无法通过Kubernetes Service的IP地址访问工作负载问题排查
问题分析与解决
你的LoadBalancer Service无法访问的核心原因是Node.js应用仅绑定了容器的本地回环地址,导致外部请求无法到达服务。
具体问题点
看你提供的app.js代码,服务器监听的主机地址设为127.0.0.1:
const hostname = '127.0.0.1'; server.listen(port, hostname, ...);
这个配置意味着服务只接受来自容器内部本地的请求,而Kubernetes Service是通过容器的集群IP来发起访问的,自然会被拒绝。
修复步骤
- 修改
app.js,将监听地址改为0.0.0.0,让服务监听容器的所有网络接口:
const http = require('http'); const hostname = '0.0.0.0'; const port = 9000; const server = http.createServer((req, res) => { res.statusCode = 200; res.setHeader('Content-Type', 'text/plain'); res.end('Do not have an inflated sense of yourself. You are just food for worms.'); }); server.listen(port, hostname, () => { console.log(`Server running at http://${hostname}:${port}/`); });
重新构建Docker镜像并推送至你的镜像仓库(比如更新版本为
gcr.io/k8s-networking-test/node-app:v1.1)。更新Deployment的镜像版本,触发Pod滚动更新:
kubectl set image deployment/food-for-worms node-app-1=gcr.io/k8s-networking-test/node-app:v1.1
- 等待所有Pod更新完成后,再次尝试访问
35.193.34.113:80即可正常访问服务。
额外验证(可选)
如果想快速验证配置是否生效,可以进入任意Pod内部,尝试用容器IP访问服务:
kubectl exec -it <pod-name> -- curl http://<container-ip>:9000
修改前这个请求会失败,修改后则会返回预期响应。
内容的提问来源于stack exchange,提问作者Nosail
相关产品推荐
相关产品推荐

