You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何解决部署到Minikube时出现的localhost:8080连接拒绝错误?

问题:GitLab CI部署Angular应用到Minikube失败,报错连接localhost:8080被拒绝

我尝试通过gitlab-ci.yml将Angular应用部署到minikube中,流水线的install、test、build阶段均顺利完成,但最后一个deploy阶段持续失败,报错信息如下:

error: error validating "kubernetes/deployment.yaml": error validating data: failed to download openapi: Get "http://localhost:8080/openapi/v2?timeout=32s": dial tcp [::1]:8080: connect: connection refused; if you choose to ignore these errors, turn validation off with --validate=false

我的gitlab-ci.yml文件内容:

stages:
  - install
  - test
  - build
  - deploy

include: 'ci/variables/default.yml'

install_dependencies:
  image: node:20.18.0-slim
  stage: install
  tags:
    - ci
  script:
    - npm config set registry ${CI_NPM_REGISTRY}
    - npm install
    - echo "Variables are '$CI_PROJECT_DIR' and '$CI_REGISTRY_IMAGE'"
  cache:
    paths:
      - node_modules/
  artifacts:
    expire_in: 1 days
    when: on_success
    paths:
      - node_modules/
  before_script:
    - npm ci --cache .npm --prefer-offline

test_app:
  stage: test
  tags:
    - ci
  script:
    - npm run test-headless
    - echo "Unit Test Job" || export failure=1

build_app:
  stage: build
  tags:
    - build
  # Use the official docker image.
  image: docker:latest
  services:
    - docker:dind
  before_script:
    - docker login -u "$CI_REGISTRY_USER" -p "$CI_REGISTRY_PASSWORD" $CI_REGISTRY
    - echo "folder before cd:"
        - ls
        - cd sinc-shop
        - "CHECK CHECK - '$CI_COMMIT_SHA'"
  script:
    # Docker: Builds a Docker image for the Angular app and pushes it to the GitLab Container Registry.
    - docker build --pull -t "$CI_REGISTRY_IMAGE:$CI_COMMIT_SHA" .
    - docker push "$CI_REGISTRY_IMAGE:$CI_COMMIT_SHA"
    - chmod +x ci/scripts/test-script.sh
    - ci/scripts/test-script.sh "VARIABLE_A" "VARIABLE_B"

  # Run this job where a Dockerfile exists
  rules:
    - if: $CI_COMMIT_BRANCH
      exists:
        - Dockerfile

deploy_prod:
  stage: deploy
  image:
    name: bitnami/kubectl
    entrypoint: [""]
  
  script:
    - kubectl apply -f kubernetes/deployment.yaml
    - kubectl apply -f kubernetes/service.yaml

  environment:
    name: production
    url: http://localhost:8080
    kubernetes:
      namespace: default
  only:
    - main

我已配置并连接了用于Kubernetes的gitlab-agent,同时查阅了Minikube官方文档及相关类似问题,但所有建议的解决方案均无效,问题仍存在。

我的.kube/config文件内容:

apiVersion: v1
clusters:
- cluster:
    certificate-authority: /Users/userName/.minikube/ca.crt
    extensions:
    - extension:
        last-update: Wed, 18 Dec 2024 07:43:12 CET
        provider: minikube.sigs.k8s.io
        version: v1.34.0
      name: cluster_info
    server: https://127.0.0.1:59349
  name: minikube
contexts:
- context:
    cluster: minikube
    extensions:
    - extension:
        last-update: Wed, 18 Dec 2024 07:43:12 CET
        provider: minikube.sigs.k8s.io
        version: v1.34.0
      name: context_info
    namespace: default
    user: minikube
  name: minikube
current-context: minikube
kind: Config
preferences: {}
users:
- name: minikube
  user:
    client-certificate: /Users/userName/.minikube/profiles/minikube/client.crt
    client-key: /Users/userName/.minikube/profiles/minikube/client.key

解决方案

核心问题

报错的本质是GitLab CI的kubectl容器无法连接到Minikube的Kubernetes API服务器:

  • CI作业的容器是隔离环境,默认没有本地的.kube/config配置,所以kubectl会尝试连接默认的http://localhost:8080,但该地址在CI容器内没有K8s API服务,导致连接被拒绝。
  • 即便你配置了GitLab Agent,也可能存在Agent未正确注入集群配置、或CI作业未关联到Agent的问题。

具体修复步骤

1. 修正GitLab Agent的关联配置

如果你已经安装了GitLab Agent到Minikube集群,需要确保:

  • Agent已在GitLab项目的Settings > Infrastructure > Kubernetes clusters中完成注册,且状态为"Connected"。
  • 在deploy_prod作业中,通过kubernetes字段关联Agent,或者确保作业的tags与Agent配置的runner标签匹配。
  • 确保Agent的权限足够(至少有default namespace的edit权限)。

2. 手动注入正确的KubeConfig到CI作业

如果Agent方式未生效,可以手动将Minikube的集群配置导入CI环境:

  • 生成包含证书数据的KubeConfig:在本地执行minikube kubectl config view --raw,得到包含证书内容(而非本地文件路径)的完整配置内容,这样CI容器不需要访问本地证书文件。
  • 添加GitLab CI变量:在GitLab项目的Settings > CI/CD > Variables中添加变量KUBECONFIG_CONTENT,值为上面生成的raw KubeConfig内容,勾选"Mask variable"避免泄露敏感信息。
  • 修改deploy作业的script:
    deploy_prod:
      stage: deploy
      image:
        name: bitnami/kubectl
        entrypoint: [""]
      
      script:
        - echo "$KUBECONFIG_CONTENT" > ~/.kube/config
        - kubectl config use-context minikube
        - kubectl apply -f kubernetes/deployment.yaml
        - kubectl apply -f kubernetes/service.yaml
    
      environment:
        name: production
        url: http://$(minikube ip):<你的服务端口>  # 替换为Minikube对外IP和服务端口
        kubernetes:
          namespace: default
      only:
        - main
    

3. 修复Build作业的缩进错误

你的build_app作业中before_script存在缩进错误,导致命令无法正确执行(虽然你说前置阶段成功,但可能是复制时的格式问题),修正为:

before_script:
  - docker login -u "$CI_REGISTRY_USER" -p "$CI_REGISTRY_PASSWORD" $CI_REGISTRY
  - echo "folder before cd:"
  - ls
  - cd sinc-shop
  - echo "CHECK CHECK - '$CI_COMMIT_SHA'"

4. 修正环境URL配置

environment.url设置为http://localhost:8080是错误的,因为这是CI容器内的localhost,而非本地Minikube的地址。应该替换为Minikube的对外IP加上服务的端口,比如执行minikube ip得到IP,再结合服务的NodePort或LoadBalancer端口。


内容的提问来源于stack exchange,提问作者k.vincent

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 12:52:05