无法通过LoadBalancer访问AKS中Pod的问题求助
问题:AKS中LoadBalancer无法连接WebAPI,报错connect ETIMEDOUT
昨日将WebAPI部署至Azure Kubernetes Service(AKS),同时创建了LoadBalancer,但通过Postman调用API时始终报错:
Error: connect ETIMEDOUT {{负载均衡器公网IP}}:8080
部署配置(deployment.yml)
apiVersion: apps/v1 kind: Deployment metadata: name: neume-billing-service-deployment labels: app: neume-billing-service spec: replicas: 1 selector: matchLabels: app: neume-billing-service-pod template: metadata: labels: app: neume-billing-service-pod spec: containers: - name: neume-billing-service-container image: neume.azurecr.io/neume:v2 ports: - containerPort: 80
服务配置(service.yml)
apiVersion: v1 kind: Service metadata: name: neume-service spec: selector: app: neume-billing-service-pod ports: - port: 8080 targetPort: 80 type: LoadBalancer
关键排查信息
kubectl describe pod结果显示Pod运行在namespace-workflow-1683420009400命名空间,状态正常,标签为app=neume-billing-service-podkubectl describe service结果显示Service运行在default命名空间,Endpoints:,说明没有匹配到任何Pod - AKS仪表板中服务的「Pods」标签页无关联Pod,但
kubectl get pods能看到正常运行的Pod
问题根源
Pod和Service处于不同的Kubernetes命名空间:
- Pod所在命名空间:
namespace-workflow-1683420009400 - Service所在命名空间:
default
Kubernetes的Service默认只会在自身所在命名空间内匹配带有对应标签的Pod,跨命名空间的标签匹配不会生效,因此Service无法找到Pod,导致Endpoints为空,最终LoadBalancer无法将流量转发到后端API,出现连接超时错误。
修复方案
有两种可行的修复方式,任选其一即可:
方式1:将Service部署到Pod所在的命名空间
修改service.yml,添加namespace字段指定Pod所在的命名空间:
apiVersion: v1 kind: Service metadata: name: neume-service namespace: namespace-workflow-1683420009400 # 指定Pod所在命名空间 spec: selector: app: neume-billing-service-pod ports: - port: 8080 targetPort: 80 type: LoadBalancer
重新应用配置:
kubectl apply -f service.yml
方式2:将Pod部署到Service所在的default命名空间
修改deployment.yml,添加namespace字段指定为default:
apiVersion: apps/v1 kind: Deployment metadata: name: neume-billing-service-deployment namespace: default # 指定default命名空间 labels: app: neume-billing-service spec: replicas: 1 selector: matchLabels: app: neume-billing-service-pod template: metadata: labels: app: neume-billing-service-pod spec: containers: - name: neume-billing-service-container image: neume.azurecr.io/neume:v2 ports: - containerPort: 80
重新应用配置:
kubectl apply -f deployment.yml
验证修复效果
执行以下命令确认Service已成功关联Pod:
kubectl describe service neume-service -n <目标命名空间>
查看输出中的Endpoints字段,若显示Pod的IP地址(如10.244.0.8:80),则说明关联成功,此时再通过LoadBalancer公网IP调用API即可正常访问。
内容的提问来源于stack exchange,提问作者stefan de boer
相关产品推荐
相关产品推荐

