GKE部署API后curl与Python客户端均出现连接拒绝错误求助
Troubleshooting "Connection Refused" for GKE-Deployed API
Hey there, let's walk through why you're hitting that connection refused error when trying to call your GKE-hosted API. This is a pretty common scenario, and we can narrow down the issue step by step:
First, Verify Core GKE Resources
- Check Pod Health: Start by confirming your API pods are actually running. Run
kubectl get pods—look for theRunningstatus. If you seeCrashLoopBackOfforError, grab the pod logs withkubectl logs <your-pod-name>to spot startup issues (like wrong port config, missing dependencies, or application crashes). - Validate Service Configuration:
- Make sure your Service's
targetPortmatches the port your API is listening on inside the container. You can check this withkubectl describe service <your-service-name>. - Look at the
Endpointssection in that output—if it's empty, your Service isn't matching any pods. Double-check the Service's label selector against your pod's labels (runkubectl describe pod <your-pod-name>to confirm labels).
- Make sure your Service's
- Check LoadBalancer Status: If you're using a LoadBalancer Service, run
kubectl get serviceto confirm theEXTERNAL-IPis assigned (not<none>orpending). A pending IP could mean you've hit GCP's external IP quota, or there's a VPC network misconfiguration.
Test Connectivity From Inside the Cluster
Before blaming external network issues, test if your API is reachable within the cluster:
- Spin up a temporary test pod to curl your Service:
kubectl run -it --rm --image=curlimages/curl curl-test -- curl http://<service-cluster-ip>:<port>/predict/ - If this works, the problem is with external access (firewalls, LoadBalancer setup). If it fails, focus on fixing the pod/service internal connectivity first.
Check External Network & Firewall Rules
- GCP Firewall Rules: GKE usually auto-creates a firewall rule for LoadBalancer Services, but it might have been modified or deleted. Head to the GCP Console → VPC Network → Firewall Rules, and verify there's a rule allowing incoming traffic from
0.0.0.0/0on port 80 (or your API's port). - API Listen Address: Critical check—ensure your API is listening on
0.0.0.0(all interfaces) instead of127.0.0.1(localhost only). If it's only bound to localhost, the container (and Service) can't reach it, even internally. - NodePort Specific Checks: If using NodePort, confirm the node's firewall allows external traffic on the assigned NodePort. Also, make sure you're using the node's external IP plus the NodePort to access the API.
Additional Checks
- Ingress Configuration: If you're using an Ingress controller, verify the Ingress resource points to the correct Service, and that the Ingress controller pods are running. Check the Ingress logs for routing errors.
- GCP Quotas: Double-check your GCP account's external IP address quota—if you've used all available addresses, LoadBalancers won't get an external IP. You can check this in the GCP Console → IAM & Admin → Quotas.
Once you work through these steps, you should be able to pinpoint whether the issue is with your application's setup, Service configuration, or external network access.
内容的提问来源于stack exchange,提问作者Naeem Khan
相关产品推荐
相关产品推荐

