You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将K8s Pod暴露至公网?Nginx Pod公网访问问题求助

How to Expose Your Nginx Pod to the Public Internet Without LoadBalancer/Ingress

Hey there! Let's work through getting your Nginx Pod accessible via your server's public IP. The issue right now is that your Pod only exists within the Kubernetes cluster network, and kubectl port-forward only creates a temporary local tunnel—so external traffic can't reach it. Since your cloud provider doesn't support LoadBalancer or Ingress, NodePort Service is your best bet. Here's a step-by-step fix:

1. Update Your Nginx Pod to Include a Label

First, Kubernetes Services use labels to match and route traffic to Pods. Your current Pod doesn't have any labels, so let's add one. Modify your pod-nginx.yml like this:

apiVersion: v1
kind: Pod
metadata:
  name: nginx
  labels:
    app: nginx  # Add this label to let the Service find the Pod
spec:
  containers:
  - name: nginx
    image: nginx:1.7.9
    ports:
    - containerPort: 80

Apply the updated Pod:

kubectl delete pod nginx  # Remove the old unlabeled Pod
kubectl apply -f pod-nginx.yml

2. Create a NodePort Service

Create a new file (e.g., nginx-nodeport.yml) with this Service configuration. A NodePort Service exposes your Pod on a static port across all cluster nodes:

apiVersion: v1
kind: Service
metadata:
  name: nginx-nodeport
spec:
  type: NodePort
  selector:
    app: nginx  # Matches the label we added to the Pod
  ports:
    - protocol: TCP
      port: 80          # Internal cluster port (other Pods use this to access the Service)
      targetPort: 80    # Matches the Pod's containerPort
      nodePort: 30080   # Optional: Pick a port between 30000-32767 (K8s default range)

Apply the Service:

kubectl apply -f nginx-nodeport.yml

Verify the Service is running:

kubectl get svc nginx-nodeport

You should see output like this (note the NODEPORT column):

NAME               TYPE       CLUSTER-IP      EXTERNAL-IP   PORT(S)        AGE
nginx-nodeport     NodePort   10.96.XXX.XXX   <none>        80:30080/TCP   1m

3. Open the NodePort in Your Firewall/Security Group

This is the most common missing step! You need to allow inbound traffic to the NodePort (e.g., 30080) on your server's firewall and cloud security group:

  • For ufw (Ubuntu/Debian):
    sudo ufw allow 30080/tcp
    
  • For firewalld (RHEL/CentOS):
    sudo firewall-cmd --add-port=30080/tcp --permanent
    sudo firewall-cmd --reload
    
  • Don't forget to update your cloud provider's security group rules to allow TCP traffic on port 30080 from 0.0.0.0/0 (or your specific IP if you want to restrict access).

4. Access Nginx via Your Server's Public IP

Now you can visit http://<serverIP>:30080 in your browser—you should see the default Nginx welcome page!

Why Your Previous NodePort Attempt Might Have Failed

  • Missing Pod Labels: If your Service's selector didn't match any Pod labels, it would show no endpoints (check with kubectl describe svc nginx-nodeport).
  • Invalid Port Range: NodePorts must be between 30000-32767 (Kubernetes default)—using a port outside this range will cause the Service to stay Pending.
  • Firewall/Security Block: Even if the Service is set up correctly, external traffic can't reach the port if it's blocked by your server's firewall or cloud security group.

Do You Need to Modify iptables Manually?

Probably not! Kubernetes' kube-proxy automatically manages iptables rules to route traffic from the NodePort to your Pod. You can check if kube-proxy is running with:

kubectl get pods -n kube-system | grep kube-proxy

If it's healthy, iptables should be configured correctly.

内容的提问来源于stack exchange,提问作者ex080

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 03:44:15