You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在DigitalOcean Kubernetes中用NodePort暴露Prometheus实现联邦监控降本

Fixing NodePort Access Issue for Prometheus Federation on DigitalOcean Kubernetes

Hey there! Let's walk through the common issues and fixes for your NodePort access problem when trying to expose sub-Prometheus instances for federation on DigitalOcean Kubernetes.

First: Correct the Access URL

The <cluster-id>.k8s.ondigitalocean.com domain points to your Kubernetes control plane, not the worker nodes where NodePort services listen. You can't use this domain to access NodePort services. Instead:

  • Grab the public IP or public hostname of any worker node in your cluster (find these in the DigitalOcean Control Panel under your cluster's "Nodes" tab, or run kubectl get nodes -o wide to view external IPs)
  • Use that IP/hostname plus your NodePort (30800 in your example) to access the service: http://<node-public-ip>:30800 or http://<node-public-hostname>:30800

Check DigitalOcean Cloud Firewall Rules

Even if you removed cluster-internal firewalls, DigitalOcean's Cloud Firewall (linked to your Kubernetes cluster) controls external access to node ports. Make sure you have a rule allowing inbound traffic to your NodePort range:

  • By default, Kubernetes NodePorts use ports 30000-32767
  • Go to your DigitalOcean Cloud Firewall settings, locate the firewall attached to your cluster
  • Add an inbound rule:
    • Protocol: TCP
    • Port Range: 30000-32767 (or just 30800 if you want to restrict to your specific port)
    • Source: The public IP of your main Prometheus server (use 0.0.0.0/0 only for testing, then lock it down for security)

Validate Service and Pod Connectivity

First, confirm your service works internally to rule out pod/service misconfiguration:

  1. Run a temporary test pod in your cluster:
    kubectl run -it --rm --image=curlimages/curl test-curl
    
  2. Inside the pod, test access to the service's ClusterIP:
    curl http://10.245.162.125:80
    
    If this returns your expected content, your service is correctly targeting the pod. Then test the NodePort using a node's internal IP:
    curl http://<node-internal-ip>:30800
    
    If this works but external access doesn't, the issue is definitely with external network/firewall settings.

Adjust External Traffic Policy (Optional but Useful)

Your service currently uses External Traffic Policy: Cluster, which means traffic to any node's NodePort will be forwarded to a pod on any node. Switching to Local routes traffic only to pods running on the node you're accessing—this helps with debugging and reduces latency:

  • Edit your service:
    kubectl edit service my-nodeport-service
    
  • Change externalTrafficPolicy: Cluster to externalTrafficPolicy: Local
  • Save the changes, then ensure you're accessing a node that hosts your pod (check kubectl get pods -o wide to see which node the pod runs on)

Final Notes for Prometheus Federation

Once you get NodePort access working:

  • Restrict the Cloud Firewall rule to only allow your main Prometheus server's IP to access the NodePort (avoid leaving it open to the public)
  • For long-term scalability, consider using a headless service with an Ingress Controller (like Nginx Ingress) if you have multiple sub-Prometheus instances—this is more cost-effective than NodePorts for multiple services and gives you better control over routing and TLS.

内容的提问来源于stack exchange,提问作者Luís Serra

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:22:32