Podman容器端口绑定正常却无法通过localhost/主机IP访问求助
Podman容器Node.js服务无法通过localhost:443访问,但私有IP可连通的问题排查
我用Podman创建了运行Node.js Web服务器的容器,发现无法通过localhost:443访问容器服务,但能通过容器私有IP(如10.88.0.5:443)连通。
测试现象
访问私有IP的结果
执行命令:
curl https://10.88.0.5
返回:
curl: (60) SSL certificate problem: unable to get local issuer certificate More details here: https://curl.se/docs/sslcerts.html curl failed to verify the legitimacy of the server and therefore could not establish a secure connection to it. To learn more about this situation and how to fix it, please visit the web page mentioned above
注:此失败仅因为SSL证书是为我的域名颁发的,但至少能确认网络已连通到网站服务。
访问localhost的结果
执行命令:
curl https://localhost --connect-timeout 5
返回:
curl: (28) SSL connection timeout
直接出现连接超时。
端口绑定验证
查看主机端口监听情况:
sudo netstat -tulp | grep https
输出显示443端口已被conmon监听:
tcp 12 0 0.0.0.0:https 0.0.0.0:* LISTEN 4991/conmon
Podman端口映射确认:
sudo podman port -l
输出:
443/tcp -> 0.0.0.0:443
容器配置文件(Containerfile)
FROM node:22.2.0 WORKDIR /app COPY package*.json ./ RUN npm install COPY . . EXPOSE 443 CMD ["node", "."]
已明确暴露443端口。
容器网络配置
[ { "name": "podman", "id": "2f259bab93aaaaa2542ba43ef33eb990d0999ee1b9924b557b7be53c0b7a1bb9", "driver": "bridge", "network_interface": "podman0", "created": "2024-07-10T12:43:23.144060349-04:00", "subnets": [ { "subnet": "10.88.0.0/16", "gateway": "10.88.0.1" } ], "ipv6_enabled": false, "internal": false, "dns_enabled": false, "ipam_options": { "driver": "host-local" } } ]
主机路由表信息
Kernel IP routing table Destination Gateway Genmask Flags Metric Ref Use Iface default mynetwork 0.0.0.0 UG 0 0 0 eno2 10.88.0.0 0.0.0.0 255.255.0.0 U 0 0 0 podman0 172.17.0.0 0.0.0.0 255.255.0.0 U 0 0 0 docker0 192.168.100.0 0.0.0.0 255.255.255.0 U 0 0 0 eno2 192.168.122.0 0.0.0.0 255.255.255.0 U 0 0 0 virbr0
已尝试的无效操作
- 禁用UFW防火墙
- 重新安装Podman
目前已排查4天仍未解决,求可行的解决方案或排查方向。
注:运行环境为最新版Debian系统。
内容的提问来源于stack exchange,提问作者Cohen Schellenberg
相关产品推荐
相关产品推荐

