You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用k3d、ArgoCD配置Traefik Ingress访问8888端口异常排查

问题原因分析
  1. 端口映射与Ingress Controller监听端口不匹配
    你创建k3d集群时的端口映射命令:

    k3d cluster create -p 8888:8888@loadbalancer -p 8080:80@loadbalancer
    

    其中8080:80@loadbalancer是把宿主机8080端口转发到集群负载均衡器的80端口,而Traefik作为默认Ingress Controller,它的Service默认暴露80/443端口,所以这个映射能关联到Traefik的监听端口,是有效的。但8888:8888@loadbalancer是转发到负载均衡器的8888端口,而Traefik并没有监听这个端口,所以当你访问localhost:8888时,请求根本没被Traefik处理,直接返回空回复。

  2. Ingress路由规则的匹配逻辑
    你的两个Ingress都配置在Traefik的80端口上:

    • ArgoCD的Ingress匹配argocd.local主机
    • 应用的Ingress匹配localhost主机
      当你访问localhost:8080时,请求被转发到Traefik的80端口,Traefik根据Host: localhost头匹配应用的Ingress,所以能正常访问;但当两个Ingress都存在时,你访问localhost:8888是打到负载均衡器的8888端口,Traefik没监听这个端口,自然无法处理。
  3. 删除ArgoCD Ingress后的现象
    删除ArgoCD的Ingress后,你访问localhost:8080依然是打到Traefik的80端口,此时只有应用的Ingress规则,所以能正常匹配——这里要注意,Ingress的backend端口是集群内部Service的端口,和宿主机映射的端口是完全独立的两回事。

解决方案

方案1:调整端口映射,复用Traefik的80端口

修改k3d集群创建命令(若重新创建集群):

k3d cluster create -p 8888:80@loadbalancer -p 8080:80@loadbalancer

或者通过k3d edit修改现有集群的端口映射,将宿主机8888绑定到负载均衡器的80端口。这样访问localhost:8888和localhost:8080都会打到Traefik的80端口,Traefik会根据Host头分别路由:

  • 访问应用:添加Host: localhost头
    curl -H "Host: localhost" localhost:8888
    
  • 访问ArgoCD:添加Host: argocd.local头
    curl -H "Host: argocd.local" localhost:8080
    

也可以在宿主机/etc/hosts中添加:

127.0.0.1 argocd.local

之后直接访问argocd.local:8080和localhost:8888就能自动匹配对应Ingress规则。

方案2:配置Traefik多端口监听

如果需要让Traefik同时监听80和8888端口,可以按以下步骤操作:

  1. 编辑Traefik的Service(默认在kube-system命名空间):
    kubectl edit svc traefik -n kube-system
    
    添加8888端口的暴露配置:
    ports:
    - name: web
      port: 80
      targetPort: web
    - name: web-alt
      port: 8888
      targetPort: web
    
  2. 修改应用的Ingress配置,指定绑定到8888端口:
    apiVersion: networking.k8s.io/v1
    kind: Ingress
    metadata:
      name: wil-app-ingress
      namespace: dev
      annotations:
        ingress.kubernetes.io/ssl-redirect: "false"
    spec:
      ports:
      - name: web-alt
        number: 8888
      rules:
      - host: localhost
        http:
          paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: wil-app-svc
                port:
                  number: 8888
    
    配置完成后,Traefik的8888端口会处理应用的Ingress请求,宿主机的8888:8888映射即可生效,直接访问localhost:8888就能访问应用。
关键概念澄清
  • Ingress Controller端口:Traefik作为Ingress Controller,它的Service暴露的端口是外部请求进入集群的入口,Ingress规则是绑定到这些端口上的。
  • Ingress backend端口:是集群内部Service的端口,仅负责集群内部的流量转发,和外部宿主机映射的端口没有直接关联。
  • Host头匹配:Traefik默认根据请求的HostHTTP头来匹配不同的Ingress规则,这是Ingress路由的核心逻辑之一。

内容的提问来源于stack exchange,提问作者Batche

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 19:05:38