Kubernetes集群中Nginx反向代理间歇性504超时排查求助
问题排查请求:Kubernetes集群Nginx Ingress间歇性504网关超时
部署环境
- 自建VM Kubernetes(v1.26)集群:1个主节点 + 1个工作节点
- 主节点部署Nginx反向代理(Ingress Controller)
- 运行基础FastAPI应用,对应Deployment、Service、Ingress配置见下文
问题现象
该部署在云服务商环境完全正常,但在自建集群中,API正常运行一段时间后会突然出现504网关超时错误。重启Nginx Pod可临时恢复,但恢复时长不稳定,曾出现几分钟内反复故障又恢复的情况,目前已正常运行1小时。
已完成排查
- 超时期间验证:
- 通过
worker-ip:30008(NodePort)可正常访问API - 在主节点通过Service的ClusterIP能curl通FastAPI Pod
- 通过
- 资源排查:已安装Kubernetes metrics API,服务器无其他负载,暂未发现内存异常
Nginx日志(成功请求到超时期间)
X.X.X.X - - [09/Feb/2023:12:30:18 +0000] "GET /docs HTTP/1.1" 200 952 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:108.0) Gecko/20100101 Firefox/108.0" 373 0.019 [my-app-8005] [] 172.16.180.6:8005 952 0.019 200 22cd1b13ef2dcbf4b1be2983649f658c X.X.X.X - - [09/Feb/2023:12:30:19 +0000] "GET /openapi.json HTTP/1.1" 200 5868 "http://xxxx/docs" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:108.0) Gecko/20100101 Firefox/108.0" 323 0.003 [my-app-8005] [] 172.16.180.6:8005 5868 0.003 200 46551c8481d446ec69de2399f49b7f86 I0209 12:31:13.983933 7 queue.go:87] "queuing" item="&ObjectMeta{Name:sync status,GenerateName:,Namespace:,SelfLink:,UID:,ResourceVersion:,Generation:0,CreationTimestamp:0001-01-01 00:00:00 +0000 UTC,DeletionTimestamp:<nil>,DeletionGracePeriodSeconds:nil,Labels:map[string]string{},Annotations:map[string]string{},OwnerReferences:[]OwnerReference{},Finalizers:[],ManagedFields:[]ManagedFieldsEntry{},}" I0209 12:31:13.984018 7 queue.go:128] "syncing" key="&ObjectMeta{Name:sync status,GenerateName:,Namespace:,SelfLink:,UID:,ResourceVersion:,Generation:0,CreationTimestamp:0001-01-01 00:00:00 +0000 UTC,DeletionTimestamp:<nil>,DeletionGracePeriodSeconds:nil,Labels:map[string]string{},Annotations:map[string]string{},OwnerReferences:[]OwnerReference{},Finalizers:[],ManagedFields:[]ManagedFieldsEntry{},}" I0209 12:31:13.990418 7 status.go:275] "skipping update of Ingress (no change)" namespace="namespace" ingress="app-ingress-xxxx" I0209 12:32:13.983857 7 queue.go:87] "queuing" item="&ObjectMeta{Name:sync status,GenerateName:,Namespace:,SelfLink:,UID:,ResourceVersion:,Generation:0,CreationTimestamp:0001-01-01 00:00:00 +0000 UTC,DeletionTimestamp:<nil>,DeletionGracePeriodSeconds:nil,Labels:map[string]string{},Annotations:map[string]string{},OwnerReferences:[]OwnerReference{},Finalizers:[],ManagedFields:[]ManagedFieldsEntry{},}" I0209 12:32:13.983939 7 queue.go:128] "syncing" key="&ObjectMeta{Name:sync status,GenerateName:,Namespace:,SelfLink:,UID:,ResourceVersion:,Generation:0,CreationTimestamp:0001-01-01 00:00:00 +0000 UTC,DeletionTimestamp:<nil>,DeletionGracePeriodSeconds:nil,Labels:map[string]string{},Annotations:map[string]string{},OwnerReferences:[]OwnerReference{},Finalizers:[],ManagedFields:[]ManagedFieldsEntry{},}" I0209 12:32:13.990895 7 status.go:275] "skipping update of Ingress (no change)" namespace="namespace" ingress="app-ingress-xxxx" 2023/02/09 12:32:59 [error] 30#30: *4409 upstream timed out (110: Operation timed out) while connecting to upstream, client: X.X.X.X , server: xxxx, request: "GET /docs HTTP/1.1", upstream: "http://172.16.180.6:8005/docs", host: "xxxx" 2023/02/09 12:33:04 [error] 30#30: *4409 upstream timed out (110: Operation timed out) while connecting to upstream, client: X.X.X.X , server: xxxx, request: "GET /docs HTTP/1.1", upstream: "http://172.16.180.6:8005/docs", host: "xxxx" 2023/02/09 12:33:09 [error] 30#30: *4409 upstream timed out (110: Operation timed out) while connecting to upstream, client: X.X.X.X , server: xxxx, request: "GET /docs HTTP/1.1", upstream: "http://172.16.180.6:8005/docs", host: "xxxx" X.X.X.X - - [09/Feb/2023:12:33:09 +0000] "GET /docs HTTP/1.1" 504 160 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:108.0) Gecko/20100101 Firefox/108.0" 373 15.004 [my-app-8005] [] 172.16.180.6:8005, 172.16.180.6:8005, 172.16.180.6:8005 0, 0, 0 5.001, 5.001, 5.001 504, 504, 504 56fb622d8d89d8d7b3cdbc4a094215c3
应用配置YAML
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: app-ingress-xxxx spec: ingressClassName: nginx rules: - host: xxxx http: paths: - path: / pathType: Prefix backend: service: name: my-app port: number: 8005 --- apiVersion: apps/v1 kind: Deployment metadata: name: my-app namespace: namespace spec: progressDeadlineSeconds: 3600 replicas: 1 selector: matchLabels: app: my-app template: metadata: labels: app: my-app spec: containers: - name: backend image: xxxx imagePullPolicy: Always ports: - containerPort: 8005 imagePullSecrets: - name: xxxx --- apiVersion: v1 kind: Service metadata: name: my-app namespace: namespace labels: app: my-app spec: type: NodePort ports: - nodePort: 30008 port: 8005 protocol: TCP selector: app: my-app
注:文中应用名称和IP已做脱敏处理。
恳请提供进一步的排查方向,谢谢!
内容的提问来源于stack exchange,提问作者peppie
相关产品推荐
相关产品推荐

