Kubernetes集群中Nginx Pod无法访问外部网络的解决请求
问题:Kubernetes Pod无法解析外部域名,CoreDNS提示无路由到DNS服务器
创建单节点Kubernetes集群并部署nginx-pod后,Pod内部无法访问外部网络,执行curl google.com报错:
curl: (6) Could not resolve host: google.com
排查信息
Pod状态
root@kube-master-1 ~]# kubectl get pods NAME READY STATUS RESTARTS AGE nginx-pod 1/1 Running 0 19s [root@kube-master-1 ~]# kubectl exec -it nginx-pod -- sh # curl google.com curl: (6) Could not resolve host: google.com
CoreDNS状态及日志
[root@kube-master-1 ~]# kubectl get pods -n kube-system NAME READY STATUS RESTARTS AGE calico-kube-controllers-57b57c56f-t4n58 1/1 Running 0 10m calico-node-2fskd 1/1 Running 0 10m calico-node-mpz67 1/1 Running 0 10m coredns-787d4945fb-hl8h7 1/1 Running 0 10m coredns-787d4945fb-k47hg 1/1 Running 0 10m etcd-kube-master-1 1/1 Running 0 10m kube-apiserver-kube-master-1 1/1 Running 0 10m kube-controller-manager-kube-master-1 1/1 Running 0 10m kube-proxy-djwpf 1/1 Running 0 10m kube-proxy-z6wbs 1/1 Running 0 10m kube-scheduler-kube-master-1 1/1 Running 0 10m
CoreDNS Pod coredns-787d4945fb-hl8h7 日志:
.:53 [INFO] plugin/reload: Running configuration SHA512 = 591cf328cccc12bc490481273e738df59329c62c0b729d94e8b61db9961c2fa5f046dd37f1cf888b953814040d180f52594972691cd6ff41be96639138a43908 CoreDNS-1.9.3 linux/amd64, go1.18.2, 45b0a11 [ERROR] plugin/errors: 2 6411469028493896089.8637463944530651356. HINFO: read udp 10.85.0.4:38789->172.168.9.1:53: read: no route to host [ERROR] plugin/errors: 2 6411469028493896089.8637463944530651356. HINFO: read udp 10.85.0.4:51289->172.168.9.1:53: read: no route to host [ERROR] plugin/errors: 2 6411469028493896089.8637463944530651356. HINFO: read udp 10.85.0.4:58043->172.168.9.1:53: read: no route to host
CoreDNS Pod coredns-787d4945fb-k47hg 日志:
[INFO] plugin/ready: Still waiting on: "kubernetes" .:53 [INFO] plugin/reload: Running configuration SHA512 = 591cf328cccc12bc490481273e738df59329c62c0b729d94e8b61db9961c2fa5f046dd37f1cf888b953814040d180f52594972691cd6ff41be96639138a43908 CoreDNS-1.9.3 linux/amd64, go1.18.2, 45b0a11 [ERROR] plugin/errors: 2 7329724478827996615.6993984998633749254. HINFO: read udp 10.85.0.3:50475->172.168.9.1:53: read: no route to host [ERROR] plugin/errors: 2 7329724478827996615.6993984998633749254. HINFO: read udp 10.85.0.3:34954->172.168.9.1:53: read: no route to host [ERROR] plugin/errors: 2 7329724478827996615.6993984998633749254. HINFO: read udp 10.85.0.3:54015->172.168.9.1:53: read: no route to host.
解决方法
1. 修复CoreDNS到外部DNS服务器的路由问题
日志显示CoreDNS Pod(IP 10.85.0.3/4)无法访问DNS服务器172.168.9.1,提示无路由:
- 先验证集群节点是否能访问该DNS服务器:
ping 172.168.9.1 traceroute 172.168.9.1 - 检查Calico网络策略,确认未阻止CoreDNS访问外部UDP 53端口:
若存在限制策略,调整规则允许CoreDNS Pod访问外部UDP 53端口。kubectl get networkpolicies -n kube-system - 若节点能访问但Pod不行,检查Calico IP池及路由配置,确保Pod网段(10.85.0.0/xx)到172.168.9.0/24的路由存在:
calicoctl get ippools calicoctl get routes
2. 替换CoreDNS的上游DNS服务器
如果172.168.9.1确实不可用,修改CoreDNS配置,替换为可靠的公共DNS:
- 编辑CoreDNS ConfigMap:
kubectl edit configmap coredns -n kube-system - 在
forward段替换DNS地址:.:53 { errors health kubernetes cluster.local in-addr.arpa ip6.arpa { pods insecure fallthrough in-addr.arpa ip6.arpa } forward . 8.8.8.8 114.114.114.114 # 替换为公共DNS cache 30 loop reload loadbalance } - 保存后等待CoreDNS自动重载配置,1-2分钟后测试Pod解析:
kubectl exec -it nginx-pod -- curl google.com
3. 解决CoreDNS等待kubernetes插件的问题
其中一个CoreDNS Pod提示Still waiting on: "kubernetes",说明无法连接kube-apiserver:
- 确认kube-apiserver状态正常:
kubectl get pods -n kube-system kube-apiserver-kube-master-1 - 检查CoreDNS的ServiceAccount权限,确保其能访问kube-apiserver:
kubectl describe serviceaccount coredns -n kube-system kubectl describe clusterrole system:coredns kubectl describe clusterrolebinding system:coredns - 若权限正常,重启CoreDNS Pod:
kubectl delete pods -n kube-system -l k8s-app=kube-dns
内容的提问来源于stack exchange,提问作者lakshmi narayanan
相关产品推荐
相关产品推荐

