Minikube内无法通过Cluster IP访问Service问题求助
Kubernetes Minikube中ClusterIP Service无法访问排查
我正在学习Kubernetes课程,已创建包含3个运行nginx的Pod的Deployment,能够单独访问每个Pod,但无法在Minikube内部通过Service的Cluster IP及暴露的端口访问整个服务。完全按照课程步骤操作,不清楚问题所在,希望有人能帮忙排查。
操作日志
alejandro@alejandro-Latitude-7390:~$ kubectl get service NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE kubernetes ClusterIP 10.96.0.1 <none> 443/TCP 38d alejandro@alejandro-Latitude-7390:~$ kubectl describe service kubernetes Name: kubernetes Namespace: default Labels: component=apiserver provider=kubernetes Annotations: <none> Selector: <none> Type: ClusterIP IP Family Policy: SingleStack IP Families: IPv4 IP: 10.96.0.1 IPs: 10.96.0.1 Port: https 443/TCP TargetPort: 8443/TCP Endpoints: 192.168.59.100:8443 Session Affinity: None Events: <none> alejandro@alejandro-Latitude-7390:~$ kubectl get service NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE kubernetes ClusterIP 10.96.0.1 <none> 443/TCP 38d alejandro@alejandro-Latitude-7390:~$ kubectl expose deployment nginx-deployment --port=80 --target-port=80 service/nginx-deployment exposed alejandro@alejandro-Latitude-7390:~$ kubectl get service NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE kubernetes ClusterIP 10.96.0.1 <none> 443/TCP 38d nginx-deployment ClusterIP 10.98.250.240 <none> 80/TCP 3s alejandro@alejandro-Latitude-7390:~$ kubectl describe service nginx-deployment Name: nginx-deployment Namespace: default Labels: app=nginx-deployment Annotations: <none> Selector: app=nginx-deployment Type: ClusterIP IP Family Policy: SingleStack IP Families: IPv4 IP: 10.98.250.240 IPs: 10.98.250.240 Port: <unset> 80/TCP TargetPort: 80/TCP Endpoints: 172.17.0.3:80,172.17.0.4:80,172.17.0.5:80 Session Affinity: None Events: <none> alejandro@alejandro-Latitude-7390:~$ sudo ssh -o StrictHostKeyChecking=no docker@192.168.59.100 [sudo] password for alejandro: docker@192.168.59.100's password: _ _ _ _ ( ) ( ) ___ ___ (_) ___ (_)| |/' _ _ | |_ __ /' _ ` _ `\| |/' _ `\| || , < ( ) ( )| '_`\ /'__`\ | ( ) ( ) || || ( ) || || |\`\ | (_) || |_) )( ___/ (_) (_) (_)(_)(_) (_)(_)(_) (_)`\___/'(_,__/'`\____) $ curl 10.98.250.240:80 ^C $
排查建议
- 检查网络组件状态:执行
kubectl get pods -n kube-system,确认kube-proxy、集群网络插件(如calico/flannel)的Pod都处于Running状态。kube-proxy负责ClusterIP的流量转发,若它异常会直接导致Service无法访问。 - 验证标签匹配:执行
kubectl get pods --show-labels,确认Pod的app标签值为nginx-deployment,与Service的Selector完全一致。虽然当前Service已关联到Endpoints,但仍需确认标签无拼写错误。 - 测试Pod节点内连通性:在Minikube节点内执行
curl 172.17.0.3:80(替换为任意Pod的IP),再次确认Pod本身能正常响应请求。 - 查看kube-proxy日志:执行
kubectl logs -n kube-system -l k8s-app=kube-proxy,排查是否有iptables/ipvs规则生成失败、转发错误等日志信息。 - 检查iptables规则:在Minikube节点内执行
sudo iptables-save | grep 10.98.250.240,查看是否存在指向Pod IP的DNAT规则。若规则缺失,说明kube-proxy未正确配置转发规则。 - 重启kube-proxy:执行
kubectl rollout restart daemonset kube-proxy -n kube-system,等待组件重启后再次测试Service连通性。 - 切换Service类型测试:执行
kubectl patch service nginx-deployment -p '{"spec":{"type":"NodePort"}}',将Service改为NodePort类型,再通过minikube service nginx-deployment访问。若NodePort能正常访问,问题集中在ClusterIP的转发逻辑;若仍无法访问,需排查Pod或网络插件的底层问题。
内容的提问来源于stack exchange,提问作者Ale2600
相关产品推荐
相关产品推荐

