如何将Kubernetes ReplicaSet的内部端点暴露为外部可访问?
Hey there! Looks like you've already got your ReplicaSet and pod ports configured correctly with 80 and 443 exposed internally—great start! To make those endpoints accessible from outside your Kubernetes cluster, you've got a few solid options depending on your environment and needs. Let's break them down:
1. NodePort (Quick Testing & On-Prem Clusters)
NodePort opens a fixed port on every node in your cluster, letting external traffic reach your service via <Node IP>:<NodePort>. This is perfect for testing or on-prem setups where you don't have a cloud load balancer.
You can create a NodePort Service (or modify your existing ClusterIP Service generated by Kompose) with this YAML:
apiVersion: v1 kind: Service metadata: name: router-service spec: type: NodePort selector: # Match the labels on your ReplicaSet's pods—check with `kubectl get pods --show-labels` io.kompose.service: router ports: - name: http port: 80 # Cluster-internal port targetPort: 80 # Port on your pod nodePort: 30080 # Optional: Pick a port between 30000-32767; omit to let K8s auto-assign - name: https port: 443 targetPort: 443 nodePort: 30443
Apply it with:
kubectl apply -f router-service-nodeport.yaml
Check the assigned NodePort (if you didn't specify one) with:
kubectl get service router-service
Then access your service using any node's public IP plus the NodePort (e.g., http://192.168.1.100:30080).
2. LoadBalancer (Cloud Environments)
If you're running on a cloud provider like AWS, GCP, or Azure, using a LoadBalancer Service will automatically provision a cloud-managed load balancer with a public IP. This is the easiest way to get a stable external endpoint for cloud deployments.
Here's the YAML:
apiVersion: v1 kind: Service metadata: name: router-service-loadbalancer spec: type: LoadBalancer selector: io.kompose.service: router ports: - name: http port: 80 targetPort: 80 - name: https port: 443 targetPort: 443
Apply it, then wait a minute for the cloud provider to assign an external IP. Check progress with:
kubectl get service router-service-loadbalancer
Once the EXTERNAL-IP field populates, you can access your service directly via that IP on ports 80 and 443.
3. Ingress (Production-Grade, Domain-Based Access)
For production setups where you want to use custom domains, SSL, and route multiple services through a single entry point, Ingress is the way to go. First, you'll need an Ingress Controller (like NGINX Ingress) installed in your cluster.
Once the controller is set up, create an Ingress resource like this:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: router-ingress annotations: nginx.ingress.kubernetes.io/ssl-redirect: "true" # Auto-redirect HTTP to HTTPS spec: tls: - hosts: - your-custom-domain.com # Replace with your actual domain secretName: router-tls-secret # Replace with your TLS cert secret name rules: - host: your-custom-domain.com http: paths: - path: / pathType: Prefix backend: service: name: router-service # Point to your existing ClusterIP/NodePort Service port: number: 80
Before applying, create a TLS Secret for your SSL cert (if using HTTPS):
kubectl create secret tls router-tls-secret --cert=path/to/your/cert.crt --key=path/to/your/private.key
Apply the Ingress YAML, then update your domain's DNS to point to the Ingress Controller's external IP. You'll then be able to access your service via https://your-custom-domain.com.
Pick the method that fits your environment best—NodePort for quick testing, LoadBalancer for cloud deployments, and Ingress for production-grade, domain-based access.
内容的提问来源于stack exchange,提问作者Philip Kirkbride

