You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AKS部署Node.js API外部IP无法访问,请求排查建议

AKS部署Node.js API后外部IP无响应的排查与解决

问题背景

将本地Docker环境运行正常的Node.js API部署至AKS集群后,Pod状态显示为Running,但通过浏览器访问Service的外部IP无响应,需排查配置问题并给出解决建议。

当前配置

Deployment与Service配置

apiVersion: apps/v1
kind: Deployment
metadata:
  name: nodejs
  labels:
    app: nodejs
spec:
  replicas: 3
  selector:
    matchLabels:
      app: nodejs
  template:
    metadata:
      labels:
        app: nodejs
    spec:
      nodeSelector:
        "kubernetes.io/os": linux
      containers:
        - name: nodejs
          image: dileepamabulage/node-app:latest
          imagePullPolicy: Always
          ports:
            - containerPort: 3003
          resources:
            limits:
              cpu: 100m
              memory: 128Mi
            requests:
              cpu: 100m
              memory: 128Mi
---
apiVersion: v1
kind: Service
metadata:
  name: nodejs
  labels:
    app: nodejs
spec:
  type: LoadBalancer
  ports:
    - port: 80
      targetPort: 3003
      protocol: TCP

Dockerfile配置

FROM node:20

WORKDIR /usr/src/app

COPY package*.json ./

RUN npm install

COPY . .

EXPOSE 3003

CMD ["node", "server.js"]

核心问题定位

你的Service配置缺少selector字段,这是导致外部IP无响应的关键原因。Kubernetes需要通过selector匹配Pod的labels(你的Pod labels为app: nodejs)才能将Service的流量转发到对应的Pod中。当前Service没有绑定任何Pod,外部请求自然无法到达容器内的API服务。

端口映射的配置本身没有错误:Dockerfile的EXPOSE 3003、Deployment的containerPort:3003、Service的targetPort:3003和port:80的映射关系完全正确。

修正后的Service配置

在Service的spec中添加selector字段,匹配Pod的labels:

apiVersion: v1
kind: Service
metadata:
  name: nodejs
  labels:
    app: nodejs
spec:
  type: LoadBalancer
  selector:
    app: nodejs  # 新增该字段,关联到标签为app:nodejs的Pod
  ports:
    - port: 80
      targetPort: 3003
      protocol: TCP

额外排查与验证步骤

  1. 确认Node.js服务监听地址
    检查server.js中的监听代码,必须确保服务绑定到0.0.0.0而非127.0.0.1(仅绑定127.0.0.1时,容器外部无法访问服务)。正确示例:

    app.listen(3003, '0.0.0.0', () => {
      console.log('Server running on port 3003');
    });
    
  2. 验证Service与Pod的关联状态
    执行命令查看Service详情:

    kubectl describe service nodejs
    

    检查Endpoints字段,若显示Pod的IP列表,说明关联成功;若为空,需确认selector与Pod labels是否完全匹配。

  3. 检查Service外部IP状态
    执行命令查看Service的外部IP:

    kubectl get service nodejs
    

    若EXTERNAL-IP列显示<pending>,说明AKS集群无法创建负载均衡器,需检查集群权限或公共IP池配置;若为有效公网IP,等待几分钟让负载均衡器配置生效后再测试访问。

  4. 集群内连通性测试

    • 创建临时测试Pod:
      kubectl run -it --rm --image=curlimages/curl test-curl -- sh
      
    • 访问Service:
      curl nodejs:80
      
      若返回API响应,说明集群内Service正常,问题可能出在外部网络防火墙或负载均衡器规则;若无响应,直接访问Pod IP测试:
      kubectl get pods -o wide  # 获取Pod的IP地址
      curl <pod-ip>:3003
      
      若Pod无响应,说明容器内服务未正常启动,需查看Pod日志排查:
      kubectl logs <pod-name>
      

内容的提问来源于stack exchange,提问作者nullsafe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 23:30:27