使用NodePort无法连接minikube中暴露的Kubernetes服务求助
我在minikube环境下搭建K8s集群,通过NodePort暴露的服务端点无法连接。容器日志显示运行正常,但访问 http://<node ip>:30100/<valid endpoint form container>(其中<node ip>是kubectl get nodes -o wide返回的INTERNAL IP列地址)没有响应。
不确定是否是部署配置问题,以下是我应用的YAML配置:
apiVersion: apps/v1 kind: Deployment metadata: name: auth-app-deployment labels: app: auth-app spec: replicas: 1 selector: matchLabels: app: auth-app template: metadata: labels: app: auth-app spec: containers: - name: auth-app image: <working image> ports: - containerPort: 80 --- apiVersion: v1 kind: Service metadata: name: auth-app-service spec: type: NodePort selector: app: auth-app ports: - protocol: TCP port: 80 targetPort: 80 nodePort: 30100
执行kubectl get all的输出结果:
NAME READY STATUS RESTARTS AGE pod/auth-app-deployment-58cd68d8cf-mjpph 1/1 Running 0 29m NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE service/auth-app-service NodePort 10.104.172.176 <none> 80:30100/TCP 138m service/kubernetes ClusterIP 10.96.0.1 <none> 443/TCP 150m NAME READY UP-TO-DATE AVAILABLE AGE deployment.apps/auth-app-deployment 1/1 1 1 138m NAME DESIRED CURRENT READY AGE replicaset.apps/auth-app-deployment-58cd68d8cf 1 1 1 29m
排查步骤及解决方案
适配minikube的NodePort访问规则
minikube环境不能直接用节点内部IP访问NodePort服务,执行minikube service auth-app-service命令,会自动生成可访问的外部URL并打开浏览器;或者运行minikube tunnel建立隧道后,再尝试访问。验证容器内服务的监听状态
进入容器执行curl localhost:80/<valid endpoint>确认服务本身能正常响应,同时检查服务监听地址是否为0.0.0.0(而非仅127.0.0.1),如果仅监听本地回环地址,集群内的Service无法连通容器内服务。确认Service与Pod的关联有效性
执行kubectl describe service auth-app-service查看Endpoints字段,若显示正确的Pod IP和端口,说明关联正常;若为空,需核对Pod标签与Service的selector是否完全匹配(当前配置标签为app: auth-app,看起来匹配,但可再次确认)。集群内测试Service连通性
启动临时Pod测试集群内访问:
kubectl run -it --rm --image=curlimages/curl curl-test # 进入Pod后执行 curl http://auth-app-service:80/<valid endpoint>
若能正常响应,说明Service到Pod的通路无问题,问题出在外部访问方式上;若无法响应,需排查容器内服务的运行状态。
- 检查主机防火墙规则
如果是在物理机或云主机上运行minikube,确认主机防火墙未阻止30100端口的入站流量。
内容的提问来源于stack exchange,提问作者chandler

