You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes上Jupyter服务:端口转发可访问,NodePort服务不可用

Jupyter NodePort Service 无法访问的合规解决方案

问题背景

我通过以下YAML配置创建了Jupyter Pod与NodePort类型的Service:

apiVersion: v1
kind: Pod
metadata:
  name: jupyter-pod
  labels:
    app: jupyter-pod
spec:
  serviceAccountName: spark-driver
  containers:
  - name: jupyter-pod
    image: spark-k8s-jupyter:v3.5.0
    imagePullPolicy: Never
    command: ["jupyter", "lab", "--ip", "0.0.0.0", "--port", "9000"]
    tty: true
    stdin: true
  restartPolicy: Always
---
apiVersion: v1
kind: Service
metadata:
  name: jupyter-pod
spec:
  type: NodePort
  selector:
    app: jupyter-pod
  ports:
    - protocol: TCP
      port: 9000  # The port that the service will serve on.
      targetPort: 9000  # The target port on the pod(s) to forward to.

使用kubectl port-forward pod/jupyter-pod 9000:9000可正常在浏览器访问Jupyter页面,但通过Service无法访问,尝试过Pod IP、localhost及多个端口均无效。目前通过设置hostNetwork: true临时解决问题,但这并非最佳实践,需要合规的解决方案。

排查信息

执行相关命令获取的信息如下:

1. Endpoints 信息

kubectl get endpoints -A
NAMESPACE              NAME                                 ENDPOINTS                                           AGE
default                jupyter-service                      10.244.0.147:9000                                   4m30s

2. Service 详情

k describe service jupyter-service
Name:                     jupyter-service
Namespace:                default
Labels:                   <none>
Annotations:              <none>
Selector:                 app=jupyter-pod
Type:                     NodePort
IP Family Policy:         SingleStack
IP Families:              IPv4
IP:                       10.106.188.89
IPs:                      10.106.188.89
Port:                     <unset>  9000/TCP
TargetPort:               9000/TCP
NodePort:                 <unset>  31175/TCP
Endpoints:                10.244.0.147:9000
Session Affinity:         None
External Traffic Policy:  Cluster
Events:                   <none>

3. Service 列表

k get service
NAME                TYPE        CLUSTER-IP      EXTERNAL-IP   PORT(S)          AGE
jupyter-pod         NodePort    10.103.70.121   <none>        9000:30192/TCP   9s

合规解决方案

1. 清理冗余Service,避免混淆

从排查信息看,存在两个同名不同配置的Service(jupyter-service和jupyter-pod),建议删除冗余的Service,仅保留一个与Pod标签匹配的Service,避免流量转发冲突。

2. 使用正确的NodePort访问方式

NodePort服务的正确访问路径是[集群节点IP]:[NodePort端口],而非localhost或Pod IP:

  • 从kubectl get service结果中,jupyter-pod的NodePort为30192,jupyter-service的NodePort为31175
  • 获取集群任意节点的内网/公网IP,访问http://<节点IP>:30192或http://<节点IP>:31175

3. 验证Pod内部端口监听状态

进入Pod内部,确认Jupyter服务确实监听在0.0.0.0:9000(而非仅localhost):

kubectl exec -it jupyter-pod -- netstat -tulpn

确保输出中存在0.0.0.0:9000的监听记录,若服务仅绑定localhost,会导致Service无法转发流量。

4. 检查防火墙与网络策略

  • 确认集群节点的防火墙规则允许NodePort端口(30192/31175)的入站流量
  • 若集群启用了NetworkPolicy,需添加允许Service访问Pod的规则:
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: allow-jupyter-service
spec:
  podSelector:
    matchLabels:
      app: jupyter-pod
  ingress:
  - from:
    - ipBlock:
        cidr: 0.0.0.0/0
    ports:
    - protocol: TCP
      port: 9000

5. 确认kube-proxy组件正常工作

kube-proxy负责Service的流量转发,检查其状态:

kubectl get pods -n kube-system | grep kube-proxy
kubectl logs -n kube-system <kube-proxy-pod-name>

若kube-proxy日志异常,重启对应Pod即可恢复转发规则。

内容的提问来源于stack exchange,提问作者Kriggs

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 20:02:37