【问题标题】:k3s - networking between pods not workingk3s - 豆荚之间的网络不起作用
【发布时间】:2021-06-02 09:37:11
【问题描述】:

即使为 Pod 设置了 clusterIP 服务,我仍在努力解决 Pod 之间的这种交叉通信。所有的 pod 都在同一个主节点上,并且在同一个命名空间中。总结:

$ kubectl get pods -o wide
NAME                         READY   STATUS    RESTARTS   AGE    IP           NODE          NOMINATED NODE   READINESS GATES
nginx-744f4df6df-rxhph       1/1     Running   0          136m   10.42.0.31   raspberrypi   <none>           <none>
nginx-2-867f4f8859-csn48     1/1     Running   0          134m   10.42.0.32   raspberrypi   <none>           <none>

$ kubectl get svc -o wide
NAME             TYPE        CLUSTER-IP      EXTERNAL-IP   PORT(S)                      AGE    SELECTOR
nginx-service    ClusterIP   10.43.155.201   <none>        80/TCP                       136m   app=nginx
nginx-service2   ClusterIP   10.43.182.138   <none>        85/TCP                       134m   app=nginx-2

我无法在 nginx 容器中 curl http://nginx-service2:85,反之亦然......虽然我验证了这在我的 docker 桌面安装中有效:

# docker desktop
root@nginx-7dc45fbd74-7prml:/# curl http://nginx-service2:85
<!DOCTYPE html>
<html>
<head>
<title>Welcome to nginx!</title>
<style>
    body {
        width: 35em;
        margin: 0 auto;
        font-family: Tahoma, Verdana, Arial, sans-serif;
    }
</style>
</head>
<body>
<h1>Welcome to nginx!</h1>
<p>If you see this page, the nginx web server is successfully installed and
working. Further configuration is required.</p>

<p>For online documentation and support please refer to
<a href="http://nginx.org/">nginx.org</a>.<br/>
Commercial support is available at
<a href="http://nginx.com/">nginx.com</a>.</p>

<p><em>Thank you for using nginx.</em></p>
</body>
</html>

# k3s
root@nginx-744f4df6df-rxhph:/# curl http://nginx-service2.pwk3spi-vraptor:85
curl: (6) Could not resolve host: nginx-service2.pwk3spi-vraptor

在谷歌搜索问题后(如果我错了,请纠正我)这似乎是一个 coredns 问题,因为查看日志并查看错误超时:

$ kubectl get pods -n kube-system
NAME                                     READY   STATUS      RESTARTS   AGE
helm-install-traefik-qr2bd               0/1     Completed   0          153d
metrics-server-7566d596c8-nnzg2          1/1     Running     59         148d
svclb-traefik-kjbbr                      2/2     Running     60         153d
traefik-758cd5fc85-wzjrn                 1/1     Running     20         62d
local-path-provisioner-6d59f47c7-4hvf2   1/1     Running     72         148d
coredns-7944c66d8d-gkdp4                 1/1     Running     0          3m47s

$ kubectl logs coredns-7944c66d8d-gkdp4 -n kube-system
.:53
[INFO] plugin/reload: Running configuration MD5 = 1c648f07b77ab1530deca4234afe0d03
CoreDNS-1.6.9
linux/arm, go1.14.1, 1766568
[ERROR] plugin/errors: 2 1898797220.1916943194. HINFO: read udp 10.42.0.38:50482->192.168.8.109:53: i/o timeout
[ERROR] plugin/errors: 2 1898797220.1916943194. HINFO: read udp 10.42.0.38:34160->192.168.8.109:53: i/o timeout
[ERROR] plugin/errors: 2 1898797220.1916943194. HINFO: read udp 10.42.0.38:53485->192.168.8.109:53: i/o timeout
[ERROR] plugin/errors: 2 1898797220.1916943194. HINFO: read udp 10.42.0.38:46642->192.168.8.109:53: i/o timeout
[ERROR] plugin/errors: 2 1898797220.1916943194. HINFO: read udp 10.42.0.38:55329->192.168.8.109:53: i/o timeout
[ERROR] plugin/errors: 2 1898797220.1916943194. HINFO: read udp 10.42.0.38:44471->192.168.8.109:53: i/o timeout
[ERROR] plugin/errors: 2 1898797220.1916943194. HINFO: read udp 10.42.0.38:49182->192.168.8.109:53: i/o timeout
[ERROR] plugin/errors: 2 1898797220.1916943194. HINFO: read udp 10.42.0.38:54082->192.168.8.109:53: i/o timeout
[ERROR] plugin/errors: 2 1898797220.1916943194. HINFO: read udp 10.42.0.38:48151->192.168.8.109:53: i/o timeout
[ERROR] plugin/errors: 2 1898797220.1916943194. HINFO: read udp 10.42.0.38:48599->192.168.8.109:53: i/o timeout

人们推荐的地方

  • 更改 coredns 配置映射以转发到您的主节点 IP

...其他 CoreFile 的东西

向前。 主机服务器IP

...其他 CoreFile 的东西

  • 或将您的 coredns clusterip IP 作为名称服务器添加到 /etc/resolve.conf

搜索 default.svc.cluster.local svc.cluster.local cluster.local

域名服务器 10.42.0.38

域名服务器 192.168.8.1

名称服务器 fe80::266:19ff:fea7:85e7%wlan0

,但是没有发现这些解决方案有效。

参考详情:

$ kubectl get nodes -o wide
NAME          STATUS   ROLES    AGE    VERSION        INTERNAL-IP     EXTERNAL-IP   OS-IMAGE                         KERNEL-VERSION   CONTAINER-RUNTIME
raspberrypi   Ready    master   153d   v1.18.9+k3s1   192.168.8.109   <none>        Raspbian GNU/Linux 10 (buster)   5.10.9-v7l+      containerd://1.3.3-k3s2

$ kubectl get svc -n kube-system -o wide
NAME                 TYPE           CLUSTER-IP      EXTERNAL-IP     PORT(S)                      AGE    SELECTOR
kube-dns             ClusterIP      10.43.0.10      <none>          53/UDP,53/TCP,9153/TCP       153d   k8s-app=kube-dns
metrics-server       ClusterIP      10.43.205.8     <none>          443/TCP                      153d   k8s-app=metrics-server
traefik-prometheus   ClusterIP      10.43.222.138   <none>          9100/TCP                     153d   app=traefik,release=traefik
traefik              LoadBalancer   10.43.249.133   192.168.8.109   80:31222/TCP,443:32509/TCP   153d   app=traefik,release=traefik

$ kubectl get ep kube-dns -n kube-system
NAME       ENDPOINTS                                     AGE
kube-dns   10.42.0.38:53,10.42.0.38:9153,10.42.0.38:53   153d

不知道我哪里出错了,或者我是否专注于错误的事情,或者如何继续。任何帮助将不胜感激。

【问题讨论】:

  • 也试过this。运气不好
  • 总而言之,这是您使用 K3s 的本地环境。您使用的是什么 Kubernetes 版本?你是部署了 MetalLB 还是只部署了 Traefik?只是为了确认一下,您的节点是 RaspberryPi?您想从 nginx-service 端点的 pod 卷曲到 nginx-service2 pod 的端点吗?
  • 感谢@PjoterS 的回复。是的,在 RaspberryPi 上,带有 Traefik,位于 2 个 clusterIP 端点之间。我发现了我的错误,并发布了答案以供参考。谢谢你:)

标签: kubernetes coredns k3s


【解决方案1】:

当所有其他方法都失败时.....返回手册。我尝试在所有错误的地方找到“问题”,而我只需要遵循 Rancher 的 k3s 安装文档(叹气)。

Rancher's documentation 非常好(你只需要实际遵循它),他们在 Raspbian Buster 环境

上安装 k3s 时声明

检查版本:

$ lsb_release -a
No LSB modules are available.
Distributor ID: Raspbian
Description:    Raspbian GNU/Linux 10 (buster)
Release:        10
Codename:       buster

您需要更改为 legacy iptables,声明运行 (link):

sudo iptables -F
sudo update-alternatives --set iptables /usr/sbin/iptables-legacy
sudo update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy
sudo reboot

注意,设置 iptables 时,请直接在 pi 上进行,而不是通过 ssh。你会被踢出去

完成此操作后,我的所有服务都很满意,并且可以通过它们定义的 clusterIP 服务名称等在容器内相互卷曲。

【讨论】:

    【解决方案2】:

    你尝试 curl 这个地址有什么原因吗:

    curl http://nginx-service2.pwk3spi-vraptor:85
    

    这不应该只是:

    curl http://nginx-service2:85
    

    【讨论】:

    • 并不重要。第二部分只是指定部署服务的命名空间。
    猜你喜欢
    • 2021-11-22
    • 2017-09-28
    • 2023-03-12
    • 2013-07-01
    • 2021-09-02
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多