You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GKE中K8s Pod跨VPC连接GCP VM内部IP的技术问询

Solution: Access VM Internal IP from GKE Pods via Selector-less Service & Endpoints

Since your VPC peering between the GKE cluster's network and the VM's network is already configured, we just need to set up the Kubernetes Service and Endpoints resources correctly to bridge the gap. Here's a step-by-step breakdown:

1. Create a Selector-less Kubernetes Service

First, define a Service without any selector field—this tells Kubernetes we'll manually map it to your VM's internal IP.

Save this as vm-access-service.yaml:

apiVersion: v1
kind: Service
metadata:
  name: vm-internal-service
  namespace: default # Adjust to your target namespace if needed
spec:
  ports:
    - name: vm-service-port # Optional but helps with clarity
      port: 80 # The port your Pods will use to reach the Service
      targetPort: 8080 # The port your VM's service is listening on
  # Omit clusterIP to let Kubernetes assign a stable IP, or use "None" for headless mode

Apply it with:

kubectl apply -f vm-access-service.yaml

2. Create Corresponding Endpoints

Next, link the Service to your VM's internal IP via an Endpoints resource. Critical: the Endpoints name must exactly match the Service name so Kubernetes associates them correctly.

Save this as vm-endpoints.yaml:

apiVersion: v1
kind: Endpoints
metadata:
  name: vm-internal-service # Must match the Service's name
  namespace: default # Same namespace as the Service
subsets:
  - addresses:
      - ip: "10.123.45.67" # Replace with your VM's actual internal IP
    ports:
      - name: vm-service-port # Must match the port name in the Service
        port: 8080 # Must match the targetPort in the Service

Apply it with:

kubectl apply -f vm-endpoints.yaml

3. Verify the Setup

Check that the resources are configured properly:

  • Confirm the Service exists:
    kubectl get service vm-internal-service
    
  • Ensure the VM IP is registered in Endpoints:
    kubectl get endpoints vm-internal-service
    

4. Test Access from a Pod

Spin up a temporary test Pod to validate connectivity:

kubectl run -it --rm test-pod --image=alpine -- sh

Inside the Pod, test accessing the Service (either via its DNS name or cluster IP):

# Using Kubernetes DNS (replace namespace if needed)
wget -qO- http://vm-internal-service.default.svc.cluster.local:80

# Or using the Service's cluster IP (replace with your actual cluster IP)
wget -qO- http://10.96.0.123:80

Key Tips to Avoid Issues

  • VPC Peering & Firewalls: Double-check that your VPC peering is active, and that the VM's firewall rules allow incoming traffic from the GKE cluster's Pod CIDR range on your service port.
  • Consistency Checks: The Endpoints name must match the Service name exactly, and port names/numbers between the two resources must align perfectly.
  • Cluster IP Options: Using clusterIP: None creates a headless Service (no load balancing), while omitting the field gives you a stable, load-balanced IP for Pods to target.

内容的提问来源于stack exchange,提问作者Christophe Bouhier

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 06:35:36