排查 Kubernetes Node 节点网络故障,一般可以按“由内到外、由本地到集群”的思路逐步定位。下面是一套系统化的排查流程和常用命令。
先明确是哪种网络问题:
kubectl get nodes
kubectl describe node <node-name>
重点关注:
Ready 状态Conditions(NetworkUnavailable 等)Eventsssh <node-ip>
ip addr
ip route
确认:
ping 8.8.8.8
ping <master-ip>
ping <other-node-ip>
cat /etc/resolv.conf
nslookup kubernetes.default
systemctl status kubelet
journalctl -u kubelet -f
# Flannel
systemctl status flanneld
# Calico
kubectl get pods -n kube-system | grep calico
# 容器化 CNI 日志
kubectl logs -n kube-system <cni-pod>
ls /etc/cni/net.d/
cat /etc/cni/net.d/*.conflist
sysctl net.bridge.bridge-nf-call-iptables
sysctl net.ipv4.ip_forward
应为:
net.bridge.bridge-nf-call-iptables = 1
net.ipv4.ip_forward = 1
iptables -L -n -v
iptables -t nat -L -n -v
kubectl get pods -o wide
kubectl exec -it <pod> -- sh
ping <other-pod-ip>
curl <service-ip>:<port>
ss -lntp
| 故障点 | 表现 | 排查重点 |
|---|---|---|
| 路由缺失 | Node/Pod 不通 | ip route |
| CNI 未就绪 | NetworkUnavailable | CNI Pod 状态 |
| 防火墙 | 端口不通 | iptables / firewalld |
| DNS 异常 | 域名解析失败 | resolv.conf |
| MTU 不匹配 | 大包丢包 | CNI MTU 设置 |
| 多网卡 | 路由走错 | 默认路由 |
ip addr
ip route
ping 8.8.8.8
systemctl status kubelet
kubectl get pods -n kube-system
iptables -L -n
如果你能补充:
kubectl describe node 输出我可以帮你做针对性排查。
免责声明:本站发布的内容(图片、视频和文字)以原创、转载和分享为主,文章观点不代表本网站立场,如果涉及侵权请联系站长邮箱:is@yisu.com进行举报,并提供相关证据,一经查实,将立刻删除涉嫌侵权内容。