无法从所有节点Telnet K8S ClusterIP服务的网络问题求助
Got it, let's get your private container registry up and running in your Kubernetes cluster with a ClusterIP service so it's only accessible internally. Here's a complete, working setup based on what you've shared:
Solution: Deploy Private Container Registry with ClusterIP in Kubernetes
First, let's put together the full configuration for both the Registry Pod and the ClusterIP Service—you had a partial Pod YAML, so here's the complete working version:
Complete YAML Configuration (registry-setup.yaml)
apiVersion: v1 kind: Pod metadata: name: registry labels: app: registry namespace: default spec: containers: - name: registry image: registry:2 ports: - containerPort: 5000 # Using emptyDir for temporary storage (matches your "no special volume" requirement) volumeMounts: - name: registry-storage mountPath: /var/lib/registry volumes: - name: registry-storage emptyDir: {} --- apiVersion: v1 kind: Service metadata: name: registry-service namespace: default spec: type: ClusterIP selector: app: registry ports: - port: 5000 targetPort: 5000
Key Details Breakdown
- Registry Pod: We're using the official
registry:2image (the standard for private Docker registries). TheemptyDirvolume provides temporary storage—note that if the Pod restarts, all stored images will be lost, which aligns with your "no special storage" need. - ClusterIP Service: This service type guarantees the registry is only reachable inside the Kubernetes cluster, which should help avoid the external network issues you ran into earlier. It targets the Pod using the
app: registrylabel, mapping the service's port 5000 to the container's port 5000.
Deployment & Verification Steps
- Apply the configuration to your cluster:
kubectl apply -f registry-setup.yaml - Confirm the Pod is running:
kubectl get pods -l app=registry - Check the Service's ClusterIP (this is what internal Pods will use to access the registry):
kubectl get service registry-service - Test internal access with a temporary busybox Pod:
A successful test will return an empty JSON responsekubectl run -it --rm busybox --image=busybox:1.36 -- wget -qO- http://<CLUSTER-IP>:5000/v2/{}, meaning the registry is reachable.
Quick Troubleshooting Tips
- If network issues persist, double-check that the Service's
selectorexactly matches the Pod'slabels—typos here are a common culprit. - Ensure cluster network policies (if you have any) aren't blocking traffic between Pods and the ClusterIP Service.
- For cluster-wide DNS access, use the service's internal DNS name:
registry-service.default.svc.cluster.local:5000from any Pod in thedefaultnamespace.
内容的提问来源于stack exchange,提问作者luke035
相关产品推荐
相关产品推荐

