GKE中K8s Pod跨VPC连接GCP VM内部IP的技术问询
Since your VPC peering between the GKE cluster's network and the VM's network is already configured, we just need to set up the Kubernetes Service and Endpoints resources correctly to bridge the gap. Here's a step-by-step breakdown:
1. Create a Selector-less Kubernetes Service
First, define a Service without any selector field—this tells Kubernetes we'll manually map it to your VM's internal IP.
Save this as vm-access-service.yaml:
apiVersion: v1 kind: Service metadata: name: vm-internal-service namespace: default # Adjust to your target namespace if needed spec: ports: - name: vm-service-port # Optional but helps with clarity port: 80 # The port your Pods will use to reach the Service targetPort: 8080 # The port your VM's service is listening on # Omit clusterIP to let Kubernetes assign a stable IP, or use "None" for headless mode
Apply it with:
kubectl apply -f vm-access-service.yaml
2. Create Corresponding Endpoints
Next, link the Service to your VM's internal IP via an Endpoints resource. Critical: the Endpoints name must exactly match the Service name so Kubernetes associates them correctly.
Save this as vm-endpoints.yaml:
apiVersion: v1 kind: Endpoints metadata: name: vm-internal-service # Must match the Service's name namespace: default # Same namespace as the Service subsets: - addresses: - ip: "10.123.45.67" # Replace with your VM's actual internal IP ports: - name: vm-service-port # Must match the port name in the Service port: 8080 # Must match the targetPort in the Service
Apply it with:
kubectl apply -f vm-endpoints.yaml
3. Verify the Setup
Check that the resources are configured properly:
- Confirm the Service exists:
kubectl get service vm-internal-service - Ensure the VM IP is registered in Endpoints:
kubectl get endpoints vm-internal-service
4. Test Access from a Pod
Spin up a temporary test Pod to validate connectivity:
kubectl run -it --rm test-pod --image=alpine -- sh
Inside the Pod, test accessing the Service (either via its DNS name or cluster IP):
# Using Kubernetes DNS (replace namespace if needed) wget -qO- http://vm-internal-service.default.svc.cluster.local:80 # Or using the Service's cluster IP (replace with your actual cluster IP) wget -qO- http://10.96.0.123:80
Key Tips to Avoid Issues
- VPC Peering & Firewalls: Double-check that your VPC peering is active, and that the VM's firewall rules allow incoming traffic from the GKE cluster's Pod CIDR range on your service port.
- Consistency Checks: The Endpoints name must match the Service name exactly, and port names/numbers between the two resources must align perfectly.
- Cluster IP Options: Using
clusterIP: Nonecreates a headless Service (no load balancing), while omitting the field gives you a stable, load-balanced IP for Pods to target.
内容的提问来源于stack exchange,提问作者Christophe Bouhier

