You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

升级K8s 1.22与Ingress v1后外部无法访问集群服务求助

调试手段建议

以下是针对当前问题可尝试的进一步调试步骤:

  • 测试公网IP端口连通性:直接对集群公网IP的80、443端口发起请求,验证网络链路是否通畅:

    curl -v http://10.245.215.152
    curl -v https://10.245.215.152 --insecure
    

    如果请求超时或被拒绝,大概率是安全组/防火墙拦截了端口,需检查节点安全组入站规则是否开放80、443端口,或节点内部iptables/firewalld是否有拦截策略。

  • 校验Ingress资源配置合法性:

    • 查看Ingress的详细状态与事件:kubectl describe ingress <你的Ingress名称>,确认Rules、TLS段配置无异常,且无报错事件。
    • 导出Ingress配置并核对API版本:kubectl get ingress -o yaml,确保使用的是networking.k8s.io/v1(K8s 1.22已废弃旧版Ingress API),同时检查path配置的pathType是否符合预期(v1版本默认Prefix,若需精确匹配需显式设置为Exact),backend结构是否遵循v1规范。
  • 集群内部验证Ingress转发逻辑:

    • 启动临时测试Pod:kubectl run -it --rm --image=curlimages/curl test-curl
    • 在Pod内模拟外部请求访问Ingress:
      # 测试HTTP
      curl -v http://grafana.shaungc.com -H "Host: grafana.shaungc.com"
      # 测试HTTPS(跳过证书校验)
      curl -v https://grafana.shaungc.com --resolve grafana.shaungc.com:443:<Ingress Controller的ClusterIP> --insecure
      
      如果内部请求正常,说明问题出在外部到集群的网络链路;如果内部也失败,需排查Ingress Controller的转发规则或后端服务连通性。
  • 检查Ingress Controller Service配置:

    • 查看Service详情:kubectl get svc <Ingress Controller Service名称> -n <Ingress命名空间> -o yaml
    • 确认Service类型(LoadBalancer/NodePort)、端口映射(80→targetPort、443→targetPort)是否正确,且targetPort与Ingress Controller Pod的监听端口一致(通常为80/443或8080/8443)。若为LoadBalancer类型,需确认EXTERNAL-IP与公网IP一致,且云服务商负载均衡的转发规则正常。
  • 排查TLS证书问题:

    • 查看默认TLS证书的有效性:
      kubectl get secret <默认证书Secret名称> -n <Ingress命名空间> -o jsonpath='{.data.tls\.crt}' | base64 -d | openssl x509 -text
      
      确认证书是否包含目标域名、是否过期。
    • 检查Ingress的TLS段是否正确引用了自定义证书Secret(若之前使用过),注意Secret需与Ingress处于同一命名空间,或Ingress Controller已配置跨命名空间引用权限。
  • 验证后端服务本身的可用性:

    • 获取后端Service的ClusterIP与端口:kubectl get svc <后端服务名称>
    • 在测试Pod内直接访问后端服务:curl -v http://<ClusterIP>:<端口>
    • 如果请求失败,说明后端服务或Pod网络存在问题,需检查Pod日志、CNI插件状态。
  • 确认Ingress Controller版本兼容性:

    • 查看Ingress Controller版本:kubectl exec <Ingress Controller Pod名称> -n <Ingress命名空间> -- nginx-ingress-controller --version
    • 核对官方文档,确认该版本是否兼容K8s 1.22(例如Nginx Ingress Controller需v1.0.0及以上版本支持K8s 1.22+)。

内容的提问来源于stack exchange,提问作者Shawn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 01:50:48