在DigitalOcean Kubernetes中用NodePort暴露Prometheus实现联邦监控降本
Hey there! Let's walk through the common issues and fixes for your NodePort access problem when trying to expose sub-Prometheus instances for federation on DigitalOcean Kubernetes.
First: Correct the Access URL
The <cluster-id>.k8s.ondigitalocean.com domain points to your Kubernetes control plane, not the worker nodes where NodePort services listen. You can't use this domain to access NodePort services. Instead:
- Grab the public IP or public hostname of any worker node in your cluster (find these in the DigitalOcean Control Panel under your cluster's "Nodes" tab, or run
kubectl get nodes -o wideto view external IPs) - Use that IP/hostname plus your NodePort (30800 in your example) to access the service:
http://<node-public-ip>:30800orhttp://<node-public-hostname>:30800
Check DigitalOcean Cloud Firewall Rules
Even if you removed cluster-internal firewalls, DigitalOcean's Cloud Firewall (linked to your Kubernetes cluster) controls external access to node ports. Make sure you have a rule allowing inbound traffic to your NodePort range:
- By default, Kubernetes NodePorts use ports 30000-32767
- Go to your DigitalOcean Cloud Firewall settings, locate the firewall attached to your cluster
- Add an inbound rule:
- Protocol: TCP
- Port Range:
30000-32767(or just30800if you want to restrict to your specific port) - Source: The public IP of your main Prometheus server (use
0.0.0.0/0only for testing, then lock it down for security)
Validate Service and Pod Connectivity
First, confirm your service works internally to rule out pod/service misconfiguration:
- Run a temporary test pod in your cluster:
kubectl run -it --rm --image=curlimages/curl test-curl - Inside the pod, test access to the service's ClusterIP:
If this returns your expected content, your service is correctly targeting the pod. Then test the NodePort using a node's internal IP:curl http://10.245.162.125:80
If this works but external access doesn't, the issue is definitely with external network/firewall settings.curl http://<node-internal-ip>:30800
Adjust External Traffic Policy (Optional but Useful)
Your service currently uses External Traffic Policy: Cluster, which means traffic to any node's NodePort will be forwarded to a pod on any node. Switching to Local routes traffic only to pods running on the node you're accessing—this helps with debugging and reduces latency:
- Edit your service:
kubectl edit service my-nodeport-service - Change
externalTrafficPolicy: ClustertoexternalTrafficPolicy: Local - Save the changes, then ensure you're accessing a node that hosts your pod (check
kubectl get pods -o wideto see which node the pod runs on)
Final Notes for Prometheus Federation
Once you get NodePort access working:
- Restrict the Cloud Firewall rule to only allow your main Prometheus server's IP to access the NodePort (avoid leaving it open to the public)
- For long-term scalability, consider using a headless service with an Ingress Controller (like Nginx Ingress) if you have multiple sub-Prometheus instances—this is more cost-effective than NodePorts for multiple services and gives you better control over routing and TLS.
内容的提问来源于stack exchange,提问作者Luís Serra

