# OpenClaw Pod 访问问题诊断报告 ## 问题描述 域名 `test-openclaw-dns.taijiagnet.com` 无法访问 ## 诊断结果 ### ✅ 正常的部分 1. **Pod 状态正常** - Pod: `test-openclaw-dns-6c457fc9c8-p5pg5` - 命名空间: `agent-test-openclaw-dns` - 状态: `Running (2/2)` - 两个容器(gateway 和 dind)都在运行 - 容器就绪状态: `true true` - 两个容器都已就绪 2. **Pod 内部服务正常** - 从 Pod 内部访问 `http://localhost:18789/health` 返回正常 HTML 响应 - 从 Pod 内部访问 Service `http://test-openclaw-dns-service:18789/health` 也正常 3. **Service 配置正确** - Service: `test-openclaw-dns-service` - 类型: `ClusterIP` - 端口: `18789/TCP` - Endpoints: `10.224.0.8:18789` ✅ 正确指向 Pod 4. **Ingress 配置正确** - Ingress: `test-openclaw-dns-ingress` - 域名: `test-openclaw-dns.taijiagnet.com` - Backend: `test-openclaw-dns-service:18789 (10.224.0.8:18789)` ✅ - TLS: 已配置自签名证书 - Ingress IP: `40.65.173.54` 5. **DNS 解析正常** - `test-openclaw-dns.taijiagnet.com` 正确解析到 `40.65.173.54` - DNS 记录与 Ingress IP 一致 6. **Ingress Controller 运行正常** - Ingress Controller Pods: 2 个都在运行 - Service: `ingress-nginx-controller` (LoadBalancer) - LoadBalancer IP: `40.65.173.54` - 端口映射: `80:32519/TCP, 443:31651/TCP` ### ❌ 问题所在 **外部网络访问被阻止** 从集群内部测试: - ✅ Pod 内部访问正常 - ✅ Service 访问正常 - ❌ 外部访问 `40.65.173.54:80` 超时 - ❌ 外部访问 `40.65.173.54:443` 超时 **根本原因:Azure 网络安全组(NSG)或防火墙规则阻止了 80/443 端口** ## 解决方案 ### 方案 1: 检查并更新 Azure 网络安全组(推荐) 1. 在 Azure Portal 中找到 AKS 集群的资源组 2. 找到与 LoadBalancer IP `40.65.173.54` 关联的网络安全组(NSG) 3. 添加入站规则: - **端口 80 (HTTP)**: 允许来自 `*` 的流量 - **端口 443 (HTTPS)**: 允许来自 `*` 的流量 ### 方案 2: 使用 Azure CLI 检查 NSG 规则 ```bash # 查找 LoadBalancer 关联的 NSG az network lb list --query "[?frontendIpConfigurations[0].publicIpAddress=='40.65.173.54']" -o table # 查找并更新 NSG 规则 az network nsg rule list --nsg-name --resource-group -o table az network nsg rule create \ --resource-group \ --nsg-name \ --name AllowHTTP \ --priority 100 \ --direction Inbound \ --access Allow \ --protocol Tcp \ --destination-port-ranges 80 az network nsg rule create \ --resource-group \ --nsg-name \ --name AllowHTTPS \ --priority 101 \ --direction Inbound \ --access Allow \ --protocol Tcp \ --destination-port-ranges 443 ``` ### 方案 3: 检查 AKS 节点池的 NSG ```bash # 查找节点池的 NSG az aks show --name --resource-group --query "agentPoolProfiles[0].vnetSubnetId" -o tsv # 然后查找该子网的 NSG 并更新规则 ``` ## 其他发现 ### 配置版本警告(非关键) - 日志显示: `Config was last written by a newer OpenClaw (2026.2.3); current version is 2026.1.30` - 这是配置版本不匹配的警告,不影响功能,但建议更新镜像版本 ### Readiness Probe 早期失败(已恢复) - 在 Pod 启动初期有 readiness probe 失败 - 现在已经恢复正常,容器状态为 `ready` ## 验证步骤 修复 NSG 规则后,验证访问: ```bash # 测试 HTTP 访问 curl -v http://test-openclaw-dns.taijiagnet.com/health # 测试 HTTPS 访问(忽略自签名证书警告) curl -k -v https://test-openclaw-dns.taijiagnet.com/health ``` ## 重要发现 ### ✅ 从集群内部访问成功 从 Kubernetes 集群内部测试访问 `40.65.173.54:80` **成功**,返回了 308 重定向响应。这说明: - LoadBalancer 配置正确 ✅ - Ingress Controller 工作正常 ✅ - 路由规则正确 ✅ - NSG 规则对集群内部生效 ✅ ### ❌ 从外部网络访问失败 从外部网络访问 `40.65.173.54:80` 和 `443` 端口超时。这说明问题在于: - **外部网络到 Azure LoadBalancer 的路径被阻止** ## 总结 **问题类型**: 外部网络到 Azure 的网络连接问题 **已确认正常的部分**: - ✅ DNS 绑定正常(DNS 解析正确) - ✅ Pod 正常运行(2/2 容器就绪) - ✅ Ingress 配置正确(路由规则正确) - ✅ Service 配置正确(Endpoints 正确) - ✅ NSG 规则已配置(允许 80/443 端口) - ✅ LoadBalancer 配置正确(从集群内部访问成功) **问题所在**: - ❌ 外部网络无法连接到 Azure LoadBalancer IP `40.65.173.54` **可能的原因**: 1. **NSG 规则可能只对集群内部生效** - 虽然规则显示 `sourceAddressPrefix: Internet`,但可能实际只允许集群内部访问 - 需要检查是否有其他限制 2. **Azure 订阅或资源组级别的网络策略** - 可能有订阅级别的网络限制 - 可能有资源组的网络策略 3. **外部网络到 Azure 的路径问题** - 可能是 ISP 或网络运营商的问题 - 可能是地理位置限制 4. **LoadBalancer 的源地址限制** - 虽然检查显示 `loadBalancerSourceRanges` 为空,但可能在其他地方有限制 **建议操作**: 1. ✅ 已确认 NSG 规则存在(优先级 501,允许 Internet 访问 80/443) 2. ⏳ 检查是否有更高优先级的 Deny 规则 3. ⏳ 在 Azure Portal 中检查 LoadBalancer 的详细配置 4. ⏳ 尝试从不同的外部网络测试(排除本地网络问题) 5. ⏳ 联系 Azure 支持检查是否有平台级别的限制