OpenShift集群中Zabbix连接外部VM失败,Agent拒绝动态IP请求
OpenShift部署Zabbix后无法监控集群外VM的解决方案
问题背景
在OpenShift集群中通过官方kubernetes.yaml部署Zabbix 6.2后,监控集群外VM时出现连接失败:
- Zabbix Server日志显示持续网络错误,最终临时禁用主机检查
- 集群外VM的Zabbix Agent日志明确拒绝了来自9.x.x.x系列动态IP的连接,因为Agent配置的
Server参数为集群内服务名zabbix-server,无法匹配动态变化的节点出口IP
Zabbix Server错误日志
Defaulted container "zabbix-server" out of: zabbix-server, zabbix-snmptraps ** Updating '/etc/zabbix/zabbix_server.conf' parameter "DBHost": 'mysql-server'...added 287:20230120:060843.131 Zabbix agent item "system.cpu.load[all,avg5]" on host "Host-C" failed: first network error, wait for 15 seconds 289:20230120:060858.592 Zabbix agent item "system.cpu.num" on host "Host-C" failed: another network error, wait for 15 seconds 289:20230120:060913.843 Zabbix agent item "system.sw.arch" on host "Host-C" failed: another network error, wait for 15 seconds 289:20230120:060929.095 temporarily disabling Zabbix agent checks on host "Host-C": interface unavailable
Zabbix Agent错误日志
350446:20230122:103232.230 failed to accept an incoming connection: connection from "9.x.x.219" rejected, allowed hosts: "zabbix-server" 350444:20230122:103332.525 failed to accept an incoming connection: connection from "9.x.x.219" rejected, allowed hosts: "zabbix-server" 350445:20230122:103432.819 failed to accept an incoming connection: connection from "9.x.x.210" rejected, allowed hosts: "zabbix-server" 350446:20230122:103533.114 failed to accept an incoming connection: connection from "9.x.x.217" rejected, allowed hosts: "zabbix-server"
稳定解决方案
方案1:为Zabbix Server配置固定出口IP(推荐)
利用OpenShift的EgressIP或LoadBalancer特性,让Zabbix Server的所有出站请求使用固定IP:
- 为Zabbix Server所在命名空间配置EgressIP,指定集群的固定出口IP地址
- 将VM上的
/etc/zabbix/zabbix_agentd.conf中Server参数修改为该固定IP - 重启Zabbix Agent服务:
systemctl restart zabbix-agent
这种方式既保证安全,又避免IP动态变化的问题
方案2:允许Agent接受整个9.x.x.x网段
如果确认9.x.x.x网段仅为OpenShift节点的出口网段,可直接在Agent配置中放行整个网段:
- 修改VM的
/etc/zabbix/zabbix_agentd.conf:
Server=9.x.x.0/24
(根据实际网段调整子网掩码,比如9.x.x.0/16)
2. 重启Zabbix Agent服务
方案3:切换为Zabbix主动监控模式
让Agent主动向Zabbix Server上报数据,无需Server主动连接:
- 在Zabbix Web控制台中,将目标主机的监控模式设置为主动式
- 修改VM的
/etc/zabbix/zabbix_agentd.conf:
ServerActive=你的Zabbix Server外部可访问地址/域名 Hostname=Host-C # 必须与Zabbix Web中配置的主机名完全一致
- 重启Zabbix Agent服务
内容的提问来源于stack exchange,提问作者Resham Chaney
相关产品推荐
相关产品推荐

