Minikube中Kubernetes服务间连接被拒绝问题排查求助
Hey there, let’s walk through troubleshooting this issue step by step. Since you can resolve the service DNS and ping its IP from the web-gateway pod, the problem is almost certainly in the application layer, service configuration, or network policies—not basic cluster networking. Here’s what to check:
1. Verify the vcsa-manager-service maps to the correct pod port
First, make sure your service is routing traffic to the right port on the vcsa-manager pod:
- Run
kubectl describe service vcsa-manager-serviceto check thespec.portssection. Confirm thetargetPortmatches the port your vcsa-manager application is actually listening on (you mentioned 7070, but double-check!). - Log into the vcsa-manager pod with
kubectl exec -it <vcsa-manager-pod-name> -- /bin/bashand test the endpoint locally:curl localhost:7070/user. If this fails, the issue is with the vcsa-manager app itself (not the network).
2. Test the endpoint directly from the web-gateway pod
Skip the web-gateway application logic entirely and send a raw request from its pod:
- Run
kubectl exec -it <web-gateway-pod-name> -- /bin/bash - Execute
curl http://vcsa-manager-service:7070/user- If you get a
connection refusederror: The vcsa-manager pod isn’t accepting connections on that port (likely listening on localhost instead of 0.0.0.0). - If you get a 404: The
/userendpoint doesn’t exist (check path spelling or app routing). - If you get a 500: The endpoint exists but the vcsa-manager app is throwing an internal error (check its logs).
- If you get a
3. Check if vcsa-manager is listening on 0.0.0.0 (not localhost)
A super common gotcha is apps binding to 127.0.0.1 instead of 0.0.0.0—this makes them only accessible from inside the pod, not from other pods in the cluster:
- In the vcsa-manager pod, run
ss -tulpn(ornetstat -tulpnif ss isn’t installed) to see listening addresses. Look for a line likeLISTEN 0 128 0.0.0.0:7070(good) vs127.0.0.1:7070(bad). - If it’s listening on localhost, update your vcsa-manager code/configuration to bind to
0.0.0.0:7070.
4. Confirm the service is linked to healthy pods
Even if DNS resolves, the service might not be pointing to any running pods:
- Run
kubectl get endpoints vcsa-manager-service. You should see the IP of your vcsa-manager pod listed underENDPOINTS. - If the endpoints are empty, check that the service’s
spec.selectormatches the labels on your vcsa-manager pods (runkubectl describe pod <vcsa-manager-pod-name>to see pod labels).
5. Check for restrictive NetworkPolicies
If your cluster uses NetworkPolicies, they might be blocking traffic from web-gateway to vcsa-manager:
- Run
kubectl get networkpoliciesto list all policies. Look for any that target either the web-gateway or vcsa-manager pods. - Temporarily delete the policy (or update it) to allow traffic between the two pods and see if the issue resolves.
6. Dig into pod logs for detailed errors
Logs will give you specific clues about what’s going wrong:
- Check web-gateway logs:
kubectl logs <web-gateway-pod-name>—look for error messages about the/userrequest (e.g., "ECONNREFUSED", "404 Not Found"). - Check vcsa-manager logs:
kubectl logs <vcsa-manager-pod-name>—see if the request is even reaching the app. If there’s no entry for the request, traffic isn’t getting through to the pod.
Start with steps 2 and 3—they’ll quickly rule out the most common issues. Once you narrow down the root cause, fixing it should be straightforward!
内容的提问来源于stack exchange,提问作者Mauro Silva

