如何将Kubernetes中运行的多容器Pod暴露至公网?
Hey there! Glad your test pod with both API and web containers is up and running smoothly. To make these services accessible from the public internet, Kubernetes offers a few reliable approaches—let’s break them down step by step, tailored to your setup:
Option 1: Use a NodePort Service
A NodePort Service exposes your pod on a static port across all nodes in your cluster. This is a great quick fix if your cluster nodes have public IP addresses (ideal for testing or small setups).
Create the Service via YAML
Save this as test-service-nodeport.yaml:
apiVersion: v1 kind: Service metadata: name: test-service spec: type: NodePort selector: purpose: test # Matches the label defined on your pod ports: - name: api port: 8085 # Internal port the service listens on targetPort: 8085 # Matches the API container's exposed port nodePort: 30085 # Optional: Pick a port between 30000-32767; Kubernetes auto-assigns one if omitted - name: web port: 5000 targetPort: 5000 nodePort: 30500
Apply the configuration with:
kubectl apply -f test-service-nodeport.yaml
Access the Services
Once the service is live, use your node’s public IP to reach the containers:
- API:
http://<your-node-public-ip>:30085 - Web:
http://<your-node-public-ip>:30500
Option 2: Use a LoadBalancer Service (Cloud Environments)
If you’re running Kubernetes on a cloud provider (GCP, AWS, Azure, etc.), a LoadBalancer Service will automatically provision a public cloud load balancer to route traffic to your pod. This is the standard production-grade option for cloud clusters.
Create the Service via YAML
Save this as test-service-loadbalancer.yaml:
apiVersion: v1 kind: Service metadata: name: test-service spec: type: LoadBalancer selector: purpose: test ports: - name: api port: 8085 targetPort: 8085 - name: web port: 5000 targetPort: 5000
Apply it with:
kubectl apply -f test-service-loadbalancer.yaml
Get the Public IP
Wait a minute or two for the cloud provider to provision the load balancer, then run this to fetch its public IP:
kubectl get service test-service
Look for the EXTERNAL-IP column—use that to access your services:
- API:
http://<loadbalancer-public-ip>:8085 - Web:
http://<loadbalancer-public-ip>:5000
Option 3: Use an Ingress (For Advanced Routing)
If you want custom domains, path-based routing, or SSL termination, an Ingress is the way to go. First, you’ll need an Ingress controller installed in your cluster (like the NGINX Ingress controller).
Example Ingress YAML
Save this as test-ingress.yaml:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: test-ingress annotations: nginx.ingress.kubernetes.io/rewrite-target: /$1 spec: rules: - host: your-domain.com # Replace with your actual domain http: paths: - path: /api(/|$)(.*) pathType: Prefix backend: service: name: test-service port: number: 8085 - path: /web(/|$)(.*) pathType: Prefix backend: service: name: test-service port: number: 5000
Apply it with:
kubectl apply -f test-ingress.yaml
Then point your domain’s DNS records to the Ingress controller’s public IP. You’ll be able to access:
- API:
http://your-domain.com/api - Web:
http://your-domain.com/web
内容的提问来源于stack exchange,提问作者Mike

