You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Kubernetes Service节点无法访问外网及入站服务配置咨询

Troubleshooting AKS Outbound Connectivity & Setting Up Internet Access to Cluster Services

Hey there, let's tackle your problem step by step—first fixing why your AKS nodes can't ping external IPs, then setting up inbound access from the internet to your cluster services.

First: Resolve Outbound Ping Failure on AKS Nodes

Even though you've configured NSG outbound rules and restarted VMs, let's verify a few critical areas that might still be blocking traffic:

  • Double-check NSG association & rule priority
    Make sure the NSG you modified is actually linked to your AKS node subnet (not the control plane subnet or a separate one). Also, confirm no higher-priority deny rules are overriding your allow rules. Run this Azure CLI command to list your NSG rules sorted by priority:

    az network nsg rule list --nsg-name <your-nsg-name> --resource-group <your-node-resource-group> --query "[].{Name:name, Priority:priority, Direction:direction, Access:access}" | sort -k2n
    

    Look for any Deny rules with a lower priority number (higher precedence) than your outbound allow rules. Also, ensure the default AllowInternetOutbound rule hasn't been modified or deleted.

  • Inspect User-Defined Routes (UDR)
    If your AKS node subnet uses a custom route table, check if there's a route for 0.0.0.0/0 that's directing traffic away from the public internet (like to a misconfigured firewall or NAT gateway). Use these commands to investigate:

    # Find which route table is attached to your node subnet
    az network route-table list --resource-group <your-node-resource-group> --query "[].{Name:name, Subnets:subnets[].id}"
    # List routes in that table
    az network route-table route list --route-table-name <route-table-name> --resource-group <your-node-resource-group>
    

    If the default route's next hop isn't set to Internet, you'll need to adjust it or ensure the target resource (like a NAT gateway) is properly provisioned and linked.

  • Verify node-level network config
    Log into one of your AKS nodes using the built-in node shell and check local network settings:

    az aks node-shell --resource-group <your-cluster-rg> --name <aks-cluster-name>
    

    Once connected, run these commands to diagnose:

    • ip route show to confirm the default gateway is set correctly
    • iptables -L -n to check for local iptables rules blocking outbound ICMP (ping) traffic
    • Even though you're pinging IPs, quickly run cat /etc/resolv.conf to rule out DNS misconfigurations that might cause unexpected side effects
  • Check AKS outbound type configuration
    If your cluster uses a NAT gateway or load balancer for outbound traffic, confirm the resource is healthy:

    • For NAT gateway: Ensure it's linked to your node subnet and has a valid, active public IP
    • For load balancer outbound: Verify that outbound rules are configured to allow traffic to the internet

Second: Set Up Internet Access to Cluster Services

Once outbound connectivity is fixed, here are the two most reliable ways to expose your services to the internet:

Option 1: Use a LoadBalancer Service

This is the simplest method for single services. Create a Service manifest with type: LoadBalancer:

apiVersion: v1
kind: Service
metadata:
  name: my-public-service
spec:
  type: LoadBalancer
  selector:
    app: your-app-label # Match the labels on your running pods
  ports:
    - protocol: TCP
      port: 80 # Port exposed on the public load balancer
      targetPort: 8080 # Port your pod is listening on

Apply it with kubectl apply -f <service-file.yaml>, then run kubectl get service my-public-service to retrieve the assigned public IP. You can then access your service directly using this IP.

Option 2: Use an Ingress Controller (for multiple services)

If you have multiple services to expose, an Ingress Controller (like NGINX) lets you route traffic via a single public IP and custom domain names.

  1. Install the NGINX Ingress Controller: You can use AKS's managed Ingress option via the Azure portal/CLI, or deploy the open-source NGINX Ingress Controller using its official manifest.
  2. Create an Ingress manifest to route traffic to your service:
    apiVersion: networking.k8s.io/v1
    kind: Ingress
    metadata:
      name: my-app-ingress
      annotations:
        nginx.ingress.kubernetes.io/rewrite-target: /
    spec:
      ingressClassName: nginx
      rules:
      - host: your-app.example.com # Replace with your custom domain
        http:
          paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: your-service-name
                port:
                  number: 80
    
  3. Get the public IP of the Ingress Controller with kubectl get service ingress-nginx-controller, then point your domain's DNS record to this IP.

Critical Note for Inbound Access

Whichever method you choose, make sure your NSG allows inbound traffic on the relevant ports (e.g., 80 for HTTP, 443 for HTTPS) to the load balancer/Ingress Controller's public IP. If you're using Azure Firewall, add additional rules to allow internet traffic to these IPs and ports.


内容的提问来源于stack exchange,提问作者rfum

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:56:58