You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes集群中Nginx Pod跨Pod连接失败问题排查求助

Nginx Pod端口配置连接问题排查

我使用Bitnami Nginx Helm Chart部署了一个Nginx Pod,尝试调整端口配置以允许同一命名空间内的其他Pod连接,但未成功。

当前配置覆盖

global:
  imagePullSecrets:
    - name: dockercredentials

image:
  registry: my-private-registry.com
  repository: nginx/nginx
  tag: 1.23
  debug: true

service:
  annotations:
    service.beta.kubernetes.io/azure-load-balancer-internal: "true"
    # Configures the LB to use this subnet in azure to get an IP
    service.beta.kubernetes.io/azure-load-balancer-internal-subnet: "my-azure-subnet"

serverBlock: |-
  server {
    listen 80;
    listen 443;
    listen 8443;
    listen 8080;

    location / {
        resolver 8.8.8.8; # may or may not be necessary.
        proxy_pass https://example.com$request_uri;
    }
  }


extraEnvVars:
  - name: http_proxy
    value: http://my.proxy:8000
  - name: https_proxy
    value: http://my.proxy:8000

containerSecurityContext:
  enabled: true
  allowPrivilegeEscalation: false
  runAsNonRoot: false
  runAsUser: 0
# Enable https port
containerPorts:
  https: 8443

livenessProbe:
  enabled: false
readinessProbe:
  enabled: false

Pod及对应Service部署信息

Service描述

k describe service/nginx-load-balancer

....
Port:                     http  80/TCP
TargetPort:               http/TCP
NodePort:                 http  31226/TCP
Endpoints:                10.245.116.86:8080
Port:                     https  443/TCP
TargetPort:               https/TCP
NodePort:                 https  31509/TCP
Endpoints:                10.245.116.86:8443
....

Deployment描述

k describe deployment.apps/nginx-load-balancer

....
  Containers:
   nginx:
    Image:       my-private-registry.com/nginx/nginx:1.23
    Ports:       8080/TCP, 8443/TCP
    Host Ports:  0/TCP, 0/TCP
    Environment:
      BITNAMI_DEBUG:            true
      NGINX_HTTP_PORT_NUMBER:   8080
      NGINX_HTTPS_PORT_NUMBER:  8443
      http_proxy:               http://my.proxy:8000
      https_proxy:              http://my.proxy:8000
....

连接测试结果

Telnet测试

# telnet 10.245.116.152 443
Trying 10.245.116.152...
telnet: Unable to connect to remote host: Connection refused
# telnet 10.245.116.152 80
Trying 10.245.116.152...
telnet: Unable to connect to remote host: Connection refused
# telnet 10.245.116.152 8080
Trying 10.245.116.152...
^C
# telnet 10.245.116.152 8443
Trying 10.245.116.152...
^C
#

Curl测试

# curl -v nginx-load-balancer
*   Trying 172.20.41.169:80...
* TCP_NODELAY set
* connect to 172.20.41.169 port 80 failed: Connection refused
* Failed to connect to nginx-load-balancer port 80: Connection refused
* Closing connection 0
curl: (7) Failed to connect to nginx-load-balancer port 80: Connection refused
# curl -v nginx-load-balancer.my-ns
*   Trying 172.20.41.169:80...
* TCP_NODELAY set
* connect to 172.20.41.169 port 80 failed: Connection refused
* Failed to connect to nginx-load-balancer.my-ns port 80: Connection refused
* Closing connection 0
curl: (7) Failed to connect to nginx-load-balancer.my-ns port 80: Connection refused
# curl -v 10.245.116.152
*   Trying 10.245.116.152:80...
* TCP_NODELAY set
* connect to 10.245.116.152 port 80 failed: Connection refused
* Failed to connect to 10.245.116.152 port 80: Connection refused
* Closing connection 0
curl: (7) Failed to connect to 10.245.116.152 port 80: Connection refused

疑问与目标

按我对Service Port和Target Port的理解,流量应在80/443端口被接收,并分别转发到8080/8443端口,对吗?我的最终目标是将流量路由到该Nginx Pod,使其通过serverBlock中的proxy_pass设置将流量重定向到example.com。

解决思路

  • 验证Nginx实际监听端口:进入Nginx Pod执行ss -tulpn | grep nginx,确认容器内Nginx是否真的在8080/8443端口监听。Bitnami的Chart会通过NGINX_HTTP_PORT_NUMBER和NGINX_HTTPS_PORT_NUMBER环境变量生成默认配置,需检查自定义serverBlock是否完全覆盖了默认配置,避免端口监听冲突。
  • 检查容器内Nginx配置:查看Pod内/opt/bitnami/nginx/conf/server_blocks/目录下的配置文件,确认自定义的server块listen指令是否生效。若存在默认server块,可通过Chart参数禁用或确保自定义配置优先级更高。
  • 排查代理连通性:连接8080/8443端口挂起,大概率是Nginx转发请求时被代理阻塞。在Nginx Pod内执行curl -v https://example.com,验证代理http://my.proxy:8000是否能正常访问目标站点。若代理不可达或拒绝请求,会导致Nginx等待超时,外部连接挂起。
  • 确认Service端口映射:虽然Service的Endpoints显示已关联Pod的8080/8443端口,但需确认Pod的容器端口名称是否与Service的TargetPort匹配(http对应8080,https对应8443)。
  • 检查网络策略:排查命名空间是否存在NetworkPolicy,限制了其他Pod与Nginx Pod的端口访问,确保允许同命名空间Pod访问8080/8443端口。

内容的提问来源于stack exchange,提问作者Virtual Penman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 11:37:09