【发布时间】:2021-07-09 00:42:24
【问题描述】:
我已在我的 Bare Metal Kubernetes 集群上成功安装了 MetalLB,但似乎只有分配给主节点的 pod 可以工作。
MLB 配置在 layer2 上,范围为 192.168.0.100-192.168.0.200,Pod 在分配给工作节点时确实会获得 IP,但这些 ip 不会响应任何请求。
如果分配的ip在节点内卷曲,它可以工作,但如果它从另一个节点或机器卷曲,它不会响应。
例子:
# kubectl get pods -o wide
NAME READY STATUS RESTARTS AGE IP NODE NOMINATED NODE READINESS GATES
nginx2-658ffbbcb6-w5w28 1/1 Running 0 4m51s 10.244.1.2 worker2.homelab.com <none> <none>
nginx21-65b87bcbcb-fv856 1/1 Running 0 4h32m 10.244.0.10 master1.homelab.com <none> <none>
# kubectl get svc
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
kubernetes ClusterIP 10.96.0.1 <none> 443/TCP 5h49m
nginx2 LoadBalancer 10.111.192.206 192.168.0.111 80:32404/TCP 5h21m
nginx21 LoadBalancer 10.108.222.125 192.168.0.113 80:31387/TCP 4h43m
# kubectl get nodes -o wide
NAME STATUS ROLES AGE VERSION INTERNAL-IP EXTERNAL-IP OS-IMAGE KERNEL-VERSION CONTAINER-RUNTIME
master1.homelab.com Ready control-plane,master 5h50m v1.20.2 192.168.0.20 <none> CentOS Linux 7 (Core) 3.10.0-1160.15.2.el7.x86_64 docker://20.10.3
worker2.homelab.com Ready <none> 10m v1.20.2 192.168.0.22 <none> CentOS Linux 7 (Core) 3.10.0-1160.15.2.el7.x86_64 docker://20.10.3
部署nginx2(Worker2,不工作的那个)
kubectl describe svc nginx2
Name: nginx2
Namespace: default
Labels: <none>
Annotations: <none>
Selector: app=nginx2
Type: LoadBalancer
IP: 10.111.192.206
LoadBalancer Ingress: 192.168.0.111
Port: http 80/TCP
TargetPort: 80/TCP
NodePort: http 32404/TCP
Endpoints: 10.244.1.2:80
Session Affinity: None
External Traffic Policy: Cluster
Events:
Type Reason Age From Message
---- ------ ---- ---- -------
Normal nodeAssigned 10m (x6 over 5h23m) metallb-speaker announcing from node "master1.homelab.com"
Normal nodeAssigned 5m18s metallb-speaker announcing from node "worker2.homelab.com"
[root@worker2 ~]# curl 192.168.0.111
<!DOCTYPE html> ..... (Works)
[root@master1 ~]# curl 192.168.0.111
curl: (7) Failed connect to 192.168.0.111:80; No route to host
部署nginx21(Master1,能用的那个)
kubectl describe svc nginx21
Name: nginx21
Namespace: default
Labels: <none>
Annotations: <none>
Selector: app=nginx21
Type: LoadBalancer
IP: 10.108.222.125
LoadBalancer Ingress: 192.168.0.113
Port: http 80/TCP
TargetPort: 80/TCP
NodePort: http 31387/TCP
Endpoints: 10.244.0.10:80
Session Affinity: None
External Traffic Policy: Cluster
Events:
Type Reason Age From Message
---- ------ ---- ---- -------
Normal nodeAssigned 12m (x3 over 4h35m) metallb-speaker announcing from node "master1.homelab.com"
[root@worker2 ~]# curl 192.168.0.113
<!DOCTYPE html> ..... (Works)
[root@master1 ~]# curl 192.168.0.113
<!DOCTYPE html> ..... (Works)
--------- PING 来自其他机器的工作 ----------
我刚刚发现了这个,所以这可能是 iptables 的问题?我真的不知道它在 MetalLB 上是如何工作的,我可以从其他机器 ping ip (192.168.0.111) 并且它会响应
【问题讨论】:
-
尝试停止节点上的 firewalld:
sudo systemctl stop firewalld。有用吗? -
@Matt 成功了!我怎么知道哪个端口或什么被防火墙阻止?防火墙的日志显示这个
Apr 14 21:21:07 worker2.homelab.com firewalld[1508]: WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w10 -D FORWARD -i docker0 -o docker0 -j DROP' failed: iptables: Bad rule (does a matching rule exist in that chain?).
标签: linux kubernetes networking