You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes readinessProbe调用TLS加密端点遇连接拒绝问题求助

Kubernetes ReadinessProbe 配置问题解决思路
  • 确认应用监听地址与端口
    Spring Boot应用默认监听0.0.0.0,如果配置为仅监听特定IP(如127.0.0.1)或非8083端口,会导致localhost连接失败。可在Pod内执行netstat -tulpn查看应用实际监听的地址和端口,确保与探针配置一致。

  • 优化curl探针命令排查细节
    在探针命令中添加调试参数,将日志输出到文件便于分析:

    readinessProbe:
      exec:
        command:
          - sh
          - -c
          - curl -v -k --cert /mnt/secret/cert.pem --key /mnt/secret/key.pem "https://localhost:8083/actuator/health/readiness" 2>/tmp/probe-debug.log | grep -q "UP"
      initialDelaySeconds: 50
      periodSeconds: 5
      failureThreshold: 30
    

    手动进入Pod后查看/tmp/probe-debug.log,可获取连接失败的具体原因,比如证书读取权限、网络策略限制等。

  • 改用httpGet探针并配置TLS参数
    无需依赖exec探针,直接通过httpGet探针的tls字段解决证书验证问题:

    • 测试环境可跳过证书验证:
      readinessProbe:
        httpGet:
          path: /actuator/health/readiness
          port: 8083
          scheme: HTTPS
          tls:
            insecureSkipVerify: true
        initialDelaySeconds: 50
        periodSeconds: 5
        failureThreshold: 30
      
    • 生产环境推荐配置CA证书:
      将CA证书挂载到Pod内后,在探针中指定证书路径:
      readinessProbe:
        httpGet:
          path: /actuator/health/readiness
          port: 8083
          scheme: HTTPS
          tls:
            caCertificates: /mnt/secret/ca.pem
        initialDelaySeconds: 50
        periodSeconds: 5
        failureThreshold: 30
      
  • 检查证书挂载权限
    确认Pod内运行探针的用户(通常与应用容器用户一致)拥有读取/mnt/secret下证书文件的权限。可执行ls -l /mnt/secret查看文件权限,若为600需确保用户属于对应组,或调整secret的挂载权限。

  • 延长初始延迟时间
    若应用启动较慢(如包含大量初始化任务、数据库连接等),50秒的初始延迟可能不足以让readiness端点就绪。可逐步调高initialDelaySeconds(如120秒),同时查看应用日志确认端点变为UP的时间。

内容的提问来源于stack exchange,提问作者Josh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 12:31:23