You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Akeyless Gateway在Docker Desktop的K8s部署中遇网络连通性问题

Akeyless Gateway网络连通性问题排查方案(Docker Desktop Kubernetes环境)

在Docker Desktop的Kubernetes集群中部署Akeyless Gateway时出现网络连通性问题,Pod日志显示No network connectivity, using existing artifacts,本地单独用Docker运行Gateway正常,已放行所有入站出站流量并检查端口。

Pod日志如下:

Starting up
No network connectivity, using existing artifacts
/usr/lib/python3/dist-packages/supervisor/options.py:473: UserWarning: Supervisord is running as root and it is searching for its configuration file in default locations (including its current working directory); you probably want to specify a "-c" argument specifying an absolute path to a configuration file for improved security.
self.warnings.warn(
2024-03-26 17:22:19,228 INFO Included extra file "/etc/supervisor/conf.d/base-supervisord.conf" during parsing
2024-03-26 17:22:19,228 INFO Included extra file "/etc/supervisor/conf.d/logrotate-cron-supervisord.conf" during parsing
2024-03-26 17:22:19,228 INFO Included extra file "/etc/supervisor/conf.d/rsyslog-supervisord.conf" during parsing
2024-03-26 17:22:19,228 INFO Included extra file "/etc/supervisor/conf.d/splunk-forwader-supervisord.conf" during parsing
2024-03-26 17:22:19,228 INFO Set uid to user 0 succeeded
2024-03-26 17:22:19,231 INFO RPC interface 'supervisor' initialized
2024-03-26 17:22:19,231 CRIT Server 'unix_http_server' running without any HTTP authentication checking
2024-03-26 17:22:19,231 INFO supervisord started with pid 14
2024-03-26 17:22:20,233 INFO spawned: 'exit_on_any_fatal' with pid 15
2024-03-26 17:22:20,235 INFO spawned: 'cron' with pid 16
2024-03-26 17:22:20,236 INFO spawned: 'rsyslog' with pid 17
2024-03-26 17:22:20,237 INFO spawned: 'splunkforwader' with pid 18
READY
splunkd 269 was not running.
Stopping splunk helpers...
Done.

已尝试操作:

  • 放行所有入站/出站流量
  • 检查所有端口配置
  • 本地Docker独立运行Gateway正常

排查与解决步骤

1. 验证Pod内部网络连通性

进入Pod执行网络测试,确认是否能访问外部网络及Akeyless API:

kubectl exec -it <akeyless-gateway-pod-name> -- ping -c 3 google.com
kubectl exec -it <akeyless-gateway-pod-name> -- curl -v https://api.akeyless.io

若无法访问,执行域名解析测试排查DNS问题:

kubectl exec -it <akeyless-gateway-pod-name> -- nslookup api.akeyless.io

同时检查Docker Desktop Kubernetes的网络配置:确认Settings > Kubernetes未修改默认网络模式,DNS配置正常。

2. 检查Helm Chart网络相关配置

  • 查看values.yaml是否开启networkPolicy,若开启需确保规则允许Pod出站访问Akeyless API地址
  • 确认是否配置了代理参数,无代理环境需确保proxy字段为空,有代理则填写正确地址
  • 临时将服务type从ClusterIP改为NodePort,测试外部是否能连通Pod

3. 排查Docker Desktop网络限制

  • 检查Settings > Resources > Network,确认未设置自定义DNS或网络访问限制
  • 临时关闭VPN、防火墙,排除外部网络拦截
  • 重置Kubernetes集群后重新部署:
docker desktop reset kubernetes

4. 检查Pod权限配置

查看Pod的SecurityContext是否存在网络权限限制,可临时添加网络相关权限测试:

# 在values.yaml中添加
securityContext:
  capabilities:
    add:
      - NET_ADMIN

5. 对比本地Docker与Kubernetes环境差异

执行docker inspect <local-gateway-container>查看本地容器的环境变量、网络模式,对比Kubernetes Pod的配置:

  • 确认AKEYLESS_GATEWAY_URL等关键环境变量一致
  • 检查本地容器的网络模式(如bridge)与Kubernetes Pod网络的兼容性

内容的提问来源于stack exchange,提问作者Saurav Garg

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 21:26:14