You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kind集群中部署的Spring Boot应用Pod URL无法访问求助

排查Spring Boot应用NodePort无法访问问题

问题背景

容器化了一个Spring Boot REST API,通过/employee端点返回员工列表,使用Helm Chart部署到Kubernetes集群。配置了NodePort类型的Service,指定Service端口为31234,应用本身运行在8085端口,镜像推送到本地localhost:5001仓库。但访问各节点IP:31234/employee均无法连接。

环境信息

节点信息

kubectl get nodes -o wide

输出:

test-dev-control-plane   Ready    control-plane   2d23h   v1.27.3   172.18.0.3            Debian GNU/Linux 11 (bullseye)   5.15.133.1-microsoft-standard-WSL2   containerd://1.7.1
test-dev-worker          Ready              2d23h   v1.27.3   172.18.0.5            Debian GNU/Linux 11 (bullseye)   5.15.133.1-microsoft-standard-WSL2   containerd://1.7.1
test-dev-worker2         Ready              2d23h   v1.27.3   172.18.0.2            Debian GNU/Linux 11 (bullseye)   5.15.133.1-microsoft-standard-WSL2   containerd://1.7.1

Service信息

kubectl get services

输出:

NAME          TYPE         CLUSTER-IP       EXTERNAL-IP    PORT(S)           AGE
emp1-chart   NodePort    10.96.181.143           31234:30296/TCP   2d19h
kubernetes   ClusterIP   10.96.0.1               443/TCP           2d23h

Pod信息

kubectl get pods

输出:

NAME                          READY   STATUS    RESTARTS        AGE
abc   1/1     Running   1 (6m20s ago)   2d19h

Helm values.yml配置

replicaCount: 1
image:
  repository: localhost:5001/employee1
  pullPolicy: IfNotPresent
  tag: "latest"
imagePullSecrets: []
nameOverride: ""
fullnameOverride: ""
serviceAccount:
  create: true
  automount: true
  annotations: {}
  name: ""
podAnnotations: {}
podLabels: {}
podSecurityContext: {}
securityContext: {}
service:
  type: NodePort
  port: 31234
ingress:
  enabled: false
  className: ""
  annotations: {}
  hosts:
    - host: chart-example.local
      paths:
        - path: /
          pathType: ImplementationSpecific
  tls: []
resources: {}
autoscaling:
  enabled: false
  minReplicas: 1
  maxReplicas: 100
  targetCPUUtilizationPercentage: 80
volumes: []
volumeMounts: []
nodeSelector: {}
tolerations: []
affinity: {}

排查步骤

1. 修正NodePort访问端口

从Service输出可以看到,emp1-chart的端口映射是31234:30296/TCP:

  • 31234是Service的ClusterIP端口(仅集群内部访问)
  • 30296是Kubernetes分配的NodePort端口(外部访问用)

你之前用31234访问是错误的,应该尝试访问:

http://172.18.0.2:30296/employee
http://172.18.0.3:30296/employee
http://172.18.0.5:30296/employee

2. 验证Service与容器端口的映射关系

应用运行在容器的8085端口,但当前values.yml仅配置了service.port: 31234,需要确认Helm生成的Deployment和Service是否正确映射了容器端口:

  • 查看Service的targetPort配置:
    kubectl describe service emp1-chart | grep TargetPort
    
    如果输出不是8085,说明Service没有正确指向容器端口,需要在values.yml中添加service.targetPort: 8085:
    service:
      type: NodePort
      port: 31234
      targetPort: 8085
    
  • 查看Deployment的容器端口配置:
    kubectl describe deployment abc | grep Port
    
    确认容器是否暴露了8085端口,若没有,需要在Helm的Deployment模板中添加容器端口定义。

3. 检查Pod内部服务可用性

直接进入Pod内部,验证应用是否正常运行:

kubectl exec -it abc -- curl localhost:8085/employee

如果返回员工列表,说明应用本身正常;如果返回连接失败,说明容器内应用未启动或端口配置错误。

4. 确认镜像与应用一致性

你提到values.yml中镜像名为localhost:5001/emp,但实际节点中的镜像和values.yml配置是localhost:5001/employee1,虽然Pod处于Running状态,但仍需确认容器内的应用是正确版本:

kubectl exec -it abc -- cat /path/to/application.properties | grep server.port

确认server.port是否为8085。

5. 排查节点网络与防火墙

因为是WSL2环境,需要检查:

  • 节点的iptables规则是否允许NodePort流量:
    iptables-save | grep 30296
    
  • Windows主机与WSL节点的网络连通性:在Windows命令行中执行ping 172.18.0.2(替换为节点IP),确认能ping通。
  • 检查WSL2的端口转发配置,确保NodePort端口已转发到Windows主机。

6. 检查Kubernetes网络策略

如果集群中配置了NetworkPolicy,可能阻止了外部流量访问:

kubectl get networkpolicies

若存在限制emp1-chart服务的策略,需要调整规则允许NodePort流量。

内容的提问来源于stack exchange,提问作者Coder17

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 17:10:22