You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS云K8s集群中创建LoadBalancer服务无法获取外部IP求助

解决AWS Kubernetes中LoadBalancer Service外部IP处于Pending状态的问题

问题现象

执行kubectl get svc后,LoadBalancer类型的Service外部IP始终显示为<pending>:

kubectl get svc
NAME         TYPE           CLUSTER-IP       EXTERNAL-IP   PORT(S)          AGE
kubernetes   ClusterIP      10.96.0.1        <none>        443/TCP          6d8h
pcb-mtncm    LoadBalancer   10.102.152.215   <pending>     8080:30892/TCP   99m

对应的Service配置:

kind: Service 
apiVersion: v1 
metadata:
  name: test-load
  namespace: default
spec:
  type: LoadBalancer
  selector:
    app: test-load
  ports:
    - protocol: TCP
      port: 8080
      targetPort: 80

Deployment配置:

apiVersion: apps/v1
kind: Deployment
metadata:
  creationTimestamp: null
  labels:
    app: test-load
  name: test-load
spec:
  replicas: 3
  selector:
    matchLabels:
      app: test-load
  strategy: {}
  template:
    metadata:
      creationTimestamp: null
      labels:
        app: test-load
    spec:
      containers:
      - image: ubuntu:latest
        name: ubuntu
        command: ["/bin/sleep", "3650d"]
        resources: {}
status: {}

排查与解决方案

1. 验证集群节点的AWS权限

AWS EKS集群的节点IAM角色必须具备创建、管理ELB的权限,否则无法触发AWS负载均衡器的创建流程。

  • 登录AWS IAM控制台,找到集群节点对应的IAM角色
  • 确认角色已关联AmazonEKSWorkerNodePolicy、AmazonEC2ContainerRegistryReadOnly、AmazonEKS_CNI_Policy这三个EKS标准权限策略
  • 若使用自定义权限,需确保包含elasticloadbalancing:*、ec2:DescribeSubnets、ec2:DescribeSecurityGroups等核心权限

2. 确认Service与Pod的标签匹配性

虽然你的Service selectorapp: test-load和Deployment Pod模板的标签一致,但仍需验证Pod是否正常运行:

kubectl get pods -l app=test-load

如果Pod未处于Running状态,先修复Pod启动问题(比如镜像拉取失败、资源不足),否则负载均衡器不会绑定未就绪的后端。

3. 检查AWS负载均衡控制器状态

EKS集群依赖AWS Load Balancer Controller(原ALB Ingress Controller)来完成Kubernetes Service到AWS ELB/NLB/ALB的映射。

  • 检查控制器是否已部署并运行:
kubectl get pods -n kube-system -l app.kubernetes.io/name=aws-load-balancer-controller
  • 若未安装,需完成以下步骤:
    1. 为集群创建IAM OIDC提供商
    2. 创建具备负载均衡管理权限的IAM角色
    3. 通过Helm或YAML配置部署控制器

4. 查看Service事件日志定位错误

通过以下命令查看Service的事件详情,直接获取负载均衡器创建失败的具体原因(如权限不足、子网不可用):

kubectl describe svc test-load

重点关注输出末尾的Events字段,里面会记录AWS侧的报错信息。

5. 检查AWS资源配额限制

确认AWS账户当前区域的Elastic Load Balancing配额是否已达上限:

  • 登录AWS控制台的Service Quotas服务
  • 搜索Elastic Load Balancing,查看应用负载均衡器/网络负载均衡器的配额使用情况,若不足可申请扩容

6. 配置Service的AWS特定注解(可选)

如果需要指定负载均衡器类型、子网或安全组,可在Service的metadata.annotations中添加配置,例如:

metadata:
  annotations:
    # 指定使用NLB类型负载均衡器
    service.beta.kubernetes.io/aws-load-balancer-type: "nlb"
    # 指定负载均衡器使用的子网
    service.beta.kubernetes.io/aws-load-balancer-subnets: "subnet-xxxxxx,subnet-yyyyyy"

添加后重新应用Service配置:

kubectl apply -f your-service-file.yaml

额外注意事项

你的Deployment使用的ubuntu:latest镜像仅执行sleep命令,容器内未监听80端口。即使外部IP分配成功,访问8080端口也会失败。建议替换为实际提供80端口服务的镜像(如nginx:latest),修改Deployment容器配置:

containers:
- image: nginx:latest
  name: nginx
  ports:
  - containerPort: 80

内容的提问来源于stack exchange,提问作者love arora

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 18:44:56