserver-ingress
  namespace: oidcapp
spec:
  ingressClassName: apisix
  rules:
  - host: authclient.com
    http:
      paths:
      - backend:
          service:
            name: client-app
            port:
              number: 80
        path: /oidcapp
        pathType: Prefix

目标应用Service详情

$ kubectl describe svc -n oidcapp client-app 
Name:                     client-app
Namespace:                oidcapp
Labels:                   app=client-app
Annotations:              <none>
Selector:                 app=client-app
Type:                     ClusterIP
IP Family Policy:         SingleStack
IP Families:              IPv4
IP:                       10.96.136.11
IPs:                      10.96.136.11
Port:                     http  80/TCP
TargetPort:               8080/TCP
Endpoints:                10.244.1.23:8080
Session Affinity:         None
Internal Traffic Policy:  Cluster

APISIX路由映射

{
    "createdIndex": 11332,
    "key": "/apisix/routes/33d660f9",
    "modifiedIndex": 11532,
    "value": {
        "priority": 0,
        "status": 1,
        "uris": [
            "/oidcapp",
            "/oidcapp/*"
        ],
        "name": "ing_oidcapp_httpserver-ingress_4cafc3f3",
        "id": "33d660f9",
        "upstream_id": "fdcb23fc",
        "host": "authclient.com",
        "create_time": 1744820603,
        "update_time": 1744851162,
        "desc": "Created by apisix-ingress-controller, DO NOT modify it manually",
        "labels": {
            "managed-by": "apisix-ingress-controller"
        }
    }
}

LoadBalancer Service配置

kind: Service
apiVersion: v1
metadata:
  name: apisix-gateway-service
  namespace: apisix
spec:
  type: LoadBalancer
  selector:
    app.kubernetes.io/name: apisix
  ports:
  - port: 5678
    targetPort: 8090

本地Hosts映射

172.18.0.2      authclient.com

APISIX命名空间Service列表

$ kubectl get svc -n apisix

NAME                     TYPE           CLUSTER-IP      EXTERNAL-IP   PORT(S)             AGE
apisix-admin             ClusterIP      10.96.220.99    <none>        9180/TCP            7d18h
apisix-gateway-service   LoadBalancer   10.96.183.128   172.18.0.2    5678:31448/TCP      80m
etcd-headless            ClusterIP      None            <none>        2379/TCP,2380/TCP   7d18h

问题现象

执行curl -v http://authclient.com:5678/oidcapp时出现连接重置:

$ curl -v http://authclient.com:5678/oidcapp
*   Trying 172.18.0.2:5678...
* TCP_NODELAY set
* Connected to authclient.com (172.18.0.2) port 5678 (#0)
> GET /oidcapp HTTP/1.1
> Host: authclient.com:5678
> User-Agent: curl/7.68.0
> Accept: */*
> 
* Recv failure: Connection reset by peer
* Closing connection 0
curl: (56) Recv failure: Connection reset by peer

预期请求链路:cURL → Kind LoadBalancer → APISIX → client-app,但负载均衡器与APISIX Ingress Controller日志无有效排查信息。

排查与解决方案

1. 验证APISIX容器端口映射

检查APISIX Pod的端口配置,确认8090是否为实际监听的HTTP协议端口:

kubectl describe pod -n apisix <apisix-pod-name> | grep -A5 Ports

APISIX默认HTTP端口为9080,HTTPS为9443,若8090不是正确的HTTP端口,需调整LoadBalancer的targetPort为9080。

2. 测试链路连通性

  • 直接在APISIX Pod内测试后端应用连通性:
kubectl exec -n apisix <apisix-pod-name> -- curl http://10.244.1.23:8080/oidcapp
  • 本地访问NodePort跳过LoadBalancer测试:
curl -v http://172.18.0.2:31448/oidcapp -H "Host: authclient.com"

3. 修正Host请求头

当前curl请求的Host头包含端口authclient.com:5678,但APISIX路由匹配的Host是authclient.com,需去掉端口:

curl -v http://authclient.com:5678/oidcapp -H "Host: authclient.com"

4. 检查APISIX上游状态

通过APISIX Admin API查询对应上游fdcb23fc的配置与状态:

curl http://<apisix-admin-ip>:9180/apisix/admin/upstreams/fdcb23fc -H "X-API-Key: <your-api-key>"

若上游状态异常,检查client-app端点是否可访问,或集群网络策略是否限制APISIX与后端通信。

5. 查看APISIX Pod日志

直接查看APISIX Pod的访问日志和错误日志,获取连接重置的具体原因:

kubectl logs -n apisix <apisix-pod-name> -f
kubectl logs -n apisix <apisix-pod-name> -f -p # 查看历史容器日志

内容的提问来源于stack exchange,提问作者Mandar K

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 09:59:56