Azure Kubernetes Service节点无法访问外网及入站服务配置咨询
Hey there, let's tackle your problem step by step—first fixing why your AKS nodes can't ping external IPs, then setting up inbound access from the internet to your cluster services.
First: Resolve Outbound Ping Failure on AKS Nodes
Even though you've configured NSG outbound rules and restarted VMs, let's verify a few critical areas that might still be blocking traffic:
Double-check NSG association & rule priority
Make sure the NSG you modified is actually linked to your AKS node subnet (not the control plane subnet or a separate one). Also, confirm no higher-priority deny rules are overriding your allow rules. Run this Azure CLI command to list your NSG rules sorted by priority:az network nsg rule list --nsg-name <your-nsg-name> --resource-group <your-node-resource-group> --query "[].{Name:name, Priority:priority, Direction:direction, Access:access}" | sort -k2nLook for any
Denyrules with a lower priority number (higher precedence) than your outbound allow rules. Also, ensure the defaultAllowInternetOutboundrule hasn't been modified or deleted.Inspect User-Defined Routes (UDR)
If your AKS node subnet uses a custom route table, check if there's a route for0.0.0.0/0that's directing traffic away from the public internet (like to a misconfigured firewall or NAT gateway). Use these commands to investigate:# Find which route table is attached to your node subnet az network route-table list --resource-group <your-node-resource-group> --query "[].{Name:name, Subnets:subnets[].id}" # List routes in that table az network route-table route list --route-table-name <route-table-name> --resource-group <your-node-resource-group>If the default route's next hop isn't set to
Internet, you'll need to adjust it or ensure the target resource (like a NAT gateway) is properly provisioned and linked.Verify node-level network config
Log into one of your AKS nodes using the built-in node shell and check local network settings:az aks node-shell --resource-group <your-cluster-rg> --name <aks-cluster-name>Once connected, run these commands to diagnose:
ip route showto confirm the default gateway is set correctlyiptables -L -nto check for local iptables rules blocking outbound ICMP (ping) traffic- Even though you're pinging IPs, quickly run
cat /etc/resolv.confto rule out DNS misconfigurations that might cause unexpected side effects
Check AKS outbound type configuration
If your cluster uses a NAT gateway or load balancer for outbound traffic, confirm the resource is healthy:- For NAT gateway: Ensure it's linked to your node subnet and has a valid, active public IP
- For load balancer outbound: Verify that outbound rules are configured to allow traffic to the internet
Second: Set Up Internet Access to Cluster Services
Once outbound connectivity is fixed, here are the two most reliable ways to expose your services to the internet:
Option 1: Use a LoadBalancer Service
This is the simplest method for single services. Create a Service manifest with type: LoadBalancer:
apiVersion: v1 kind: Service metadata: name: my-public-service spec: type: LoadBalancer selector: app: your-app-label # Match the labels on your running pods ports: - protocol: TCP port: 80 # Port exposed on the public load balancer targetPort: 8080 # Port your pod is listening on
Apply it with kubectl apply -f <service-file.yaml>, then run kubectl get service my-public-service to retrieve the assigned public IP. You can then access your service directly using this IP.
Option 2: Use an Ingress Controller (for multiple services)
If you have multiple services to expose, an Ingress Controller (like NGINX) lets you route traffic via a single public IP and custom domain names.
- Install the NGINX Ingress Controller: You can use AKS's managed Ingress option via the Azure portal/CLI, or deploy the open-source NGINX Ingress Controller using its official manifest.
- Create an Ingress manifest to route traffic to your service:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: my-app-ingress annotations: nginx.ingress.kubernetes.io/rewrite-target: / spec: ingressClassName: nginx rules: - host: your-app.example.com # Replace with your custom domain http: paths: - path: / pathType: Prefix backend: service: name: your-service-name port: number: 80 - Get the public IP of the Ingress Controller with
kubectl get service ingress-nginx-controller, then point your domain's DNS record to this IP.
Critical Note for Inbound Access
Whichever method you choose, make sure your NSG allows inbound traffic on the relevant ports (e.g., 80 for HTTP, 443 for HTTPS) to the load balancer/Ingress Controller's public IP. If you're using Azure Firewall, add additional rules to allow internet traffic to these IPs and ports.
内容的提问来源于stack exchange,提问作者rfum

