AWS上Kubernetes集群无法解析服务DNS名称问题求助
Let’s work through the most common fixes for the DNS resolution problem with your widget-svc service in AWS EKS. Since you can access the service directly but DNS isn’t resolving, we’ll focus on validating Kubernetes DNS components, service naming conventions, and cluster configuration.
1. Verify CoreDNS (kube-dns) is running correctly
Kubernetes relies on CoreDNS (or kube-dns in older clusters) for internal DNS resolution. First, check if the DNS pods are healthy:
kubectl get pods -n kube-system -l k8s-app=kube-dns
You should see all pods in Running state. If any are crashing or pending, check their logs for errors:
kubectl logs -n kube-system -l k8s-app=kube-dns
Also, confirm the CoreDNS configmap has proper forwarder settings for your AWS VPC (it should point to your VPC's DNS server, usually the VPC CIDR base + 2):
kubectl get configmap coredns -n kube-system -o yaml
2. Use the full Kubernetes service DNS name
Kubernetes services have a fully qualified domain name (FQDN) in the format <service-name>.<namespace>.svc.cluster.local. Since your service is in the default namespace (you didn’t specify a custom one), you need to use:
widget-svc.default.svc.cluster.local
Test this from within a cluster pod to rule out naming issues:
kubectl run -it --rm --image=busybox:1.28 dns-test -- nslookup widget-svc.default.svc.cluster.local
If this works but the shortname widget-svc doesn’t, check your pod’s DNS search domains (see step 4).
3. Double-check service and pod label matching
Even though you can access the service, it’s worth confirming the selector labels match between your service and deployment:
- Check the service’s selector:
kubectl get service widget-svc -o yaml | grep -A2 selector - Verify pods have the matching label:
kubectl get pods -l app=widget-test
Also, ensure the service has a valid ClusterIP assigned (not Pending):
kubectl get service widget-svc
4. Inspect pod DNS configuration
Check the DNS settings inside one of your widget-pod instances to ensure it’s pointing to the cluster DNS service:
kubectl exec <your-pod-name> -- cat /etc/resolv.conf
You should see a nameserver entry pointing to the kube-dns ClusterIP (typically 10.96.0.10), and search domains that include default.svc.cluster.local, svc.cluster.local, and your AWS VPC domain. If the nameserver is missing or incorrect, this could cause DNS failures.
5. AWS EKS VPC-specific checks
Ensure your EKS cluster’s VPC has the required DNS settings enabled:
- In the AWS Console, navigate to your VPC > Settings > DNS Hostnames, confirm
Enable DNS hostnamesis checked - Check
Enable DNS supportis also enabled in the same section
If you’re using a custom CNI (like Calico), verify network policies aren’t blocking TCP/UDP traffic on port 53 (DNS) to thekube-systemnamespace.
内容的提问来源于stack exchange,提问作者satya

