You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes Network Policy异常:mydeploy2访问mydeploy超时求助

Kubernetes Network Policy 故障排查:mydeploy2到mydeploy访问超时

我花了一上午时间仍无法让Kubernetes Network Policy按预期工作。集群内除pod/mydeploy2-784fbfd764-mfslq到pod/mydeploy-5865fb49b4-ks7sx的curl请求出现超时外,其余Ingress和Egress规则均正常运行。

集群服务信息

NAME                             READY   STATUS    RESTARTS   AGE    LABELS
pod/mydeploy-5865fb49b4-ks7sx    1/1     Running   0          108m   app=mydeploy,pod-template-hash=5865fb49b4
pod/mydeploy2-784fbfd764-mfslq   1/1     Running   0          103m   app=mydeploy2,pod-template-hash=784fbfd764
pod/nginx-77b4fdf86c-w55np       1/1     Running   0          138m   app=nginx,pod-template-hash=77b4fdf86c
pod/nginx2-6f69878b4f-jvgn2      1/1     Running   0          16m    app=nginx2,pod-template-hash=6f69878b4f

NAME                        READY   UP-TO-DATE   AVAILABLE   AGE    LABELS
deployment.apps/mydeploy    1/1     1            1           108m   app=mydeploy
deployment.apps/mydeploy2   1/1     1            1           103m   app=mydeploy2
deployment.apps/nginx       1/1     1            1           138m   app=nginx
deployment.apps/nginx2      1/1     1            1           16m    app=nginx2

NAME                TYPE        CLUSTER-IP       EXTERNAL-IP   PORT(S)   AGE    LABELS
service/mydeploy    ClusterIP   10.103.14.10     <none>        80/TCP    108m   app=mydeploy
service/mydeploy2   ClusterIP   10.102.159.245   <none>        80/TCP    103m   app=mydeploy2
service/nginx       ClusterIP   10.110.131.138   <none>        80/TCP    138m   app=nginx
service/nginx2      ClusterIP   10.101.249.45    <none>        80/TCP    16m    app=nginx2

当前配置的Network Policy

---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  creationTimestamp: "2023-05-01T18:48:28Z"
  generation: 5
  name: default-deny
  namespace: policy-demo
  resourceVersion: "405350"
  uid: 52f57496-526f-4da0-abf2-a105e43e1c8b
spec:
  podSelector:
    matchLabels:
      app: nginx
  policyTypes:
  - Ingress
  - Egress
status: {}
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: default-allow
  namespace: policy-demo
spec:
  podSelector:
    matchLabels:
      app: mydeploy2
  egress:
    - to:
      - podSelector:
          matchLabels:
            app: mydeploy
  ingress:
    - from:
      - podSelector:
          matchLabels:
            app: mydeploy
  policyTypes:
    - Egress
    - Ingress
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: default-allow-2
  namespace: policy-demo
spec:
  podSelector:
    matchLabels:
      app: mydeploy
  egress:
    - {}
  ingress:
    - {}
  policyTypes:
    - Ingress
    - Egress

故障现象:mydeploy2 Pod访问mydeploy超时

k exec mydeploy2-784fbfd764-mfslq -- curl mydeploy
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
  0     0    0     0    0     0      0      0 --:--:--  0:00:12 --:--:--     0
  0     0    0     0    0     0      0      0 --:--:--  0:00:19 --:--:--     0curl: (6) Could not resolve host: mydeploy
command terminated with exit code 6

正常情况:mydeploy Pod访问mydeploy2正常

k exec mydeploy-5865fb49b4-ks7sx -- curl mydeploy2
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100   615  100   615    0     0   600k      0 --:--:-- --:--:-- --:--:--  600
<!DOCTYPE html>
<html>
<head>
<title>Welcome to nginx!</title>
<style>
html { color-scheme: light dark; }
body { width: 35em; margin: 0 auto;
font-family: Tahoma, Verdana, Arial, sans-serif; }
</style>
</head>
<body>
<h1>Welcome to nginx!</h1>
<p>If you see this page, the nginx web server is successfully installed and
working. Further configuration is required.</p>

<p>For online documentation and support please refer to
<a href="http://nginx.org/">nginx.org</a>.<br/>
Commercial support is available at
<a href="http://nginx.com/">nginx.com</a>.</p>

<p><em>Thank you for using nginx.</em></p>
</body>
</html>

内容的提问来源于stack exchange,提问作者sandeep

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 05:47:46