Azure Kubernetes Service中部署ASP.NET应用无法访问求助
问题排查与修复方案
1. 核心端口不匹配问题
你的Istio VirtualService配置中,目标端口指定为8080,但Deployment里的容器端口是80、Service暴露的端口也是80,这直接导致Istio路由无法将请求转发到正确端口,是访问失败的首要原因。
修复: 修改VirtualService的目标端口为80:
apiVersion: networking.istio.io/v1alpha3 kind: VirtualService metadata: name: aks-test-web-app spec: hosts: - "sample.com" - "sample.internal" gateways: - sample http: - match: - uri: prefix: /aks-test-webapp route: - destination: host: aks-test-web-app.sample.svc.cluster.local port: number: 80 # 此处改为80
2. 验证Istio网关配置
你的VirtualService关联了名为sample的网关,需确保该网关存在且配置正确:
- 网关必须监听
80端口,且selector匹配Istio ingress网关的标签(通常为istio=ingressgateway) - 示例正确的Gateway配置:
apiVersion: networking.istio.io/v1alpha3 kind: Gateway metadata: name: sample spec: selector: istio: ingressgateway # 确保该标签对应集群内的Istio ingress网关Pod servers: - port: number: 80 name: http protocol: HTTP hosts: - "sample.com" - "sample.internal"
3. 修正访问方式
若使用Istio Ingress Gateway,不能直接访问LoadBalancer Service的外部IP,需按以下方式访问:
- 获取Istio Ingress Gateway的外部IP:
kubectl get service istio-ingressgateway -n istio-system
- 在本地hosts文件中添加映射:
[网关外部IP] sample.com - 通过路径访问:
http://sample.com/aks-test-webapp
4. 基础连通性测试(跳过Istio时)
若暂时不需要Istio路由,可先删除VirtualService,再做以下验证:
- 确认Service的外部IP已正常分配:
kubectl get service aks-test-web-app
- 集群内部测试连通性(Windows容器环境):
kubectl run -it --rm test-pod --image=mcr.microsoft.com/windows/servercore:ltsc2019 -- powershell Invoke-WebRequest http://aks-test-web-app.agys-pay.svc.cluster.local:80
- 检查AKS节点的网络安全组(NSG),确保入站规则允许
80端口的外部流量。
5. 检查容器内应用状态
若以上步骤仍无法解决,需确认Pod内的应用是否真的正常运行:
- 进入Pod内部测试:
kubectl exec -it aks-test-web-app-84647d8585-ht9wv -- powershell Invoke-WebRequest http://localhost:80
- 查看容器日志排查应用启动问题:
kubectl logs aks-test-web-app-84647d8585-ht9wv
内容的提问来源于stack exchange,提问作者Kalai Selvi
相关产品推荐
相关产品推荐

