K8s问题:无法从Worker节点通过ClusterIP访问同节点Pod
Let’s break down the possible causes and fixes for your issue where you can’t reach a Pod via its ClusterIP Service from the same Worker node:
1. Verify Kube-proxy is Running on the Worker Node
ClusterIP routing relies entirely on kube-proxy to manage iptables rules that forward traffic from the ClusterIP to the Pod’s IP. On your Worker node, run these commands to check its status:
# Check kube-proxy service status (if using systemd) systemctl status kube-proxy # Or check the kube-proxy Pod in the kube-system namespace kubectl get pods -n kube-system | grep kube-proxy
If kube-proxy isn’t running or is in a crashloop, restart it:
systemctl restart kube-proxy # Or delete the Pod to let Kubernetes recreate it kubectl delete pod -n kube-system <kube-proxy-pod-name>
2. Validate Iptables Rules for the ClusterIP
Kube-proxy creates iptables rules to map the ClusterIP to the Pod’s Endpoint. On the Worker node, check if the rules exist:
iptables-save | grep 10.100.126.230
You should see a DNAT rule pointing to your Pod’s IP (192.168.171.74:5000). If no rules show up, force kube-proxy to reload its configuration:
kubectl rollout restart daemonset kube-proxy -n kube-system
3. Test Direct Access to the Pod IP
First, rule out issues with the Pod itself. On the Worker node, try curling the Pod’s IP directly:
curl http://192.168.171.74:5000
If this fails, check if the container’s registry service is actually listening on port 5000:
kubectl exec -it registry-7ccd695dc7-69cx4 -- netstat -tulpn | grep 5000
You should see output like tcp 0 0 0.0.0.0:5000 0.0.0.0:* LISTEN 1/registry. If not, check the container logs to debug service startup issues:
kubectl logs registry-7ccd695dc7-69cx4
4. Check Calico Network Plugin Status
Your Pod uses Calico for networking, so ensure Calico is functioning correctly on the Worker node:
# Check calico-node status calico-node status # Verify the Pod's IP is in the node's routing table ip route show | grep 192.168.171.74
If the route doesn’t exist, restart the Calico node Pod on the Worker:
kubectl delete pod -n kube-system -l k8s-app=calico-node
5. Rule Out Firewall Blockages
Check if the Worker node’s firewall is blocking traffic to the ClusterIP or Pod IP:
# Check ufw status (if enabled) ufw status # List iptables input rules iptables -L INPUT -n
If you see rules blocking port 5000 or the ClusterIP/Pod IP ranges, adjust the firewall to allow this traffic.
内容的提问来源于stack exchange,提问作者Aakash Verma

