You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Minikube内无法通过Cluster IP访问Service问题求助

Kubernetes Minikube中ClusterIP Service无法访问排查

我正在学习Kubernetes课程,已创建包含3个运行nginx的Pod的Deployment,能够单独访问每个Pod,但无法在Minikube内部通过Service的Cluster IP及暴露的端口访问整个服务。完全按照课程步骤操作,不清楚问题所在,希望有人能帮忙排查。

操作日志

alejandro@alejandro-Latitude-7390:~$ kubectl get service
NAME         TYPE        CLUSTER-IP   EXTERNAL-IP   PORT(S)   AGE
kubernetes   ClusterIP   10.96.0.1    <none>        443/TCP   38d
alejandro@alejandro-Latitude-7390:~$ kubectl describe service kubernetes
Name:              kubernetes
Namespace:         default
Labels:            component=apiserver
                   provider=kubernetes
Annotations:       <none>
Selector:          <none>
Type:              ClusterIP
IP Family Policy:  SingleStack
IP Families:       IPv4
IP:                10.96.0.1
IPs:               10.96.0.1
Port:              https  443/TCP
TargetPort:        8443/TCP
Endpoints:         192.168.59.100:8443
Session Affinity:  None
Events:            <none>
alejandro@alejandro-Latitude-7390:~$ kubectl get service
NAME         TYPE        CLUSTER-IP   EXTERNAL-IP   PORT(S)   AGE
kubernetes   ClusterIP   10.96.0.1    <none>        443/TCP   38d
alejandro@alejandro-Latitude-7390:~$ kubectl expose deployment nginx-deployment --port=80 --target-port=80
service/nginx-deployment exposed
alejandro@alejandro-Latitude-7390:~$ kubectl get service
NAME               TYPE        CLUSTER-IP      EXTERNAL-IP   PORT(S)   AGE
kubernetes         ClusterIP   10.96.0.1       <none>        443/TCP   38d
nginx-deployment   ClusterIP   10.98.250.240   <none>        80/TCP    3s
alejandro@alejandro-Latitude-7390:~$ kubectl describe service nginx-deployment
Name:              nginx-deployment
Namespace:         default
Labels:            app=nginx-deployment
Annotations:       <none>
Selector:          app=nginx-deployment
Type:              ClusterIP
IP Family Policy:  SingleStack
IP Families:       IPv4
IP:                10.98.250.240
IPs:               10.98.250.240
Port:              <unset>  80/TCP
TargetPort:        80/TCP
Endpoints:         172.17.0.3:80,172.17.0.4:80,172.17.0.5:80
Session Affinity:  None
Events:            <none>
alejandro@alejandro-Latitude-7390:~$ sudo ssh -o StrictHostKeyChecking=no docker@192.168.59.100 
[sudo] password for alejandro: 
docker@192.168.59.100's password: 
                         _             _            
            _         _ ( )           ( )           
  ___ ___  (_)  ___  (_)| |/' _   _ | |_      __  
/' _ ` _ `\| |/' _ `\| || , <  ( ) ( )| '_`\  /'__`\
| ( ) ( ) || || ( ) || || |\`\ | (_) || |_) )(  ___/
(_) (_) (_)(_)(_) (_)(_)(_) (_)`\___/'(_,__/'`\____)

$ curl 10.98.250.240:80
^C
$ 

排查建议

  • 检查网络组件状态:执行 kubectl get pods -n kube-system,确认kube-proxy、集群网络插件(如calico/flannel)的Pod都处于Running状态。kube-proxy负责ClusterIP的流量转发,若它异常会直接导致Service无法访问。
  • 验证标签匹配:执行 kubectl get pods --show-labels,确认Pod的app标签值为nginx-deployment,与Service的Selector完全一致。虽然当前Service已关联到Endpoints,但仍需确认标签无拼写错误。
  • 测试Pod节点内连通性:在Minikube节点内执行 curl 172.17.0.3:80(替换为任意Pod的IP),再次确认Pod本身能正常响应请求。
  • 查看kube-proxy日志:执行 kubectl logs -n kube-system -l k8s-app=kube-proxy,排查是否有iptables/ipvs规则生成失败、转发错误等日志信息。
  • 检查iptables规则:在Minikube节点内执行 sudo iptables-save | grep 10.98.250.240,查看是否存在指向Pod IP的DNAT规则。若规则缺失,说明kube-proxy未正确配置转发规则。
  • 重启kube-proxy:执行 kubectl rollout restart daemonset kube-proxy -n kube-system,等待组件重启后再次测试Service连通性。
  • 切换Service类型测试:执行 kubectl patch service nginx-deployment -p '{"spec":{"type":"NodePort"}}',将Service改为NodePort类型,再通过minikube service nginx-deployment访问。若NodePort能正常访问,问题集中在ClusterIP的转发逻辑;若仍无法访问,需排查Pod或网络插件的底层问题。

内容的提问来源于stack exchange,提问作者Ale2600

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 20:25:22