EKS Fargate集群Spring Boot应用无法公网访问求助
EKS Fargate集群部署Spring Boot应用无法访问端点问题
已执行操作
1. CloudFormation创建EKS Fargate集群
使用以下CloudFormation模板成功创建堆栈:
--- AWSTemplateFormatVersion: '2010-09-09' Description: 'AWS CloudFormation template for EKS Fargate managed Kubernetes cluster with exposed endpoints' Resources: VPC: Type: AWS::EC2::VPC Properties: CidrBlock: 10.0.0.0/16 EnableDnsSupport: true EnableDnsHostnames: true InternetGateway: Type: AWS::EC2::InternetGateway VPCGatewayAttachment: Type: AWS::EC2::VPCGatewayAttachment Properties: VpcId: !Ref VPC InternetGatewayId: !Ref InternetGateway PublicSubnet: Type: AWS::EC2::Subnet Properties: VpcId: !Ref VPC CidrBlock: 10.0.2.0/24 MapPublicIpOnLaunch: true AvailabilityZone: !Select [ 0, !GetAZs '' ] PrivateSubnetA: Type: AWS::EC2::Subnet Properties: VpcId: !Ref VPC CidrBlock: 10.0.0.0/24 AvailabilityZone: !Select [ 0, !GetAZs '' ] PrivateSubnetB: Type: AWS::EC2::Subnet Properties: VpcId: !Ref VPC CidrBlock: 10.0.1.0/24 AvailabilityZone: !Select [ 1, !GetAZs '' ] PublicRouteTable: Type: AWS::EC2::RouteTable Properties: VpcId: !Ref VPC PublicRoute: Type: AWS::EC2::Route Properties: RouteTableId: !Ref PublicRouteTable DestinationCidrBlock: 0.0.0.0/0 GatewayId: !Ref InternetGateway SubnetRouteTableAssociationA: Type: AWS::EC2::SubnetRouteTableAssociation Properties: SubnetId: !Ref PublicSubnet RouteTableId: !Ref PublicRouteTable EIP: Type: AWS::EC2::EIP NatGateway: Type: AWS::EC2::NatGateway Properties: SubnetId: !Ref PublicSubnet AllocationId: !GetAtt EIP.AllocationId PrivateRouteTable: Type: AWS::EC2::RouteTable Properties: VpcId: !Ref VPC PrivateRoute: Type: AWS::EC2::Route Properties: RouteTableId: !Ref PrivateRouteTable DestinationCidrBlock: 0.0.0.0/0 NatGatewayId: !Ref NatGateway PrivateSubnetRouteTableAssociationA: Type: AWS::EC2::SubnetRouteTableAssociation Properties: SubnetId: !Ref PrivateSubnetA RouteTableId: !Ref PrivateRouteTable PrivateSubnetRouteTableAssociationB: Type: AWS::EC2::SubnetRouteTableAssociation Properties: SubnetId: !Ref PrivateSubnetB RouteTableId: !Ref PrivateRouteTable EKSCluster: Type: AWS::EKS::Cluster Properties: Name: EKSFargateCluster Version: '1.26' ResourcesVpcConfig: SubnetIds: - !Ref PrivateSubnetA - !Ref PrivateSubnetB RoleArn: !GetAtt EKSClusterRole.Arn FargateProfile: Type: AWS::EKS::FargateProfile Properties: ClusterName: !Ref EKSCluster FargateProfileName: FargateProfile PodExecutionRoleArn: !GetAtt FargatePodExecutionRole.Arn Selectors: - Namespace: default Subnets: - !Ref PrivateSubnetA - !Ref PrivateSubnetB FargateProfileCoredns: Type: AWS::EKS::FargateProfile Properties: ClusterName: !Ref EKSCluster FargateProfileName: CorednsProfile PodExecutionRoleArn: !GetAtt FargatePodExecutionRole.Arn Selectors: - Namespace: kube-system Labels: - Key: k8s-app Value: kube-dns Subnets: - !Ref PrivateSubnetA - !Ref PrivateSubnetB FargatePodExecutionRole: Type: AWS::IAM::Role Properties: AssumeRolePolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Principal: Service: - eks-fargate-pods.amazonaws.com Action: - sts:AssumeRole ManagedPolicyArns: - arn:aws:iam::aws:policy/AmazonEKSFargatePodExecutionRolePolicy EKSClusterRole: Type: AWS::IAM::Role Properties: AssumeRolePolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Principal: Service: - eks.amazonaws.com Action: - sts:AssumeRole ManagedPolicyArns: - arn:aws:iam::aws:policy/AmazonEKSClusterPolicy - arn:aws:iam::aws:policy/AmazonEKSVPCResourceController
2. 修补CoreDNS适配Fargate
执行以下命令移除CoreDNS的EC2计算类型注解:
kubectl patch deployment coredns \ -n kube-system \ --type json \ -p='[{"op": "remove", "path": "/spec/template/metadata/annotations/eks.amazonaws.com~1compute-type"}]'
3. 部署Spring Boot应用与LoadBalancer Service
使用以下Kubernetes清单部署应用(镜像来自公共ECR):
--- apiVersion: apps/v1 kind: Deployment metadata: name: example-app spec: replicas: 2 selector: matchLabels: app: example-app template: metadata: labels: app: example-app spec: containers: - name: ventu image: public.ecr.aws/not_real_url/public_ecr_name:latest ports: - containerPort: 8080 --- apiVersion: v1 kind: Service metadata: name: example-service spec: type: LoadBalancer selector: app: example-app ports: - protocol: TCP port: 80 targetPort: 8080
执行kubectl get svc得到输出:
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE example-service LoadBalancer 172.20.228.77 aa0116829ac2647a7bf39a97bffb0183-1208408433.eu-central-1.elb.amazonaws.com 80:31915/TCP 16m kubernetes ClusterIP 172.20.0.1 <none> 443/TCP 29m
问题现象
访问example-service的EXTERNAL-IP时得到空响应,无法访问Spring Boot应用定义的唯一路径/api/v1/info,应用配置如下:
server.port=8080 server.servlet.context-path=/api/v1
已确认的正常状态
- Pod已成功启动,
kubectl logs pod-name能看到Spring Boot启动日志 - CoreDNS Pod运行正常
- 使用busybox测试集群DNS解析正常
问题排查与解决方案
1. 确认请求路径正确性
Spring Boot配置了server.servlet.context-path=/api/v1,因此完整的访问路径应为:
http://<EXTERNAL-IP>/api/v1/info
若直接访问根路径(http://<EXTERNAL-IP>),会返回404或空响应,这是Spring Boot的默认行为。
2. 检查网络流量权限
Fargate Pod部署在私有子网,需验证以下网络配置:
- LoadBalancer安全组:确保允许来自互联网的80端口入站流量(0.0.0.0/0或指定IP范围)
- Fargate Pod安全组:确认允许来自LoadBalancer安全组的8080端口入站流量(Fargate Profile会自动创建关联Pod的安全组)
- VPC网络ACL:检查私有子网和公共子网的网络ACL是否允许80(入站)、8080(入站/出站)流量通过
3. 验证Service与Pod的关联
执行以下命令确认Service的Endpoints是否正确关联到Pod:
kubectl describe svc example-service
查看Endpoints字段,应显示已启动Pod的IP和8080端口。若Endpoints为空,需检查Deployment的标签与Service的选择器是否匹配(当前配置标签一致,大概率无问题)。
4. 测试集群内部访问
先在集群内部验证应用是否可正常响应:
- 访问Service的ClusterIP:
kubectl run -it --rm busybox --image=busybox:1.28 -- wget -O- http://172.20.228.77/api/v1/info - 直接访问Pod的IP(需先通过
kubectl get pods -o wide获取Pod IP):kubectl run -it --rm busybox --image=busybox:1.28 -- wget -O- http://<Pod-IP>:8080/api/v1/info
如果内部访问正常,说明问题出在外部流量到LoadBalancer的路径上;如果内部也无响应,需检查Spring Boot应用的端点配置是否正确(比如是否有过滤器拦截请求)。
内容的提问来源于stack exchange,提问作者Jakub Zak
相关产品推荐
相关产品推荐

