You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Minikube中用ExternalName Service访问Ingress暴露服务遇连接拒绝问题

问题排查:ExternalName Service 无法访问 Ingress 暴露的服务

问题场景

在本地Minikube集群测试Kubernetes跨集群访问场景:通过ExternalName Service访问另一集群(本地仅单集群,仅验证方式可行性)中Ingress暴露的内部服务。执行minikube tunnel启动隧道后,本地可通过http://k8s-yaml-hello.info正常访问服务,但在集群内运行的Pod中执行curl k8s-yaml-hello-internal时,出现错误:

curl: (7) Failed to connect to k8s-yaml-hello-internal port 80 after 1161 ms: Connection refused

相关配置

service.yaml

apiVersion: v1
kind: Service
metadata:
  name: k8s-yaml-hello
spec:
  selector:
    app: k8s-yaml-hello
  ports:
  - port: 3000
    targetPort: 3000

ingress.yaml

kind: Ingress
metadata:
  name: k8s-yaml-hello-ingress
  labels:
    name: k8s-yaml-hello-ingress
spec:
  rules:
  - host: k8s-yaml-hello.info
    http:
      paths:
      - pathType: Prefix
        path: "/"
        backend:
          service:
            name: k8s-yaml-hello
            port: 
              number: 3000

externalName.yaml

apiVersion: v1
kind: Service
metadata:
  name: k8s-yaml-hello-internal
spec:
  ports:
  - name: ''
    appProtocol: http
    protocol: TCP
    port: 3000
  type: ExternalName
  externalName: k8s-yaml-hello.info

本地etc/hosts

127.0.0.1   k8s-yaml-hello.info

排查与解决方案

1. 端口不匹配问题

执行curl时未指定端口,默认使用80端口,但你的ExternalName Service配置的暴露端口是3000,因此需指定端口访问:

curl k8s-yaml-hello-internal:3000

若希望无需指定端口,可修改ExternalName Service的端口为80(Ingress默认监听端口):

apiVersion: v1
kind: Service
metadata:
  name: k8s-yaml-hello-internal
spec:
  ports:
  - name: http
    appProtocol: http
    protocol: TCP
    port: 80
  type: ExternalName
  externalName: k8s-yaml-hello.info

重新应用配置:kubectl apply -f externalName.yaml

2. Pod内部域名解析问题

本地机器的etc/hosts配置无法同步到集群Pod内部,Pod无法将k8s-yaml-hello.info解析到正确地址:

  • 先获取Minikube集群的Ingress Controller访问地址:
    minikube ip
    
  • 临时测试:进入Pod内部手动修改/etc/hosts
    kubectl exec -it <你的Pod名称> -- /bin/sh
    echo "<Minikube_IP> k8s-yaml-hello.info" >> /etc/hosts
    
  • 永久配置:在Pod的Deployment/YAML中添加hostAliases字段
    spec:
      hostAliases:
      - ip: "<Minikube_IP>"
        hostnames:
        - "k8s-yaml-hello.info"
    

3. 验证ExternalName Service状态

确认ExternalName Service已正常创建并解析:

kubectl get svc k8s-yaml-hello-internal
kubectl describe svc k8s-yaml-hello-internal

检查输出中ExternalName字段是否为k8s-yaml-hello.info,端口配置是否正确。

内容的提问来源于stack exchange,提问作者mt-user20620859

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 07:35:17