在OpenShift上部署Redis后无法连接的问题求助
Error 10060 is a connection timeout, meaning your redis-cli request isn’t reaching the Redis instance at all. Let’s walk through the most likely issues and fixes step by step:
1. OpenShift Routes are HTTP/HTTPS-only by default (Redis uses TCP)
Redis runs on a raw TCP protocol, but standard OpenShift Routes are built to handle HTTP/HTTPS traffic. Trying to use a regular Route for Redis will fail because the ingress controller doesn’t know how to route TCP traffic through it.
Fixes:
- Option 1: Use a TCP Route (OCP 4.4+): If you’re on OpenShift Container Platform, configure your ingress controller to support TCP routes:
- Edit the ingress controller config to expose Redis’ default port (6379) as a TCP endpoint.
- Create a Route with
spec.tls.termination: passthroughandspec.port.targetPortpointing to your Redis service’s port.
- Option 2: Switch to NodePort/LoadBalancer Service: For simpler external access, change your Redis Service type to
NodePort(connect via<node-ip>:<node-port>) orLoadBalancer(if your cluster supports it, you’ll get an external IP to use).
2. Redis is bound only to localhost
By default, Redis is configured to listen on 127.0.0.1, which means it won’t accept connections from outside its container.
Fix:
- Update your Redis deployment to bind to
0.0.0.0:- Add a command argument in your Deployment/DeploymentConfig:
--bind 0.0.0.0 - Or modify
redis.confto setbind 0.0.0.0(if using a custom config)
- Add a command argument in your Deployment/DeploymentConfig:
- Verify the bind address by exec-ing into the pod:
It should returnoc rsh <redis-pod-name> redis-cli CONFIG GET bind["0.0.0.0"].
3. Network policies or firewalls are blocking traffic
A connection timeout usually means traffic is being blocked between your local machine and the Redis pod.
Checks:
- Cluster External Firewall: Ensure the port used by your Route/Service is open in your cloud provider’s firewall or on-premise network rules.
- OpenShift NetworkPolicy: Run
oc get networkpoliciesto list existing policies, and confirm none are restricting incoming traffic to the Redis Service. - Pod Security Context: Ensure the pod has permissions to accept incoming connections (less likely for timeout errors, but worth checking).
4. Route-Service-Port misconfiguration
Double-check that your Route is correctly linked to the right Service and port:
- Run
oc get routes <your-route-name> -o yamlto confirm:spec.to.namematches your Redis Service namespec.port.targetPortmatches the port exposed by your Service (should be 6379 for Redis)
- Run
oc get svc <redis-service-name>to verify the Service targets the correct pod labels and exposes port 6379.
5. TLS mismatch (if using encrypted Routes)
If your Route uses TLS termination (like passthrough), your redis-cli needs to use TLS to connect. Without it, the connection will time out because the ingress controller expects TLS traffic.
Fix:
- Connect with the
--tlsflag:redis-cli -h xx.com --tls - If using a self-signed cert, add
--insecureto skip verification:redis-cli -h xx.com --tls --insecure
Start with checking the Route type and Redis bind address—those are the two most frequent causes for this exact error.
内容的提问来源于stack exchange,提问作者Spaceship222

