Docker部署的GRPC客户端调用不安全GRPC服务遇连接拒绝错误求助
修复方案
1. 修正容器间通信的端口
你的docker-compose将主机8000端口映射到grpc服务容器的80端口,但容器间通信无需经过主机映射端口,直接使用服务容器内部监听的80端口即可。
修改grpcclient的环境变量:
- "GrpcServiceUrl=http://grpcservice:80"
2. 确保服务完全启动后再发起调用
depends_on仅保证容器启动顺序,不保证服务完成初始化。如果客户端启动时服务还未准备就绪,会触发连接拒绝错误。
- 测试环境:在客户端代码中添加启动延迟:
public static void CallGrpcService() { string serviceUrl = System.Environment.GetEnvironmentVariable("GrpcServiceUrl"); AppContext.SetSwitch("System.Net.Http.SocketsHttpHandler.Http2UnencryptedSupport", true); // 等待服务初始化完成 System.Threading.Thread.Sleep(5000); var channel = GrpcChannel.ForAddress(serviceUrl); var client = new Greeter.GreeterClient(channel); var reply = client.SayHello(new HelloRequest { Name = "GreeterClient" }); Console.WriteLine("Greeting: " + reply.Message); Console.WriteLine("Press any key to exit..."); Console.ReadKey(); }
- 生产环境:为grpc服务添加健康检查,让客户端等待服务健康后再启动:
grpcservice: # 现有配置... healthcheck: test: ["CMD", "curl", "-f", "http://localhost/healthz"] # 替换为你的服务健康检查端点 interval: 5s timeout: 5s retries: 3 grpcclient: # 现有配置... depends_on: grpcservice: condition: service_healthy
3. 确认gRPC服务监听所有网络接口
如果服务仅监听localhost,容器外(包括同网络的其他容器)无法访问。在ASP.NET Core服务的Program.cs中配置Kestrel监听所有IP:
builder.WebHost.ConfigureKestrel(options => { options.ListenAnyIP(80, o => o.Protocols = HttpProtocols.Http2); });
内容的提问来源于stack exchange,提问作者Ewerton
相关产品推荐
相关产品推荐

