Kubernetes集群Pod间使用Axios通信报隧道套接字建立失败问题
问题根因
- 你当前使用的
tunnel.httpsOverHttps是用于需要通过HTTPS代理发送请求的场景,Kubernetes集群内部Pod直接通信不需要走代理,该配置默认会尝试连接本地443端口的代理服务,因此触发ECONNREFUSED 127.0.0.1:443报错 - 原request配置中设置了
strictSSL: false关闭了证书有效性校验,Axios默认开启证书校验,因此你注释httpsAgent配置后会触发证书过期报错 - 你的Axios配置还存在语法错误:对象内的
httpsAgent属性应该用冒号赋值,不是等号
修复方案
直接使用Node.js内置的https.Agent替代tunnel包的agent即可,无需引入tunnel依赖,配置参考如下:
const https = require('https'); // 其余业务代码保持不变 axios({ url: 'https://other-service:8000/api/endpoint', method: 'post', responseType: 'json', headers: { 'username': '<username>' }, auth: { 'username': '<username>', 'password': '<password>', }, data: data, // 替换为内置https.Agent httpsAgent: new https.Agent({ key: privateKey, cert: certificate, // 对应原request的strictSSL: false,关闭证书有效性校验 rejectUnauthorized: false }) });
可选优化建议
- 生产环境建议替换为有效期内的可信证书,开启
rejectUnauthorized: true保证通信安全 - 集群内部服务互访如果没有强制HTTPS要求,可直接使用HTTP通信,无需额外配置证书逻辑
内容的提问来源于stack exchange,提问作者piccy
相关产品推荐
相关产品推荐

