如何为Azure上创建的AKS集群添加外部IP以实现外部访问?
Hey Paul, let's fix that missing External IP issue for your AKS cluster so you can expose your services to the outside world. Here are the go-to methods you can use:
The most straightforward way to get a public External IP is to change your service type to LoadBalancer—Azure will automatically provision a public IP for it.
First, check your current services to confirm their type:
kubectl get servicesYou’ll likely see your target service listed with
ClusterIPas the type (which only allows internal cluster access).Option 1: Update an existing service
Edit the service configuration with:kubectl edit service <your-service-name>Find the
spec.typefield, change its value fromClusterIPtoLoadBalancer, then save and exit the editor.Option 2: Deploy a new service with LoadBalancer type
If you're setting up a new service, include the type in your deployment YAML. For example:apiVersion: v1 kind: Service metadata: name: my-public-service spec: type: LoadBalancer selector: app: my-app ports: - protocol: TCP port: 80 targetPort: 8080Apply this YAML with
kubectl apply -f <your-file.yaml>.Wait a few minutes, then run
kubectl get servicesagain. TheExternal-IPcolumn for your service will show a public IP address once Azure finishes provisioning it.
If you have multiple services to expose and want to share a single public IP, an Ingress Controller is the way to go. The NGINX Ingress Controller is the most common choice for AKS.
Step 1: Deploy the NGINX Ingress Controller
Using Helm (make sure you have Helm installed on your machine):helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx helm repo update helm install nginx-ingress ingress-nginx/ingress-nginxStep 2: Get the External IP for the Ingress Controller
After deployment, check the service created by the ingress controller:kubectl get service nginx-ingress-ingress-nginx-controllerThe
External-IPhere is your public entry point for all services routed through the ingress.Step 3: Create an Ingress Resource
Define routing rules in an Ingress YAML file to map your domain (or raw IP) to your services. Example:apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: my-ingress annotations: nginx.ingress.kubernetes.io/rewrite-target: / spec: ingressClassName: nginx rules: - http: paths: - path: /my-app pathType: Prefix backend: service: name: my-app-service port: number: 80Apply this with
kubectl apply -f <ingress-file.yaml>. Now you can access your service viahttp://<ingress-external-ip>/my-app.
If your LoadBalancer’s External IP stays <pending>:
- Check that your AKS cluster’s managed identity (or service principal) has the
Network Contributorrole assigned to the resource group where your cluster resides. This permission is required for Azure to create public IPs on behalf of the cluster. - You can also use a static public IP (pre-created in Azure) by adding the
loadBalancerIPfield to your service YAML, pointing to the static IP’s address. This ensures your IP doesn’t change if the service restarts.
内容的提问来源于stack exchange,提问作者Paul

