You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求助:在Kubernetes中通过NodePort暴露Nginx至公网IP失败

Troubleshooting Nginx Exposure via NodePort in Kubernetes

Let’s walk through the most common issues that could be preventing your Nginx Pod from being exposed to the public internet—since you’ve already confirmed firewalls and ACLs are fully open for TCP traffic, the problem is likely tied to your Service configuration or how you’re trying to access the app.

1. Ensure Your Service Selector Matches Pod/Deployment Labels

This is the #1 culprit for NodePort Services failing to connect to Pods. The spec.selector in your Service YAML must exactly match the labels applied to your Nginx Pods (or Deployment template).

Example Correct Service YAML

apiVersion: v1
kind: Service
metadata:
  name: nginx-nodeport
spec:
  type: NodePort
  selector:
    app: nginx  # This must match the label on your Nginx Pods!
  ports:
    - port: 80               # Internal Service port (used for cluster-internal traffic)
      targetPort: 80         # Port Nginx is listening on inside the Pod
      nodePort: 30080        # Optional: Must be in 30000-32767 range; omit for auto-assignment

How to Verify:

  • Check your Pod labels: kubectl get pods --show-labels
  • Check your Service’s selector: kubectl describe service nginx-nodeport (look for the Selector field)
  • If they don’t match, update your Service YAML and reapply it with kubectl apply -f service.yaml

2. Use the Correct Access URL: <Public IP>:<NodePort>

NodePort Services expose your app on a high-range port (30000-32767) on every node in your cluster. You cannot access it via <Public IP>:80—you need to use the specific NodePort assigned by Kubernetes.

How to Find the NodePort:

Run kubectl get service nginx-nodeport—you’ll see output like this:

NAME             TYPE       CLUSTER-IP      EXTERNAL-IP   PORT(S)        AGE
nginx-nodeport   NodePort   10.96.123.45    <none>        80:30080/TCP   5m

The NodePort here is 30080, so your access URL should be http://<Your Instance Public IP>:30080

3. Confirm Your Kubernetes Node Has a Public IP

If your cluster node doesn’t have a public IP attached (e.g., it’s a private node behind a NAT gateway), you won’t be able to reach the NodePort directly via your “instance public IP.”

How to Check:

Run kubectl get nodes -o wide and look at the EXTERNAL-IP column. If it shows <none> or a private IP, you’ll need to:

  • Assign a public IP to the node, or
  • Switch to a LoadBalancer type Service (if your cloud provider supports it), or
  • Use an ingress controller to route external traffic to the NodePort

4. Verify the Service Has Endpoints Attached

A Service without endpoints means it can’t find any Pods to route traffic to.

How to Check:

Run kubectl describe service nginx-nodeport and look for the Endpoints section. If it’s empty, go back to step 1—your selector is misaligned. If it shows one or more Pod IPs, the Service is correctly linked to your Pods.

5. Ensure Nginx is Listening on the Correct Port Inside the Pod

Rarely, the issue might be that Nginx isn’t listening on the targetPort you specified in your Service.

How to Verify:

Exec into the Pod and test local access:

kubectl exec -it <your-nginx-pod-name> -- curl localhost:80

If this returns the Nginx default page, the port is correct. If not, check your Nginx configuration inside the Pod or update the targetPort in your Service YAML.


内容的提问来源于stack exchange,提问作者Jeel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:47:28