You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为Azure上创建的AKS集群添加外部IP以实现外部访问?

Hey Paul, let's fix that missing External IP issue for your AKS cluster so you can expose your services to the outside world. Here are the go-to methods you can use:

1. Expose Your Service as a LoadBalancer

The most straightforward way to get a public External IP is to change your service type to LoadBalancer—Azure will automatically provision a public IP for it.

  • First, check your current services to confirm their type:

    kubectl get services
    

    You’ll likely see your target service listed with ClusterIP as the type (which only allows internal cluster access).

  • Option 1: Update an existing service
    Edit the service configuration with:

    kubectl edit service <your-service-name>
    

    Find the spec.type field, change its value from ClusterIP to LoadBalancer, then save and exit the editor.

  • Option 2: Deploy a new service with LoadBalancer type
    If you're setting up a new service, include the type in your deployment YAML. For example:

    apiVersion: v1
    kind: Service
    metadata:
      name: my-public-service
    spec:
      type: LoadBalancer
      selector:
        app: my-app
      ports:
        - protocol: TCP
          port: 80
          targetPort: 8080
    

    Apply this YAML with kubectl apply -f <your-file.yaml>.

  • Wait a few minutes, then run kubectl get services again. The External-IP column for your service will show a public IP address once Azure finishes provisioning it.

2. Use an Ingress Controller (Great for Multiple Services)

If you have multiple services to expose and want to share a single public IP, an Ingress Controller is the way to go. The NGINX Ingress Controller is the most common choice for AKS.

  • Step 1: Deploy the NGINX Ingress Controller
    Using Helm (make sure you have Helm installed on your machine):

    helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx
    helm repo update
    helm install nginx-ingress ingress-nginx/ingress-nginx
    
  • Step 2: Get the External IP for the Ingress Controller
    After deployment, check the service created by the ingress controller:

    kubectl get service nginx-ingress-ingress-nginx-controller
    

    The External-IP here is your public entry point for all services routed through the ingress.

  • Step 3: Create an Ingress Resource
    Define routing rules in an Ingress YAML file to map your domain (or raw IP) to your services. Example:

    apiVersion: networking.k8s.io/v1
    kind: Ingress
    metadata:
      name: my-ingress
      annotations:
        nginx.ingress.kubernetes.io/rewrite-target: /
    spec:
      ingressClassName: nginx
      rules:
      - http:
          paths:
          - path: /my-app
            pathType: Prefix
            backend:
              service:
                name: my-app-service
                port:
                  number: 80
    

    Apply this with kubectl apply -f <ingress-file.yaml>. Now you can access your service via http://<ingress-external-ip>/my-app.

Troubleshooting: If External IP is Stuck in "Pending"

If your LoadBalancer’s External IP stays <pending>:

  • Check that your AKS cluster’s managed identity (or service principal) has the Network Contributor role assigned to the resource group where your cluster resides. This permission is required for Azure to create public IPs on behalf of the cluster.
  • You can also use a static public IP (pre-created in Azure) by adding the loadBalancerIP field to your service YAML, pointing to the static IP’s address. This ensures your IP doesn’t change if the service restarts.

内容的提问来源于stack exchange,提问作者Paul

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 08:37:52