Kind集群中部署的Spring Boot应用Pod URL无法访问求助
排查Spring Boot应用NodePort无法访问问题
问题背景
容器化了一个Spring Boot REST API,通过/employee端点返回员工列表,使用Helm Chart部署到Kubernetes集群。配置了NodePort类型的Service,指定Service端口为31234,应用本身运行在8085端口,镜像推送到本地localhost:5001仓库。但访问各节点IP:31234/employee均无法连接。
环境信息
节点信息
kubectl get nodes -o wide
输出:
test-dev-control-plane Ready control-plane 2d23h v1.27.3 172.18.0.3 Debian GNU/Linux 11 (bullseye) 5.15.133.1-microsoft-standard-WSL2 containerd://1.7.1 test-dev-worker Ready 2d23h v1.27.3 172.18.0.5 Debian GNU/Linux 11 (bullseye) 5.15.133.1-microsoft-standard-WSL2 containerd://1.7.1 test-dev-worker2 Ready 2d23h v1.27.3 172.18.0.2 Debian GNU/Linux 11 (bullseye) 5.15.133.1-microsoft-standard-WSL2 containerd://1.7.1
Service信息
kubectl get services
输出:
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE emp1-chart NodePort 10.96.181.143 31234:30296/TCP 2d19h kubernetes ClusterIP 10.96.0.1 443/TCP 2d23h
Pod信息
kubectl get pods
输出:
NAME READY STATUS RESTARTS AGE abc 1/1 Running 1 (6m20s ago) 2d19h
Helm values.yml配置
replicaCount: 1 image: repository: localhost:5001/employee1 pullPolicy: IfNotPresent tag: "latest" imagePullSecrets: [] nameOverride: "" fullnameOverride: "" serviceAccount: create: true automount: true annotations: {} name: "" podAnnotations: {} podLabels: {} podSecurityContext: {} securityContext: {} service: type: NodePort port: 31234 ingress: enabled: false className: "" annotations: {} hosts: - host: chart-example.local paths: - path: / pathType: ImplementationSpecific tls: [] resources: {} autoscaling: enabled: false minReplicas: 1 maxReplicas: 100 targetCPUUtilizationPercentage: 80 volumes: [] volumeMounts: [] nodeSelector: {} tolerations: [] affinity: {}
排查步骤
1. 修正NodePort访问端口
从Service输出可以看到,emp1-chart的端口映射是31234:30296/TCP:
31234是Service的ClusterIP端口(仅集群内部访问)30296是Kubernetes分配的NodePort端口(外部访问用)
你之前用31234访问是错误的,应该尝试访问:
http://172.18.0.2:30296/employee http://172.18.0.3:30296/employee http://172.18.0.5:30296/employee
2. 验证Service与容器端口的映射关系
应用运行在容器的8085端口,但当前values.yml仅配置了service.port: 31234,需要确认Helm生成的Deployment和Service是否正确映射了容器端口:
- 查看Service的targetPort配置:
如果输出不是kubectl describe service emp1-chart | grep TargetPort8085,说明Service没有正确指向容器端口,需要在values.yml中添加service.targetPort: 8085:service: type: NodePort port: 31234 targetPort: 8085 - 查看Deployment的容器端口配置:
确认容器是否暴露了kubectl describe deployment abc | grep Port8085端口,若没有,需要在Helm的Deployment模板中添加容器端口定义。
3. 检查Pod内部服务可用性
直接进入Pod内部,验证应用是否正常运行:
kubectl exec -it abc -- curl localhost:8085/employee
如果返回员工列表,说明应用本身正常;如果返回连接失败,说明容器内应用未启动或端口配置错误。
4. 确认镜像与应用一致性
你提到values.yml中镜像名为localhost:5001/emp,但实际节点中的镜像和values.yml配置是localhost:5001/employee1,虽然Pod处于Running状态,但仍需确认容器内的应用是正确版本:
kubectl exec -it abc -- cat /path/to/application.properties | grep server.port
确认server.port是否为8085。
5. 排查节点网络与防火墙
因为是WSL2环境,需要检查:
- 节点的iptables规则是否允许NodePort流量:
iptables-save | grep 30296 - Windows主机与WSL节点的网络连通性:在Windows命令行中执行
ping 172.18.0.2(替换为节点IP),确认能ping通。 - 检查WSL2的端口转发配置,确保NodePort端口已转发到Windows主机。
6. 检查Kubernetes网络策略
如果集群中配置了NetworkPolicy,可能阻止了外部流量访问:
kubectl get networkpolicies
若存在限制emp1-chart服务的策略,需要调整规则允许NodePort流量。
内容的提问来源于stack exchange,提问作者Coder17
相关产品推荐
相关产品推荐

