You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

K8s问题:无法从Worker节点通过ClusterIP访问同节点Pod

Troubleshooting ClusterIP Access Failure on Worker Node

Let’s break down the possible causes and fixes for your issue where you can’t reach a Pod via its ClusterIP Service from the same Worker node:

1. Verify Kube-proxy is Running on the Worker Node

ClusterIP routing relies entirely on kube-proxy to manage iptables rules that forward traffic from the ClusterIP to the Pod’s IP. On your Worker node, run these commands to check its status:

# Check kube-proxy service status (if using systemd)
systemctl status kube-proxy

# Or check the kube-proxy Pod in the kube-system namespace
kubectl get pods -n kube-system | grep kube-proxy

If kube-proxy isn’t running or is in a crashloop, restart it:

systemctl restart kube-proxy
# Or delete the Pod to let Kubernetes recreate it
kubectl delete pod -n kube-system <kube-proxy-pod-name>

2. Validate Iptables Rules for the ClusterIP

Kube-proxy creates iptables rules to map the ClusterIP to the Pod’s Endpoint. On the Worker node, check if the rules exist:

iptables-save | grep 10.100.126.230

You should see a DNAT rule pointing to your Pod’s IP (192.168.171.74:5000). If no rules show up, force kube-proxy to reload its configuration:

kubectl rollout restart daemonset kube-proxy -n kube-system

3. Test Direct Access to the Pod IP

First, rule out issues with the Pod itself. On the Worker node, try curling the Pod’s IP directly:

curl http://192.168.171.74:5000

If this fails, check if the container’s registry service is actually listening on port 5000:

kubectl exec -it registry-7ccd695dc7-69cx4 -- netstat -tulpn | grep 5000

You should see output like tcp 0 0 0.0.0.0:5000 0.0.0.0:* LISTEN 1/registry. If not, check the container logs to debug service startup issues:

kubectl logs registry-7ccd695dc7-69cx4

4. Check Calico Network Plugin Status

Your Pod uses Calico for networking, so ensure Calico is functioning correctly on the Worker node:

# Check calico-node status
calico-node status

# Verify the Pod's IP is in the node's routing table
ip route show | grep 192.168.171.74

If the route doesn’t exist, restart the Calico node Pod on the Worker:

kubectl delete pod -n kube-system -l k8s-app=calico-node

5. Rule Out Firewall Blockages

Check if the Worker node’s firewall is blocking traffic to the ClusterIP or Pod IP:

# Check ufw status (if enabled)
ufw status

# List iptables input rules
iptables -L INPUT -n

If you see rules blocking port 5000 or the ClusterIP/Pod IP ranges, adjust the firewall to allow this traffic.


内容的提问来源于stack exchange,提问作者Aakash Verma

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 15:23:14