1

我在 GKE 中有部署和服务。我将部署公开为负载均衡器,但我无法通过服务(curl 或浏览器)访问它。我得到一个:

curl: (7) Failed to connect to <my-Ip-Address> port 443: Connection refused

我可以直接转发到 pod,它工作正常:

kubectl --namespace=redfalcon port-forward web-service-rf-76967f9c68-2zbhm 9999:443 >> /dev/null

curl -k -v --request POST   --url https://localhost:9999/auth/login/   --header 'content-type: application/json'   --header 'x-profile-key: '   --data '{"email":"<testusername>","password":"<testpassword>"}'

我很可能错误地配置了我的服务,但看不到如何配置。对我所做的任何帮助将不胜感激。

服务 Yaml:

---
apiVersion: v1
kind: Service
metadata:
  name: red-falcon-lb
  namespace: redfalcon
spec:
  type: LoadBalancer
  ports:
  - name: https
    port: 443
    protocol: TCP
  selector:
   app: web-service-rf

部署 YAML

apiVersion: apps/v1 # for versions before 1.9.0 use apps/v1beta2
kind: Deployment
metadata:
  name: web-service-rf
spec:
  selector:
    matchLabels:
      app: web-service-rf
  replicas: 2 # tells deployment to run 2 pods matching the template
  template:
    metadata:
      labels:
        app: web-service-rf
    spec:
      initContainers:
        - name: certificate-init-container
          image: proofpoint/certificate-init-container:0.2.0
          imagePullPolicy: Always
          env:
            - name: NAMESPACE
              valueFrom:
                fieldRef:
                  fieldPath: metadata.namespace
            - name: POD_NAME
              valueFrom:
                fieldRef:
                  fieldPath: metadata.name
          args:
            - "-namespace=$(NAMESPACE)"
            - "-pod-name=$(POD_NAME)"
            - "-query-k8s"
          volumeMounts:
            - name: tls
              mountPath: /etc/tls
      containers:
        - name: web-service-rf
          image: gcr.io/redfalcon-186521/redfalcon-webserver-minimal:latest
#          image: gcr.io/redfalcon-186521/redfalcon-webserver-full:latest
          command:
            - "./server"
            - "--port=443"
          imagePullPolicy: Always
          env:
            - name: GOOGLE_APPLICATION_CREDENTIALS
              value: /var/secrets/google/key.json
          ports:
            - containerPort: 443
          resources:
            limits:
              memory: "500Mi"
              cpu: "100m"
          volumeMounts:
          - mountPath: /etc/tls
            name: tls
          - mountPath: /var/secrets/google
            name: google-cloud-key
      volumes:
        - name: tls
          emptyDir: {}
        - name: google-cloud-key
          secret:
           secretName: pubsub-key

输出:kubectl describe svc red-falcon-lb

Name:                     red-falcon-lb
Namespace:                redfalcon
Labels:                   <none>
Annotations:              kubectl.kubernetes.io/last-applied-configuration={"apiVersion":"v1","kind":"Service","metadata":{"annotations":{},"name":"red-falcon-lb","namespace":"redfalcon"},"spec":{"ports":[{"name":"https","port...
Selector:                 app=web-service-rf
Type:                     LoadBalancer
IP:                       10.43.245.9
LoadBalancer Ingress:     <EXTERNAL IP REDACTED>
Port:                     https  443/TCP
TargetPort:               443/TCP
NodePort:                 https  31524/TCP
Endpoints:                10.40.0.201:443,10.40.0.202:443
Session Affinity:         None
External Traffic Policy:  Cluster
Events:
  Type    Reason                Age   From                Message
  ----    ------                ----  ----                -------
  Normal  EnsuringLoadBalancer  39m   service-controller  Ensuring load balancer
  Normal  EnsuredLoadBalancer   38m   service-controller  Ensured load balancer
4

1 回答 1

2

我弄清楚那是什么...

我的 golang 应用程序正在侦听 localhost 而不是 0.0.0.0。这意味着 kubectl 上的端口转发工作但任何服务暴露都不起作用。

我必须在我的 k8s 命令中添加“--host 0.0.0.0”,然后它会监听来自本地主机外部的请求。

我的命令最终是......

"./server --port 8080 --host 0.0.0.0"

于 2018-08-08T23:17:46.853 回答