Kubernetes中无法通过Service名称连接MongoDB问题求助
Kubernetes中MongoDB Service名称连接超时问题排查
问题描述
在Kubernetes部署MongoDB实例,已创建对应的Pod和Service,但通过Service名称auth-mongo-srv连接MongoDB时出现连接超时错误,使用Service的Cluster IP(10.105.37.75)则可以正常连接。
Service信息
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE auth-mongo-srv ClusterIP 10.105.37.75 <none> 27017/TCP 19s
MongoDB连接代码
try { await mongoose.connect('mongodb://auth-mongo-srv:27017/auth'); console.log("Connected with MongoDB !!!"); } catch (err) { console.log(err); }
控制台错误信息
[INFO] 17:23:25 ts-node-dev ver. 2.0.0 (using ts-node ver. 10.9.1, typescript ver. 4.8.4) [auth-service] MongooseServerSelectionError: connection timed out [auth-service] at NativeConnection.Connection.openUri (/app/node_modules/mongoose/lib/connection.js:824:32) [auth-service] at /app/node_modules/mongoose/lib/index.js:381:10 [auth-service] at /app/node_modules/mongoose/lib/helpers/promiseOrCallback.js:41:5 [auth-service] at new Promise (<anonymous>) [auth-service] at promiseOrCallback (/app/node_modules/mongoose/lib/helpers/promiseOrCallback.js:40:10) [auth-service] at Mongoose._promiseOrCallback (/app/node_modules/mongoose/lib/index.js:1234:10) [auth-service] at Mongoose.connect (/app/node_modules/mongoose/lib/index.js:380:20) [auth-service] at /app/src/index.ts:13:24 [auth-service] at Generator.next (<anonymous>) [auth-service] at /app/src/index.ts:8:71 { [auth-service] reason: TopologyDescription { [auth-service] type: 'Unknown', [auth-service] servers: Map(1) { 'auth-mongo-srv:27017' => [ServerDescription] }, [auth-service] stale: false, [auth-service] compatible: true, [auth-service] heartbeatFrequencyMS: 10000, [auth-service] localThresholdMS: 15, [auth-service] setName: null, [auth-service] maxElectionId: null, [auth-service] maxSetVersion: null, [auth-service] commonWireVersion: 0, [auth-service] logicalSessionTimeoutMinutes: null [auth-service] }, [auth-service] code: undefined [auth-service] }
排查与解决步骤
1. 验证DNS解析
- 在发起连接的客户端Pod内执行DNS查询,确认Service名称能解析到正确的Cluster IP:
kubectl exec -it <client-pod-name> -- nslookup auth-mongo-srv - 如果解析失败,检查CoreDNS组件状态:
kubectl get pods -n kube-system | grep coredns kubectl logs <coredns-pod-name> -n kube-system - 若客户端与MongoDB Service不在同一命名空间,需使用完整域名格式:
auth-mongo-srv.<mongo-namespace>.svc.cluster.local
2. 检查Service与Pod的关联
- 查看Service的selector配置,确认与MongoDB Pod的labels匹配:
kubectl describe service auth-mongo-srv kubectl describe pod <mongo-pod-name> - 检查Service的Endpoints,确认有活跃的Pod IP:
如果Endpoints为空,说明selector不匹配,需调整Service的selector或Pod的labels。kubectl get endpoints auth-mongo-srv
3. 检查网络策略限制
- 确认当前命名空间没有网络策略阻止客户端访问MongoDB的27017端口:
若存在网络策略,需添加规则允许客户端所在命名空间访问MongoDB Service。kubectl get networkpolicy
4. 优化连接配置
- 使用完整的Service域名进行连接:
await mongoose.connect('mongodb://auth-mongo-srv.<namespace>.svc.cluster.local:27017/auth'); - 增加连接超时与重试参数:
await mongoose.connect('mongodb://auth-mongo-srv:27017/auth', { connectTimeoutMS: 30000, retryWrites: true, w: 'majority' });
内容的提问来源于stack exchange,提问作者Nahid Hasan
相关产品推荐
相关产品推荐

