You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EKS Fargate集群Spring Boot应用无法公网访问求助

EKS Fargate集群部署Spring Boot应用无法访问端点问题

已执行操作

1. CloudFormation创建EKS Fargate集群

使用以下CloudFormation模板成功创建堆栈:

---
AWSTemplateFormatVersion: '2010-09-09'
Description: 'AWS CloudFormation template for EKS Fargate managed Kubernetes cluster with exposed endpoints'

Resources:
  VPC:
    Type: AWS::EC2::VPC
    Properties:
      CidrBlock: 10.0.0.0/16
      EnableDnsSupport: true
      EnableDnsHostnames: true

  InternetGateway:
    Type: AWS::EC2::InternetGateway

  VPCGatewayAttachment:
    Type: AWS::EC2::VPCGatewayAttachment
    Properties:
      VpcId: !Ref VPC
      InternetGatewayId: !Ref InternetGateway

  PublicSubnet:
    Type: AWS::EC2::Subnet
    Properties:
      VpcId: !Ref VPC
      CidrBlock: 10.0.2.0/24
      MapPublicIpOnLaunch: true
      AvailabilityZone: !Select [ 0, !GetAZs '' ]

  PrivateSubnetA:
    Type: AWS::EC2::Subnet
    Properties:
      VpcId: !Ref VPC
      CidrBlock: 10.0.0.0/24
      AvailabilityZone: !Select [ 0, !GetAZs '' ]

  PrivateSubnetB:
    Type: AWS::EC2::Subnet
    Properties:
      VpcId: !Ref VPC
      CidrBlock: 10.0.1.0/24
      AvailabilityZone: !Select [ 1, !GetAZs '' ]

  PublicRouteTable:
    Type: AWS::EC2::RouteTable
    Properties:
      VpcId: !Ref VPC

  PublicRoute:
    Type: AWS::EC2::Route
    Properties:
      RouteTableId: !Ref PublicRouteTable
      DestinationCidrBlock: 0.0.0.0/0
      GatewayId: !Ref InternetGateway

  SubnetRouteTableAssociationA:
    Type: AWS::EC2::SubnetRouteTableAssociation
    Properties:
      SubnetId: !Ref PublicSubnet
      RouteTableId: !Ref PublicRouteTable

  EIP:
    Type: AWS::EC2::EIP

  NatGateway:
    Type: AWS::EC2::NatGateway
    Properties:
      SubnetId: !Ref PublicSubnet
      AllocationId: !GetAtt EIP.AllocationId

  PrivateRouteTable:
    Type: AWS::EC2::RouteTable
    Properties:
      VpcId: !Ref VPC

  PrivateRoute:
    Type: AWS::EC2::Route
    Properties:
      RouteTableId: !Ref PrivateRouteTable
      DestinationCidrBlock: 0.0.0.0/0
      NatGatewayId: !Ref NatGateway

  PrivateSubnetRouteTableAssociationA:
    Type: AWS::EC2::SubnetRouteTableAssociation
    Properties:
      SubnetId: !Ref PrivateSubnetA
      RouteTableId: !Ref PrivateRouteTable

  PrivateSubnetRouteTableAssociationB:
    Type: AWS::EC2::SubnetRouteTableAssociation
    Properties:
      SubnetId: !Ref PrivateSubnetB
      RouteTableId: !Ref PrivateRouteTable

  EKSCluster:
    Type: AWS::EKS::Cluster
    Properties:
      Name: EKSFargateCluster
      Version: '1.26'
      ResourcesVpcConfig:
        SubnetIds:
          - !Ref PrivateSubnetA
          - !Ref PrivateSubnetB
      RoleArn: !GetAtt EKSClusterRole.Arn

  FargateProfile:
    Type: AWS::EKS::FargateProfile
    Properties:
      ClusterName: !Ref EKSCluster
      FargateProfileName: FargateProfile
      PodExecutionRoleArn: !GetAtt FargatePodExecutionRole.Arn
      Selectors:
        - Namespace: default
      Subnets:
        - !Ref PrivateSubnetA
        - !Ref PrivateSubnetB

  FargateProfileCoredns:
    Type: AWS::EKS::FargateProfile
    Properties:
      ClusterName: !Ref EKSCluster
      FargateProfileName: CorednsProfile
      PodExecutionRoleArn: !GetAtt FargatePodExecutionRole.Arn
      Selectors:
        - Namespace: kube-system
          Labels:
            - Key: k8s-app
              Value: kube-dns
      Subnets:
        - !Ref PrivateSubnetA
        - !Ref PrivateSubnetB

  FargatePodExecutionRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Principal:
              Service:
                - eks-fargate-pods.amazonaws.com
            Action:
              - sts:AssumeRole
      ManagedPolicyArns:
        - arn:aws:iam::aws:policy/AmazonEKSFargatePodExecutionRolePolicy

  EKSClusterRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Principal:
              Service:
                - eks.amazonaws.com
            Action:
              - sts:AssumeRole
      ManagedPolicyArns:
        - arn:aws:iam::aws:policy/AmazonEKSClusterPolicy
        - arn:aws:iam::aws:policy/AmazonEKSVPCResourceController

2. 修补CoreDNS适配Fargate

执行以下命令移除CoreDNS的EC2计算类型注解:

kubectl patch deployment coredns \
    -n kube-system \
    --type json \
    -p='[{"op": "remove", "path": "/spec/template/metadata/annotations/eks.amazonaws.com~1compute-type"}]'

3. 部署Spring Boot应用与LoadBalancer Service

使用以下Kubernetes清单部署应用(镜像来自公共ECR):

---
apiVersion: apps/v1
kind: Deployment
metadata:
  name: example-app
spec:
  replicas: 2
  selector:
    matchLabels:
      app: example-app
  template:
    metadata:
      labels:
        app: example-app
    spec:
      containers:
        - name: ventu
          image: public.ecr.aws/not_real_url/public_ecr_name:latest
          ports:
            - containerPort: 8080

---
apiVersion: v1
kind: Service
metadata:
  name: example-service
spec:
  type: LoadBalancer
  selector:
    app: example-app
  ports:
    - protocol: TCP
      port: 80
      targetPort: 8080

执行kubectl get svc得到输出:

NAME              TYPE           CLUSTER-IP      EXTERNAL-IP                                                                  PORT(S)        AGE
example-service   LoadBalancer   172.20.228.77   aa0116829ac2647a7bf39a97bffb0183-1208408433.eu-central-1.elb.amazonaws.com   80:31915/TCP   16m
kubernetes        ClusterIP      172.20.0.1      <none>                                                                       443/TCP        29m

问题现象

访问example-service的EXTERNAL-IP时得到空响应,无法访问Spring Boot应用定义的唯一路径/api/v1/info,应用配置如下:

server.port=8080
server.servlet.context-path=/api/v1

已确认的正常状态

  • Pod已成功启动,kubectl logs pod-name能看到Spring Boot启动日志
  • CoreDNS Pod运行正常
  • 使用busybox测试集群DNS解析正常

问题排查与解决方案

1. 确认请求路径正确性

Spring Boot配置了server.servlet.context-path=/api/v1,因此完整的访问路径应为:

http://<EXTERNAL-IP>/api/v1/info

若直接访问根路径(http://<EXTERNAL-IP>),会返回404或空响应,这是Spring Boot的默认行为。

2. 检查网络流量权限

Fargate Pod部署在私有子网,需验证以下网络配置:

  • LoadBalancer安全组:确保允许来自互联网的80端口入站流量(0.0.0.0/0或指定IP范围)
  • Fargate Pod安全组:确认允许来自LoadBalancer安全组的8080端口入站流量(Fargate Profile会自动创建关联Pod的安全组)
  • VPC网络ACL:检查私有子网和公共子网的网络ACL是否允许80(入站)、8080(入站/出站)流量通过

3. 验证Service与Pod的关联

执行以下命令确认Service的Endpoints是否正确关联到Pod:

kubectl describe svc example-service

查看Endpoints字段,应显示已启动Pod的IP和8080端口。若Endpoints为空,需检查Deployment的标签与Service的选择器是否匹配(当前配置标签一致,大概率无问题)。

4. 测试集群内部访问

先在集群内部验证应用是否可正常响应:

  • 访问Service的ClusterIP:
    kubectl run -it --rm busybox --image=busybox:1.28 -- wget -O- http://172.20.228.77/api/v1/info
    
  • 直接访问Pod的IP(需先通过kubectl get pods -o wide获取Pod IP):
    kubectl run -it --rm busybox --image=busybox:1.28 -- wget -O- http://<Pod-IP>:8080/api/v1/info
    

如果内部访问正常,说明问题出在外部流量到LoadBalancer的路径上;如果内部也无响应,需检查Spring Boot应用的端点配置是否正确(比如是否有过滤器拦截请求)。

内容的提问来源于stack exchange,提问作者Jakub Zak

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 23:32:05