You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法通过Kubernetes Service的IP地址访问工作负载问题排查

问题分析与解决

你的LoadBalancer Service无法访问的核心原因是Node.js应用仅绑定了容器的本地回环地址,导致外部请求无法到达服务。

具体问题点

看你提供的app.js代码,服务器监听的主机地址设为127.0.0.1:

const hostname = '127.0.0.1';
server.listen(port, hostname, ...);

这个配置意味着服务只接受来自容器内部本地的请求,而Kubernetes Service是通过容器的集群IP来发起访问的,自然会被拒绝。

修复步骤

  1. 修改app.js,将监听地址改为0.0.0.0,让服务监听容器的所有网络接口:
const http = require('http');

const hostname = '0.0.0.0';
const port = 9000;

const server = http.createServer((req, res) => {
  res.statusCode = 200;
  res.setHeader('Content-Type', 'text/plain');
  res.end('Do not have an inflated sense of yourself. You are just food for worms.');
});

server.listen(port, hostname, () => {
  console.log(`Server running at http://${hostname}:${port}/`);
});
  1. 重新构建Docker镜像并推送至你的镜像仓库(比如更新版本为gcr.io/k8s-networking-test/node-app:v1.1)。

  2. 更新Deployment的镜像版本,触发Pod滚动更新:

kubectl set image deployment/food-for-worms node-app-1=gcr.io/k8s-networking-test/node-app:v1.1
  1. 等待所有Pod更新完成后,再次尝试访问35.193.34.113:80即可正常访问服务。

额外验证(可选)

如果想快速验证配置是否生效,可以进入任意Pod内部,尝试用容器IP访问服务:

kubectl exec -it <pod-name> -- curl http://<container-ip>:9000

修改前这个请求会失败,修改后则会返回预期响应。

内容的提问来源于stack exchange,提问作者Nosail

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 20:20:20