连接Kubernetes上部署的REST服务时出现请求超时问题求助
Let’s break down the most likely issues and actionable checks to fix your timeout problem—since your Pods are running and the Service looks configured correctly at first glance, we’ll focus on the hidden gaps:
1. Confirm Service Selector Matches Pod Labels
This is the #1 cause of Service routing failures. Your Service uses selector: app: account-docker-kubernetes, but we need to verify your Pods actually carry this label.
Run this command to inspect your Pods' labels:
kubectl get pods --show-labels
Look for the app label on your account-docker-kubernetes-* Pods. If they don’t have app: account-docker-kubernetes, your Service isn’t linking to any Pods at all.
To fix this:
- Either update your Deployment/StatefulSet to add the
app: account-docker-kuberneteslabel to Pod templates - Or adjust your Service’s
selectorto match the existing labels on your Pods
2. Check if the Service Has Valid Endpoints
Even if the selector seems correct, let’s confirm the Service is actually connected to your Pods. Run:
kubectl describe service account-docker-kubernetes
Look for the Endpoints section in the output. It should list the IPs of your running Pods (e.g., 10.1.0.39:8082,10.1.0.40:8082). If this section is empty, that confirms the selector mismatch issue above.
3. Test Direct Connectivity to a Pod
Let’s rule out issues with the Pod’s service itself. From your local machine (if you can reach the Pod network) or from another Pod in the cluster, run:
curl http://10.1.0.39:8082/bank/health/
If this returns "UP", the Pod’s service is working, and the problem lies with the Service or network routing to the NodePort. If it fails, double-check that your Spring Boot app is binding to 0.0.0.0 (not 127.0.0.1—your logs show Tomcat starting on port 8082, which defaults to 0.0.0.0, but confirm your app config just in case).
4. Adjust NodePort Access for Docker Desktop
Docker Desktop’s Kubernetes setup has a network quirk on Windows/WSL2:
- Instead of using the node’s internal IP (
192.168.65.4), try accessinghttp://localhost:30163/bank/health/directly from your host machine. - If that still fails, ensure Docker Desktop hasn’t restricted port 30163—check Settings > Resources > Port Mapping (NodePort usually handles this automatically, but it’s worth verifying).
5. Double-Check Firewalls and Network Policies
Even though you mentioned the firewall is closed:
- Confirm no local Windows firewall rules are blocking inbound traffic on port 30163.
- If you have Kubernetes Network Policies in place, run
kubectl get networkpoliciesto ensure they aren’t blocking traffic to your Service or Pods.
内容的提问来源于stack exchange,提问作者Tony Cavanagh

