5.6 KiB
5.6 KiB
OpenClaw Pod 访问问题诊断报告
问题描述
域名 test-openclaw-dns.taijiagnet.com 无法访问
诊断结果
✅ 正常的部分
-
Pod 状态正常
- Pod:
test-openclaw-dns-6c457fc9c8-p5pg5 - 命名空间:
agent-test-openclaw-dns - 状态:
Running (2/2)- 两个容器(gateway 和 dind)都在运行 - 容器就绪状态:
true true- 两个容器都已就绪
- Pod:
-
Pod 内部服务正常
- 从 Pod 内部访问
http://localhost:18789/health返回正常 HTML 响应 - 从 Pod 内部访问 Service
http://test-openclaw-dns-service:18789/health也正常
- 从 Pod 内部访问
-
Service 配置正确
- Service:
test-openclaw-dns-service - 类型:
ClusterIP - 端口:
18789/TCP - Endpoints:
10.224.0.8:18789✅ 正确指向 Pod
- Service:
-
Ingress 配置正确
- Ingress:
test-openclaw-dns-ingress - 域名:
test-openclaw-dns.taijiagnet.com - Backend:
test-openclaw-dns-service:18789 (10.224.0.8:18789)✅ - TLS: 已配置自签名证书
- Ingress IP:
40.65.173.54
- Ingress:
-
DNS 解析正常
test-openclaw-dns.taijiagnet.com正确解析到40.65.173.54- DNS 记录与 Ingress IP 一致
-
Ingress Controller 运行正常
- Ingress Controller Pods: 2 个都在运行
- Service:
ingress-nginx-controller(LoadBalancer) - LoadBalancer IP:
40.65.173.54 - 端口映射:
80:32519/TCP, 443:31651/TCP
❌ 问题所在
外部网络访问被阻止
从集群内部测试:
- ✅ Pod 内部访问正常
- ✅ Service 访问正常
- ❌ 外部访问
40.65.173.54:80超时 - ❌ 外部访问
40.65.173.54:443超时
根本原因:Azure 网络安全组(NSG)或防火墙规则阻止了 80/443 端口
解决方案
方案 1: 检查并更新 Azure 网络安全组(推荐)
- 在 Azure Portal 中找到 AKS 集群的资源组
- 找到与 LoadBalancer IP
40.65.173.54关联的网络安全组(NSG) - 添加入站规则:
- 端口 80 (HTTP): 允许来自
*的流量 - 端口 443 (HTTPS): 允许来自
*的流量
- 端口 80 (HTTP): 允许来自
方案 2: 使用 Azure CLI 检查 NSG 规则
# 查找 LoadBalancer 关联的 NSG
az network lb list --query "[?frontendIpConfigurations[0].publicIpAddress=='40.65.173.54']" -o table
# 查找并更新 NSG 规则
az network nsg rule list --nsg-name <nsg-name> --resource-group <rg-name> -o table
az network nsg rule create \
--resource-group <rg-name> \
--nsg-name <nsg-name> \
--name AllowHTTP \
--priority 100 \
--direction Inbound \
--access Allow \
--protocol Tcp \
--destination-port-ranges 80
az network nsg rule create \
--resource-group <rg-name> \
--nsg-name <nsg-name> \
--name AllowHTTPS \
--priority 101 \
--direction Inbound \
--access Allow \
--protocol Tcp \
--destination-port-ranges 443
方案 3: 检查 AKS 节点池的 NSG
# 查找节点池的 NSG
az aks show --name <aks-cluster-name> --resource-group <rg-name> --query "agentPoolProfiles[0].vnetSubnetId" -o tsv
# 然后查找该子网的 NSG 并更新规则
其他发现
配置版本警告(非关键)
- 日志显示:
Config was last written by a newer OpenClaw (2026.2.3); current version is 2026.1.30 - 这是配置版本不匹配的警告,不影响功能,但建议更新镜像版本
Readiness Probe 早期失败(已恢复)
- 在 Pod 启动初期有 readiness probe 失败
- 现在已经恢复正常,容器状态为
ready
验证步骤
修复 NSG 规则后,验证访问:
# 测试 HTTP 访问
curl -v http://test-openclaw-dns.taijiagnet.com/health
# 测试 HTTPS 访问(忽略自签名证书警告)
curl -k -v https://test-openclaw-dns.taijiagnet.com/health
重要发现
✅ 从集群内部访问成功
从 Kubernetes 集群内部测试访问 40.65.173.54:80 成功,返回了 308 重定向响应。这说明:
- LoadBalancer 配置正确 ✅
- Ingress Controller 工作正常 ✅
- 路由规则正确 ✅
- NSG 规则对集群内部生效 ✅
❌ 从外部网络访问失败
从外部网络访问 40.65.173.54:80 和 443 端口超时。这说明问题在于:
- 外部网络到 Azure LoadBalancer 的路径被阻止
总结
问题类型: 外部网络到 Azure 的网络连接问题
已确认正常的部分:
- ✅ DNS 绑定正常(DNS 解析正确)
- ✅ Pod 正常运行(2/2 容器就绪)
- ✅ Ingress 配置正确(路由规则正确)
- ✅ Service 配置正确(Endpoints 正确)
- ✅ NSG 规则已配置(允许 80/443 端口)
- ✅ LoadBalancer 配置正确(从集群内部访问成功)
问题所在:
- ❌ 外部网络无法连接到 Azure LoadBalancer IP
40.65.173.54
可能的原因:
-
NSG 规则可能只对集群内部生效
- 虽然规则显示
sourceAddressPrefix: Internet,但可能实际只允许集群内部访问 - 需要检查是否有其他限制
- 虽然规则显示
-
Azure 订阅或资源组级别的网络策略
- 可能有订阅级别的网络限制
- 可能有资源组的网络策略
-
外部网络到 Azure 的路径问题
- 可能是 ISP 或网络运营商的问题
- 可能是地理位置限制
-
LoadBalancer 的源地址限制
- 虽然检查显示
loadBalancerSourceRanges为空,但可能在其他地方有限制
- 虽然检查显示
建议操作:
- ✅ 已确认 NSG 规则存在(优先级 501,允许 Internet 访问 80/443)
- ⏳ 检查是否有更高优先级的 Deny 规则
- ⏳ 在 Azure Portal 中检查 LoadBalancer 的详细配置
- ⏳ 尝试从不同的外部网络测试(排除本地网络问题)
- ⏳ 联系 Azure 支持检查是否有平台级别的限制