You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

单节点k0s集群中无法通过Service访问selenium/standalone-chrome服务

问题根因

  1. Service Selector与Pod标签不匹配
    你提供的Pod定义中metadata字段没有配置任何Labels,无论初始Service用app: standalone-chrome还是后续修改的name: standalone-chrome作为筛选规则,都无法匹配到后端Pod,这也是你查看Service详情时Endpoints字段为空的直接原因,没有后端端点的Service无法完成请求转发。

  2. Selenium默认仅监听本地回环地址
    selenium/standalone-chrome镜像默认启动时绑定127.0.0.1,仅接收Pod本地发起的请求。kubectl port-forward是通过Kubernetes代理直接访问Pod本地回环地址的服务,所以可以正常访问,但集群内其他Pod通过PodIP/Service访问时,请求从Pod的网卡进入,会被直接拒绝。

修复步骤

步骤1:修正Pod定义

添加匹配Service的Labels,同时新增环境变量指定Selenium监听所有网卡地址:

apiVersion: v1
kind: Pod
metadata:
  name: standalone-chrome
  # 新增Labels,和Service的Selector保持一致
  labels:
    app: standalone-chrome
spec:
  containers:
  - name: standalone-chrome
    image: selenium/standalone-chrome
    ports:
    - containerPort: 4444
    env:
    - name: JAVA_OPTS
      value: '-Dwebdriver.chrome.whitelistedIps=""'
    # 新增环境变量,指定Selenium监听所有网卡
    - name: SE_OPTS
      value: '--host 0.0.0.0'

步骤2:修正Service定义

显式指定targetPort,Selector和Pod的Labels保持一致:

apiVersion: v1
kind: Service
metadata:
  name: standalone-chrome-service
  labels:
    app: standalone-chrome
spec:
  ports:
  - port: 4444
    # 显式指定映射到Pod的4444端口,避免默认映射错误
    targetPort: 4444
    name: standalone-chrome
  type: ClusterIP
  selector:
    app: standalone-chrome

步骤3:验证生效

删除原有旧的Pod和Service,重新应用上述两个配置文件后,执行以下命令确认Service已匹配到后端Pod:

kubectl describe service standalone-chrome-service

正常返回中Endpoints字段会显示为[PodIP]:4444,此时再从busybox容器中执行wget http://standalone-chrome-service:4444即可正常访问。


内容的提问来源于stack exchange,提问作者gnychis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.25 02:15:08