如何将K8s Pod暴露至公网?Nginx Pod公网访问问题求助
Hey there! Let's work through getting your Nginx Pod accessible via your server's public IP. The issue right now is that your Pod only exists within the Kubernetes cluster network, and kubectl port-forward only creates a temporary local tunnel—so external traffic can't reach it. Since your cloud provider doesn't support LoadBalancer or Ingress, NodePort Service is your best bet. Here's a step-by-step fix:
1. Update Your Nginx Pod to Include a Label
First, Kubernetes Services use labels to match and route traffic to Pods. Your current Pod doesn't have any labels, so let's add one. Modify your pod-nginx.yml like this:
apiVersion: v1 kind: Pod metadata: name: nginx labels: app: nginx # Add this label to let the Service find the Pod spec: containers: - name: nginx image: nginx:1.7.9 ports: - containerPort: 80
Apply the updated Pod:
kubectl delete pod nginx # Remove the old unlabeled Pod kubectl apply -f pod-nginx.yml
2. Create a NodePort Service
Create a new file (e.g., nginx-nodeport.yml) with this Service configuration. A NodePort Service exposes your Pod on a static port across all cluster nodes:
apiVersion: v1 kind: Service metadata: name: nginx-nodeport spec: type: NodePort selector: app: nginx # Matches the label we added to the Pod ports: - protocol: TCP port: 80 # Internal cluster port (other Pods use this to access the Service) targetPort: 80 # Matches the Pod's containerPort nodePort: 30080 # Optional: Pick a port between 30000-32767 (K8s default range)
Apply the Service:
kubectl apply -f nginx-nodeport.yml
Verify the Service is running:
kubectl get svc nginx-nodeport
You should see output like this (note the NODEPORT column):
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE nginx-nodeport NodePort 10.96.XXX.XXX <none> 80:30080/TCP 1m
3. Open the NodePort in Your Firewall/Security Group
This is the most common missing step! You need to allow inbound traffic to the NodePort (e.g., 30080) on your server's firewall and cloud security group:
- For
ufw(Ubuntu/Debian):sudo ufw allow 30080/tcp - For
firewalld(RHEL/CentOS):sudo firewall-cmd --add-port=30080/tcp --permanent sudo firewall-cmd --reload - Don't forget to update your cloud provider's security group rules to allow TCP traffic on port 30080 from 0.0.0.0/0 (or your specific IP if you want to restrict access).
4. Access Nginx via Your Server's Public IP
Now you can visit http://<serverIP>:30080 in your browser—you should see the default Nginx welcome page!
Why Your Previous NodePort Attempt Might Have Failed
- Missing Pod Labels: If your Service's
selectordidn't match any Pod labels, it would show no endpoints (check withkubectl describe svc nginx-nodeport). - Invalid Port Range: NodePorts must be between 30000-32767 (Kubernetes default)—using a port outside this range will cause the Service to stay Pending.
- Firewall/Security Block: Even if the Service is set up correctly, external traffic can't reach the port if it's blocked by your server's firewall or cloud security group.
Do You Need to Modify iptables Manually?
Probably not! Kubernetes' kube-proxy automatically manages iptables rules to route traffic from the NodePort to your Pod. You can check if kube-proxy is running with:
kubectl get pods -n kube-system | grep kube-proxy
If it's healthy, iptables should be configured correctly.
内容的提问来源于stack exchange,提问作者ex080

