AKS部署Prometheus后CloudShell端口转发无法访问localhost:9090怎么办
问题根因
你在Azure CloudShell中执行的port-forward默认绑定的是CloudShell后台实例的本地环回地址,和你本地设备的网络完全隔离,因此直接访问本地127.0.0.1:9090无法连通。
可行解决方案
方案1:使用CloudShell内置预览功能
这是成本最低的临时调试方案,不需要修改集群资源:
- 调整port-forward命令,指定监听所有网络接口:
kubectl --namespace monitoring port-forward prometheus-server 9090:9090 --address 0.0.0.0
- 命令保持运行状态,点击CloudShell顶部工具栏的「预览」按钮,在端口输入框填写9090后确认,即可直接在新标签页打开Prometheus界面。
私有AKS集群需提前将CloudShell加入集群所在虚拟网络,否则无法连通。
方案2:临时将Prometheus Service改为LoadBalancer类型
适合需要多人同时访问调试的场景:
- 执行命令修改Service类型:
kubectl patch service prometheus-server -n monitoring -p '{"spec":{"type":"LoadBalancer"}}'
- 等待3分钟左右,执行命令获取分配的公网IP:
kubectl get service prometheus-server -n monitoring --output jsonpath='{.status.loadBalancer.ingress[0].ip}'
- 在本地浏览器访问
http://<获取到的公网IP>:9090即可访问。
调试完成后建议改回ClusterIP避免公网暴露风险:
kubectl patch service prometheus-server -n monitoring -p '{"spec":{"type":"ClusterIP"}}'
方案3:本地终端执行port-forward
适合长期调试使用:
- 本地设备安装Azure CLI和kubectl后,执行
az aks get-credentials --resource-group <你的AKS资源组名> --name <你的AKS集群名>获取集群访问凭证 - 在本地终端执行原port-forward命令:
kubectl --namespace monitoring port-forward prometheus-server 9090
- 直接访问本地
http://127.0.0.1:9090即可。
内容的提问来源于stack exchange,提问作者Makina74
相关产品推荐
相关产品推荐

