如何访问Kubernetes集群中部署的PostgreSQL?解决Ingress不支持TCP导致的GUI连接问题
Got it, let's break down how to fix this. You're absolutely correct—standard Kubernetes Ingress is designed for HTTP/HTTPS traffic, so it can't route PostgreSQL's TCP connections. Here are practical methods to connect your GUI tool (like pgAdmin, DBeaver) to your PostgreSQL pod:
1. Temporary Access with kubectl port-forward (Great for Development/Testing)
This is the quickest way for one-off access, perfect if you just need to debug or run a quick query.
Run this command in your terminal:
kubectl port-forward deployment/postgresql-development 5432:5432 -n development
Once the port forward is active, open your GUI tool and connect to localhost:5432 using your PostgreSQL credentials (POSTGRES_USER=postgres as set in your deployment).
Note: This connection only lasts as long as the terminal session is open—close the terminal, and the port forward stops.
2. Expose via NodePort Service (Permanent Access in a Private Cluster)
If you need persistent access within your network, convert your existing Service to a NodePort type.
First, fix your existing service.yaml—the current selector includes unnecessary ingress-nginx labels that will prevent the Service from finding your PostgreSQL pod. Update it to match your Deployment's pod labels:
apiVersion: "v1" kind: "Service" metadata: name: "postgresql-development" namespace: "development" labels: app: "postgresql-development" spec: type: NodePort # Add this line to enable NodePort ports: - port: 59799 targetPort: 5432 protocol: TCP nodePort: 30432 # Optional: Specify a static port (30000-32767 range) selector: app: "postgresql-development" tier: "mysql" # Match the pod's tier label from your Deployment
Apply the updated Service:
kubectl apply -f service.yaml -n development
Now, connect your GUI tool using any cluster node's IP address plus the NodePort (e.g., 192.168.1.100:30432).
3. Expose via LoadBalancer Service (Cloud Environments)
If you're running Kubernetes on a cloud provider (AWS, GCP, Azure), use a LoadBalancer Service to get a public or private external IP.
Modify your service.yaml to set type: LoadBalancer:
apiVersion: "v1" kind: "Service" metadata: name: "postgresql-development" namespace: "development" labels: app: "postgresql-development" spec: type: LoadBalancer # Use LoadBalancer for cloud environments ports: - port: 59799 targetPort: 5432 protocol: TCP selector: app: "postgresql-development" tier: "mysql"
Apply the Service, then get the external IP:
kubectl get service postgresql-development -n development
Look for the EXTERNAL-IP column—use that IP plus port 59799 in your GUI tool.
4. Advanced: Use NGINX Ingress Controller for TCP Proxy
Since you're already using the NGINX Ingress Controller, you can configure it to route TCP traffic (this requires cluster admin access).
Step 1: Update the NGINX Ingress ConfigMap
Add a TCP port mapping to the ConfigMap (usually named nginx-ingress-controller in the ingress-nginx namespace):
apiVersion: v1 kind: ConfigMap metadata: name: nginx-ingress-controller namespace: ingress-nginx data: tcp-services: | 5432: development/postgresql-development:59799 # Format: external-port: namespace/service-name:service-port
Step 2: Update the NGINX Ingress Controller Service
Expose the TCP port in the Controller's Service:
apiVersion: v1 kind: Service metadata: name: nginx-ingress-controller namespace: ingress-nginx spec: ports: - name: tcp-postgres port: 5432 targetPort: 5432 protocol: TCP selector: app.kubernetes.io/name: ingress-nginx app.kubernetes.io/part-of: ingress-nginx
After applying these changes, you can connect your GUI tool to your Ingress Controller's external IP (or node IP) on port 5432.
Quick Note on Your Existing Config
Your original service.yaml had incorrect selector labels (app.kubernetes.io/name: ingress-nginx etc.)—these don't match your Deployment's pod labels, so the Service wouldn't have been able to route traffic to the PostgreSQL pod even if you could use Ingress. Make sure to fix that as shown in the NodePort/LoadBalancer examples above.
内容的提问来源于stack exchange,提问作者SVD

