求助:在Kubernetes中通过NodePort暴露Nginx至公网IP失败
Let’s walk through the most common issues that could be preventing your Nginx Pod from being exposed to the public internet—since you’ve already confirmed firewalls and ACLs are fully open for TCP traffic, the problem is likely tied to your Service configuration or how you’re trying to access the app.
1. Ensure Your Service Selector Matches Pod/Deployment Labels
This is the #1 culprit for NodePort Services failing to connect to Pods. The spec.selector in your Service YAML must exactly match the labels applied to your Nginx Pods (or Deployment template).
Example Correct Service YAML
apiVersion: v1 kind: Service metadata: name: nginx-nodeport spec: type: NodePort selector: app: nginx # This must match the label on your Nginx Pods! ports: - port: 80 # Internal Service port (used for cluster-internal traffic) targetPort: 80 # Port Nginx is listening on inside the Pod nodePort: 30080 # Optional: Must be in 30000-32767 range; omit for auto-assignment
How to Verify:
- Check your Pod labels:
kubectl get pods --show-labels - Check your Service’s selector:
kubectl describe service nginx-nodeport(look for theSelectorfield) - If they don’t match, update your Service YAML and reapply it with
kubectl apply -f service.yaml
2. Use the Correct Access URL: <Public IP>:<NodePort>
NodePort Services expose your app on a high-range port (30000-32767) on every node in your cluster. You cannot access it via <Public IP>:80—you need to use the specific NodePort assigned by Kubernetes.
How to Find the NodePort:
Run kubectl get service nginx-nodeport—you’ll see output like this:
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE nginx-nodeport NodePort 10.96.123.45 <none> 80:30080/TCP 5m
The NodePort here is 30080, so your access URL should be http://<Your Instance Public IP>:30080
3. Confirm Your Kubernetes Node Has a Public IP
If your cluster node doesn’t have a public IP attached (e.g., it’s a private node behind a NAT gateway), you won’t be able to reach the NodePort directly via your “instance public IP.”
How to Check:
Run kubectl get nodes -o wide and look at the EXTERNAL-IP column. If it shows <none> or a private IP, you’ll need to:
- Assign a public IP to the node, or
- Switch to a
LoadBalancertype Service (if your cloud provider supports it), or - Use an ingress controller to route external traffic to the NodePort
4. Verify the Service Has Endpoints Attached
A Service without endpoints means it can’t find any Pods to route traffic to.
How to Check:
Run kubectl describe service nginx-nodeport and look for the Endpoints section. If it’s empty, go back to step 1—your selector is misaligned. If it shows one or more Pod IPs, the Service is correctly linked to your Pods.
5. Ensure Nginx is Listening on the Correct Port Inside the Pod
Rarely, the issue might be that Nginx isn’t listening on the targetPort you specified in your Service.
How to Verify:
Exec into the Pod and test local access:
kubectl exec -it <your-nginx-pod-name> -- curl localhost:80
If this returns the Nginx default page, the port is correct. If not, check your Nginx configuration inside the Pod or update the targetPort in your Service YAML.
内容的提问来源于stack exchange,提问作者Jeel

