You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Minikube中Kubernetes服务间连接被拒绝问题排查求助

Troubleshooting Connection Error Between web-gateway and vcsa-manager-service in Minikube

Hey there, let’s walk through troubleshooting this issue step by step. Since you can resolve the service DNS and ping its IP from the web-gateway pod, the problem is almost certainly in the application layer, service configuration, or network policies—not basic cluster networking. Here’s what to check:

1. Verify the vcsa-manager-service maps to the correct pod port

First, make sure your service is routing traffic to the right port on the vcsa-manager pod:

  • Run kubectl describe service vcsa-manager-service to check the spec.ports section. Confirm the targetPort matches the port your vcsa-manager application is actually listening on (you mentioned 7070, but double-check!).
  • Log into the vcsa-manager pod with kubectl exec -it <vcsa-manager-pod-name> -- /bin/bash and test the endpoint locally: curl localhost:7070/user. If this fails, the issue is with the vcsa-manager app itself (not the network).

2. Test the endpoint directly from the web-gateway pod

Skip the web-gateway application logic entirely and send a raw request from its pod:

  • Run kubectl exec -it <web-gateway-pod-name> -- /bin/bash
  • Execute curl http://vcsa-manager-service:7070/user
    • If you get a connection refused error: The vcsa-manager pod isn’t accepting connections on that port (likely listening on localhost instead of 0.0.0.0).
    • If you get a 404: The /user endpoint doesn’t exist (check path spelling or app routing).
    • If you get a 500: The endpoint exists but the vcsa-manager app is throwing an internal error (check its logs).

3. Check if vcsa-manager is listening on 0.0.0.0 (not localhost)

A super common gotcha is apps binding to 127.0.0.1 instead of 0.0.0.0—this makes them only accessible from inside the pod, not from other pods in the cluster:

  • In the vcsa-manager pod, run ss -tulpn (or netstat -tulpn if ss isn’t installed) to see listening addresses. Look for a line like LISTEN 0 128 0.0.0.0:7070 (good) vs 127.0.0.1:7070 (bad).
  • If it’s listening on localhost, update your vcsa-manager code/configuration to bind to 0.0.0.0:7070.

4. Confirm the service is linked to healthy pods

Even if DNS resolves, the service might not be pointing to any running pods:

  • Run kubectl get endpoints vcsa-manager-service. You should see the IP of your vcsa-manager pod listed under ENDPOINTS.
  • If the endpoints are empty, check that the service’s spec.selector matches the labels on your vcsa-manager pods (run kubectl describe pod <vcsa-manager-pod-name> to see pod labels).

5. Check for restrictive NetworkPolicies

If your cluster uses NetworkPolicies, they might be blocking traffic from web-gateway to vcsa-manager:

  • Run kubectl get networkpolicies to list all policies. Look for any that target either the web-gateway or vcsa-manager pods.
  • Temporarily delete the policy (or update it) to allow traffic between the two pods and see if the issue resolves.

6. Dig into pod logs for detailed errors

Logs will give you specific clues about what’s going wrong:

  • Check web-gateway logs: kubectl logs <web-gateway-pod-name>—look for error messages about the /user request (e.g., "ECONNREFUSED", "404 Not Found").
  • Check vcsa-manager logs: kubectl logs <vcsa-manager-pod-name>—see if the request is even reaching the app. If there’s no entry for the request, traffic isn’t getting through to the pod.

Start with steps 2 and 3—they’ll quickly rule out the most common issues. Once you narrow down the root cause, fixing it should be straightforward!

内容的提问来源于stack exchange,提问作者Mauro Silva

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 06:43:04