You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes NodePort服务Pod无法接收外部连接问题求助

Hey there, let's break down this Kubernetes issue together—you already did a great job narrowing things down with tcptrack to confirm the load balancer is sending traffic to your node's 30010 port. That’s a huge clue! Let’s walk through the most likely causes and how to troubleshoot them:

1. Confirm Your NodePort Service is Connected to Healthy Pods

First up, we need to make sure your Service is actually pointing to Pods that are running and ready. Run this command to inspect your Service:
kubectl describe service <your-service-name>
Look for the Endpoints section—if it’s empty, or lists IPs that don’t match your Pods, that’s a red flag. The Service can’t route traffic if it doesn’t have healthy endpoints to send it to.

Also, check your Pods’ status directly:
kubectl get pods -o wide
Make sure the READY column shows a full count (like 1/1 if you have one container per Pod) and the STATUS is Running. If a Pod isn’t marked ready, the Service will exclude it from traffic routing.

2. Check for Blocking Network Policies or Firewall Rules

Even if the node’s port is seeing traffic, Kubernetes Network Policies might be blocking traffic from the node to your Pod. List all network policies in your Pod’s namespace:
kubectl get networkpolicy
If any policies exist, verify they explicitly allow ingress traffic from the node’s IP range or from the Service’s cluster IP.

Don’t forget to check the node’s local firewall too (like iptables or firewalld). For iptables, run this to see rules related to your NodePort:
iptables -L -n | grep 30010
You should see rules that allow traffic to forward from the node port to your Pod’s IP and container port. If those rules are missing, that’s a problem.

3. Double-Check Port Mappings Between Service and Pod

A super common mistake is mismatching the targetPort in your Service with the actual port your container is listening on. Let’s verify:

  • In your Pod manifest, confirm the containerPort matches the port your app is running on:
    containers:
    - name: your-app-container
      ports:
      - containerPort: 8080 # Make sure this is your app's listening port
    
  • In your Service manifest, ensure targetPort matches that container port:
    spec:
      ports:
      - port: 80
        targetPort: 8080 # Must match containerPort above
        nodePort: 30010
    

If these don’t line up, traffic will reach the node port but never make it to the container.

4. Test Direct Pod Access with kubectl port-forward

To rule out the Service and load balancer entirely, test connecting directly to your Pod. Run:
kubectl port-forward <your-pod-name> 8080:8080
Then access localhost:8080 (or from the node itself, if you’re testing remotely). If this works, the problem is definitely in the routing between the node port and the Pod—not the Pod itself.

5. Inspect Kubernetes iptables Routing Rules

Kubernetes uses kube-proxy and iptables to route traffic from NodePorts to Pods. Let’s check if those rules are set up correctly:

First, find your Service’s hash (you can get this from the kubectl describe service output, look for KUBE-SVC-<HASH> in the iptables references). Then run:
iptables-save | grep KUBE-SVC-<your-service-hash>
You should see rules that forward traffic from the NodePort to your Pod’s endpoints. If these rules are missing or misconfigured, kube-proxy might be malfunctioning.

Also, confirm kube-proxy is running on the node:
kubectl get pods -n kube-system | grep kube-proxy
It should show a Running status for the node in question.

6. Verify Your CNI Plugin Configuration

If you’re using a Container Network Interface (CNI) plugin like Calico, Flannel, or Weave, a misconfigured CNI can block traffic between the node and Pod. Check the CNI’s pod logs for errors:
kubectl logs <cni-pod-name> -n kube-system
For example, if using Calico, look for calico-node pods in the kube-system namespace. Any errors related to network routing or IP allocation could be the culprit.

Once you work through these checks, you should be able to spot where the traffic is getting stuck. Let me know if you hit any weird anomalies in the output!

内容的提问来源于stack exchange,提问作者eran meiri

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 07:03:54