You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes集群中Nginx Pod无法访问外部网络的解决请求

问题:Kubernetes Pod无法解析外部域名,CoreDNS提示无路由到DNS服务器

创建单节点Kubernetes集群并部署nginx-pod后,Pod内部无法访问外部网络,执行curl google.com报错:

curl: (6) Could not resolve host: google.com

排查信息

Pod状态

root@kube-master-1 ~]# kubectl get pods
NAME        READY   STATUS    RESTARTS   AGE
nginx-pod   1/1     Running   0          19s

[root@kube-master-1 ~]# kubectl exec -it nginx-pod -- sh
# curl google.com
curl: (6) Could not resolve host: google.com

CoreDNS状态及日志

[root@kube-master-1 ~]# kubectl get pods -n kube-system
NAME                                      READY   STATUS    RESTARTS   AGE
calico-kube-controllers-57b57c56f-t4n58   1/1     Running   0          10m
calico-node-2fskd                         1/1     Running   0          10m
calico-node-mpz67                         1/1     Running   0          10m
coredns-787d4945fb-hl8h7                  1/1     Running   0          10m
coredns-787d4945fb-k47hg                  1/1     Running   0          10m
etcd-kube-master-1                        1/1     Running   0          10m
kube-apiserver-kube-master-1              1/1     Running   0          10m
kube-controller-manager-kube-master-1     1/1     Running   0          10m
kube-proxy-djwpf                          1/1     Running   0          10m
kube-proxy-z6wbs                          1/1     Running   0          10m
kube-scheduler-kube-master-1              1/1     Running   0          10m

CoreDNS Pod coredns-787d4945fb-hl8h7 日志:

.:53
[INFO] plugin/reload: Running configuration SHA512 = 591cf328cccc12bc490481273e738df59329c62c0b729d94e8b61db9961c2fa5f046dd37f1cf888b953814040d180f52594972691cd6ff41be96639138a43908
CoreDNS-1.9.3
linux/amd64, go1.18.2, 45b0a11
[ERROR] plugin/errors: 2 6411469028493896089.8637463944530651356. HINFO: read udp 10.85.0.4:38789->172.168.9.1:53: read: no route to host
[ERROR] plugin/errors: 2 6411469028493896089.8637463944530651356. HINFO: read udp 10.85.0.4:51289->172.168.9.1:53: read: no route to host
[ERROR] plugin/errors: 2 6411469028493896089.8637463944530651356. HINFO: read udp 10.85.0.4:58043->172.168.9.1:53: read: no route to host

CoreDNS Pod coredns-787d4945fb-k47hg 日志:

[INFO] plugin/ready: Still waiting on: "kubernetes"
.:53
[INFO] plugin/reload: Running configuration SHA512 = 591cf328cccc12bc490481273e738df59329c62c0b729d94e8b61db9961c2fa5f046dd37f1cf888b953814040d180f52594972691cd6ff41be96639138a43908
CoreDNS-1.9.3
linux/amd64, go1.18.2, 45b0a11
[ERROR] plugin/errors: 2 7329724478827996615.6993984998633749254. HINFO: read udp 10.85.0.3:50475->172.168.9.1:53: read: no route to host
[ERROR] plugin/errors: 2 7329724478827996615.6993984998633749254. HINFO: read udp 10.85.0.3:34954->172.168.9.1:53: read: no route to host
[ERROR] plugin/errors: 2 7329724478827996615.6993984998633749254. HINFO: read udp 10.85.0.3:54015->172.168.9.1:53: read: no route to host.

解决方法

1. 修复CoreDNS到外部DNS服务器的路由问题

日志显示CoreDNS Pod(IP 10.85.0.3/4)无法访问DNS服务器172.168.9.1,提示无路由:

  • 先验证集群节点是否能访问该DNS服务器:
    ping 172.168.9.1
    traceroute 172.168.9.1
    
  • 检查Calico网络策略,确认未阻止CoreDNS访问外部UDP 53端口:
    kubectl get networkpolicies -n kube-system
    
    若存在限制策略,调整规则允许CoreDNS Pod访问外部UDP 53端口。
  • 若节点能访问但Pod不行,检查Calico IP池及路由配置,确保Pod网段(10.85.0.0/xx)到172.168.9.0/24的路由存在:
    calicoctl get ippools
    calicoctl get routes
    

2. 替换CoreDNS的上游DNS服务器

如果172.168.9.1确实不可用,修改CoreDNS配置,替换为可靠的公共DNS:

  • 编辑CoreDNS ConfigMap:
    kubectl edit configmap coredns -n kube-system
    
  • 在forward段替换DNS地址:
    .:53 {
        errors
        health
        kubernetes cluster.local in-addr.arpa ip6.arpa {
            pods insecure
            fallthrough in-addr.arpa ip6.arpa
        }
        forward . 8.8.8.8 114.114.114.114  # 替换为公共DNS
        cache 30
        loop
        reload
        loadbalance
    }
    
  • 保存后等待CoreDNS自动重载配置,1-2分钟后测试Pod解析:
    kubectl exec -it nginx-pod -- curl google.com
    

3. 解决CoreDNS等待kubernetes插件的问题

其中一个CoreDNS Pod提示Still waiting on: "kubernetes",说明无法连接kube-apiserver:

  • 确认kube-apiserver状态正常:
    kubectl get pods -n kube-system kube-apiserver-kube-master-1
    
  • 检查CoreDNS的ServiceAccount权限,确保其能访问kube-apiserver:
    kubectl describe serviceaccount coredns -n kube-system
    kubectl describe clusterrole system:coredns
    kubectl describe clusterrolebinding system:coredns
    
  • 若权限正常,重启CoreDNS Pod:
    kubectl delete pods -n kube-system -l k8s-app=kube-dns
    

内容的提问来源于stack exchange,提问作者lakshmi narayanan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 22:54:56