You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CentOS7 K8s集群外部无法访问NGINX Ingress Controller排查求助

系统环境

Operating System: CentOS Linux 7 (Core)
CPE OS Name: cpe:/o:centos:centos:7
Kernel: Linux 3.10.0-1160.45.1.el7.x86_64

我使用外部负载均衡组件HAProxy与Keepalived,虚拟IP为172.24.16.6。此前创建NodePort类型服务时可从外部正常访问Pod,已确认负载均衡IP到集群的链路可用。

我参照官方文档通过清单文件安装了NGINX Ingress Controller,随后执行$ kubectl apply -f service/loadbalancer.yaml应用了如下Service配置:

apiVersion: v1
kind: Service
metadata:
  name: nginx-ingress
  namespace: nginx-ingress
spec:
  externalTrafficPolicy: Local
  type: LoadBalancer
  externalIPs:
  - 172.24.16.6
  ports:
  - port: 80
    targetPort: 80
    protocol: TCP
    name: http
  - port: 443
    targetPort: 443
    protocol: TCP
    name: https
  selector:
    app: nginx-ingress

部署完成后查看集群资源状态如下:

]$ kubectl get all -o wide -n nginx-ingress
NAME                                 READY   STATUS    RESTARTS   AGE   IP                NODE                          NOMINATED NODE   READINESS GATES
pod/nginx-ingress-768698d9df-c2wlx   1/1     Running   0          27m   192.168.105.197   srv-dev-k8s-worker-05   <none>           <none>

NAME                    TYPE           CLUSTER-IP       EXTERNAL-IP   PORT(S)                      AGE   SELECTOR
service/nginx-ingress   LoadBalancer   10.104.239.149   172.24.16.6   80:30053/TCP,443:30021/TCP   22m   app=nginx-ingress

NAME                            READY   UP-TO-DATE   AVAILABLE   AGE   CONTAINERS      IMAGES                      SELECTOR
deployment.apps/nginx-ingress   1/1     1            1           28m   nginx-ingress   nginx/nginx-ingress:2.0.2   app=nginx-ingress

NAME                                       DESIRED   CURRENT   READY   AGE   CONTAINERS      IMAGES                      SELECTOR
replicaset.apps/nginx-ingress-6454cfbc49   0         0         0       28m   nginx-ingress   nginx/nginx-ingress:2.0.2   app=nginx-ingress,pod-template-hash=6454cfbc49
replicaset.apps/nginx-ingress-768698d9df   1         1         1       27m   nginx-ingress   nginx/nginx-ingress:2.0.2   app=nginx-ingress,pod-template-hash=768698d9df

单独查询nginx-ingress Pod状态:

$ kubectl -n nginx-ingress get pod -o wide
NAME                             READY   STATUS    RESTARTS   AGE   IP                NODE                          NOMINATED NODE   READINESS GATES
nginx-ingress-768698d9df-c2wlx   1/1     Running   0          72m   192.168.105.197   srv-dev-k8s-worker-05   <none>           <none>

执行netstat命令可见80、443端口已正常监听并绑定172.24.16.6:

$ netstat -tulpn
(No info could be read for "-p": geteuid()=1002 but you should be root.)
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name
tcp        0      0 172.24.16.6:80          0.0.0.0:*               LISTEN      -
tcp        0      0 127.0.0.1:10257         0.0.0.0:*               LISTEN      -
tcp        0      0 0.0.0.0:179             0.0.0.0:*               LISTEN      -
tcp        0      0 127.0.0.1:10259         0.0.0.0:*               LISTEN      -
tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN      -
tcp        0      0 172.24.16.6:443         0.0.0.0:*               LISTEN      -
tcp        0      0 127.0.0.1:43707         0.0.0.0:*               LISTEN      -
tcp        0      0 0.0.0.0:32000           0.0.0.0:*               LISTEN      -
tcp        0      0 0.0.0.0:30021           0.0.0.0:*               LISTEN      -
tcp        0      0 0.0.0.0:30053           0.0.0.0:*               LISTEN      -
tcp        0      0 127.0.0.1:10248         0.0.0.0:*               LISTEN      -
tcp        0      0 127.0.0.1:10249         0.0.0.0:*               LISTEN      -
tcp        0      0 127.0.0.1:9098          0.0.0.0:*               LISTEN      -
tcp        0      0 127.0.0.1:9099          0.0.0.0:*               LISTEN      -
tcp        0      0 172.24.25.141:2379      0.0.0.0:*               LISTEN      -
tcp        0      0 127.0.0.1:2379          0.0.0.0:*               LISTEN      -
tcp        0      0 127.0.0.1:6444          0.0.0.0:*               LISTEN      -
tcp        0      0 0.0.0.0:6444            0.0.0.0:*               LISTEN      -
tcp        0      0 172.24.25.141:2380      0.0.0.0:*               LISTEN      -
tcp6       0      0 :::10256                :::*                    LISTEN      -
tcp6       0      0 :::22                   :::*                    LISTEN      -
tcp6       0      0 :::31231                :::*                    LISTEN      -
tcp6       0      0 :::5473                 :::*                    LISTEN      -
tcp6       0      0 :::10250                :::*                    LISTEN      -
tcp6       0      0 :::6443                 :::*                    LISTEN      -
udp        0      0 127.0.0.1:323           0.0.0.0:*                           -
udp        0      0 0.0.0.0:4789            0.0.0.0:*                           -
udp        0      0 0.0.0.0:58191           0.0.0.0:*                           -
udp        0      0 0.0.0.0:68              0.0.0.0:*                           -
udp6       0      0 ::1:323                 :::*                                -

但检查iptables规则时发现未开放对应端口,目前无法从外部访问Ingress Controller,请求协助排查解决该问题。


内容的提问来源于stack exchange,提问作者Maksim

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.29 04:36:04