温馨提示×

温馨提示×

您好,登录后才能下订单哦!

密码登录×
登录注册×
其他方式登录
点击 登录注册 即表示同意《亿速云用户服务条款》

怎样排查Node节点网络故障

发布时间:2026-09-26 15:22:16 来源:亿速云 阅读:87 作者:小樊 栏目:系统运维

排查 Kubernetes Node 节点网络故障,一般可以按“由内到外、由本地到集群”的思路逐步定位。下面是一套系统化的排查流程和常用命令。


一、确认故障现象

先明确是哪种网络问题:

  • Node 本身不通外网?
  • Node 到 Master 不通?
  • Pod 之间不通?
  • Pod 访问 Service / 外网不通?
  • DNS 解析失败?

二、检查 Node 基础状态

1. 查看节点状态

kubectl get nodes
kubectl describe node <node-name>

重点关注:

  • Ready 状态
  • Conditions(NetworkUnavailable 等)
  • Events

2. 登录问题 Node

ssh <node-ip>

三、检查节点网络基础

1. 网卡与 IP

ip addr
ip route

确认:

  • 网卡是否 up
  • IP 是否正确
  • 默认路由是否存在

2. 测试基础连通性

ping 8.8.8.8
ping <master-ip>
ping <other-node-ip>

3. DNS 检查

cat /etc/resolv.conf
nslookup kubernetes.default

四、检查 kubelet 与 CNI

1. kubelet 状态

systemctl status kubelet
journalctl -u kubelet -f

2. CNI 插件状态(常见:Calico / Flannel / Cilium)

# Flannel
systemctl status flanneld

# Calico
kubectl get pods -n kube-system | grep calico

# 容器化 CNI 日志
kubectl logs -n kube-system <cni-pod>

3. CNI 配置文件

ls /etc/cni/net.d/
cat /etc/cni/net.d/*.conflist

五、检查桥接与 iptables

1. 桥接转发

sysctl net.bridge.bridge-nf-call-iptables
sysctl net.ipv4.ip_forward

应为:

net.bridge.bridge-nf-call-iptables = 1
net.ipv4.ip_forward = 1

2. iptables / nftables

iptables -L -n -v
iptables -t nat -L -n -v

六、Pod 网络排查(在 Node 上)

1. 查看 Pod IP

kubectl get pods -o wide

2. 进入 Pod 测试

kubectl exec -it <pod> -- sh
ping <other-pod-ip>
curl <service-ip>:<port>

3. 检查端口监听

ss -lntp

七、常见故障点总结

故障点 表现 排查重点
路由缺失 Node/Pod 不通 ip route
CNI 未就绪 NetworkUnavailable CNI Pod 状态
防火墙 端口不通 iptables / firewalld
DNS 异常 域名解析失败 resolv.conf
MTU 不匹配 大包丢包 CNI MTU 设置
多网卡 路由走错 默认路由

八、快速排错清单(建议保存)

ip addr
ip route
ping 8.8.8.8
systemctl status kubelet
kubectl get pods -n kube-system
iptables -L -n

如果你能补充:

  • 使用的 CNI 插件
  • 是 Pod 不通 / Node 不通 / 外网不通
  • 错误日志或 kubectl describe node 输出

我可以帮你做针对性排查。

向AI问一下细节

免责声明:本站发布的内容(图片、视频和文字)以原创、转载和分享为主,文章观点不代表本网站立场,如果涉及侵权请联系站长邮箱:is@yisu.com进行举报,并提供相关证据,一经查实,将立刻删除涉嫌侵权内容。

AI
助
手