Lab 11.2 Ingress Controller - connection refused on public ip address
I have installed Kubernetes on two Google cloud VM instances. Each node has a public IP address.
I have been through all the lessons and labs step by step and everything has worked correctly and matched the lab output until I got to lab 11.2 Ingress Controller. Everything is working except that the curl command to the public IP address from outside of the cluster is refused.
curl -H "Host: internal.org" [xxx.xxx.xxx.xxx]
curl: (7) Failed to connect to [xxx.xxx.xxx.xxx] port 80: Connection refused
Linkerd is running and accessible at that same IP address (on port 31500). I can ping the public IP address. I followed the early instructions for adding a firewall rule to allow traffic on all ports.
The NGINX ingress controller is installed, but shows a EXTERNAL-IP. I don't know if that's normal because the lab PDF never shows anything different. It doesn't seem correct, though.
default service/myingress-ingress-nginx-controller LoadBalancer 10.111.7.242 80:30499/TCP,443:32138/TCP 93m
default service/myingress-ingress-nginx-controller-admission ClusterIP 10.100.37.237 443/TCP 93m
Can anyone help me figure out what I've missed?
Comments
-
Hi @spongocoel,
Do you have the output where the nginx ingress controller service shows the external IP assigned to it?
When validating that the nginx ingress pods are running, do you see them distributed as node agents, where each node is running exactly one
myingress
pod?Is this behavior observed only when testing ingress to the
internal
service? What about theexternal
service?Are you curling straight to the IP address, or do you have
http://
prefixing it?When curling to a node IP address (private or public), keep in mind you are exposing the service as a NodePort, so the node IP alone will not work, you'd need to provide the high NodePort value with
curl
.Regards,
-Chris0 -
The ingress controller service does not show an external IP address. I just realized that earlier I wrote "shows a EXTERNAL-IP" when I meant to say "shows no EXTERNAL-IP":
$ kubectl get service -A | grep myingress
default myingress-ingress-nginx-controller LoadBalancer 10.111.7.242 80:30499/TCP,443:32138/TCP 24h
default myingress-ingress-nginx-controller-admission ClusterIP 10.100.37.237 443/TCP 24hThere is an nginx ingress pod running on both nodes:
$ kubectl get pod -A -o=wide | grep myingress
default myingress-ingress-nginx-controller-gz8cb 2/2 Running 2 24h 192.168.171.75 worker
default myingress-ingress-nginx-controller-tpx4x 2/2 Running 2 24h 192.168.219.127 masterBoth of these calls from the master or worker node return the correct html response from the web server:
curl -H "Host: internal.org" http://10.111.7.242
curl -H "Host:www.external.com" http://10.111.7.242Curling to the public ip address of either node, with or without "http://" prefixed results in a "connection refused". I've tried it from the master node of the cluster as well as from my laptop.
My understanding is that I am curling to the public ip address of the nodes in the cluster, and that the ingress service is exposed as a LoadBalancer type. I think the point is to allow access to the cluster on port 80 and via the ingress rules, route to the appropriate pod to respond to the request. The goal, as I understand it, is to not have to use a "weird" high numbered port to serve http requests from the cluster.
I don't see, however, how the node's port 80 is routed to the cluster. I assumed that was part of the ingress controller install, or was part of the Linkerd install (I still don't understand exactly what that install was for).
Thanks for your help. I really appreciate it.
- Scott
0 -
I just realized the forum software is eating text within angle brackets. The service external ip address was being removed from the output. I'll try again, replacing angle brackets with square brackets:
$ kubectl get service -A | grep myingress
default myingress-ingress-nginx-controller LoadBalancer 10.111.7.242 [pending] 80:30499/TCP,443:32138/TCP 25h
default myingress-ingress-nginx-controller-admission ClusterIP 10.100.37.237 [none] 443/TCP 25h0 -
Hi @spongocoel,
Thanks for clarifying.
A LoadBalancer type service, without an actual external load balancer (which is expected in our scenario), will behave as a typical NodePort type service. When attempting to access such a service on public or private node IP addresses, the NodePort needs to be specified as well
curl IPaddress:nodeport
Regards,
-Chris0 -
When you say that an external load balancer is expected, is that something I missed in the coursework? Do I need to install something separately for that? Is it covered in the course?
I'm using Google Cloud Platform VMs since that was suggested in the early course materials.
The lab exercises were written and tested using Ubuntu instances running on Google Cloud Platform.
Is that learning I need to do independently, outside of the course?
0 -
Hi @spongocoel,
There is no load balancer included in the lab work, which is the reason why the External-IP field of the service remains in a pending state.
Regards,
-Chris0 -
I got a similar problem starting from today on lab 11.2
curl -H "Host: www.external.com" x.x.x.x always return 404 Not Found error.
curl -H "Host: internal.org" x.x.x.x also return the same error.For the past 2 weeks I didn't encounter this problem...
The one I pulled this morning, by default, is ingress-nginx-4.0.1.tgz
The problem is solved after pulling an older version: helm fetch --version 3.36.0 ingress/ingress-nginxFYI:
https://artifacthub.io/packages/helm/ingress-nginx/ingress-nginx
4.0.1 24 Aug, 2021
3.36.0 22 Aug, 2021My lab is a KVM with 3 Ubuntu 18.04.5 LTS running on a LM 20.1 wtih 32GB RAM computer...
0 -
Hi @proliant,
Thank you for your feedback. I have seen similar issues reported on and off with various versions of the ingress-nginx helm chart, that seem to be related to the configuration of the chart.
Regards,
-Chris0 -
Hi,
I ran into the same issue
curl -H "Host: www.external.com" x.x.x.x always return 404 Not Found error.
I found out that the newest version of the ingress-nginx controller (4.0.x) requires some additional infos in the yaml file of the Ingress resource!
According to the lab documenation the yaml should look like this:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: ingress-test namespace: default spec: rules: - host: www.external.com (...)
That it is not enough anymore!
With 4.0.x you need to declare the "ingress.class" !!
So you need to add the following annotation ;-)apiVersion: networking.k8s.io/v1 kind: Ingress metadata: annotations: kubernetes.io/ingress.class: nginx name: ingress-test namespace: default spec: rules: (...)
annotations:
kubernetes.io/ingress.class: nginxdoes the trick even with 4.0.x
Hope this helps others and the author of the lab documentation incoperates this update.
Cheers, Michael
2 -
Appreciate the feedback. Indeed there was a breaking change recently. We will update the material and get a new version out soon.
Regards,
0 -
Hi,
The material doesn't seem to be updated. I followed the labs closely and was stuck for two hours until I realized the ingestStorageClass annotation/field was missing.Just a kind reminder to put a note about IngestClass in the material.
Regards,
0 -
asdf
0 -
Please update the material.. I don't understand why I had to get stuck here for an hour when this is known since last year September...
0 -
Putting it here as well, update this! Run some CI on your documentation. The material costs a comfy penny, surely you can put some CI in place? Devops mentality for your documentation as well please.
0
Categories
- All Categories
- 167 LFX Mentorship
- 219 LFX Mentorship: Linux Kernel
- 795 Linux Foundation IT Professional Programs
- 355 Cloud Engineer IT Professional Program
- 179 Advanced Cloud Engineer IT Professional Program
- 82 DevOps Engineer IT Professional Program
- 127 Cloud Native Developer IT Professional Program
- 112 Express Training Courses
- 138 Express Courses - Discussion Forum
- 6.2K Training Courses
- 48 LFC110 Class Forum - Discontinued
- 17 LFC131 Class Forum
- 35 LFD102 Class Forum
- 227 LFD103 Class Forum
- 14 LFD110 Class Forum
- 39 LFD121 Class Forum
- 15 LFD133 Class Forum
- 7 LFD134 Class Forum
- 17 LFD137 Class Forum
- 63 LFD201 Class Forum
- 3 LFD210 Class Forum
- 5 LFD210-CN Class Forum
- 2 LFD213 Class Forum - Discontinued
- 128 LFD232 Class Forum - Discontinued
- 1 LFD233 Class Forum
- 2 LFD237 Class Forum
- 23 LFD254 Class Forum
- 697 LFD259 Class Forum
- 109 LFD272 Class Forum
- 3 LFD272-JP クラス フォーラム
- 10 LFD273 Class Forum
- 154 LFS101 Class Forum
- 1 LFS111 Class Forum
- 1 LFS112 Class Forum
- 1 LFS116 Class Forum
- 1 LFS118 Class Forum
- LFS120 Class Forum
- 7 LFS142 Class Forum
- 7 LFS144 Class Forum
- 3 LFS145 Class Forum
- 1 LFS146 Class Forum
- 3 LFS147 Class Forum
- 1 LFS148 Class Forum
- 15 LFS151 Class Forum
- 1 LFS157 Class Forum
- 33 LFS158 Class Forum
- 8 LFS162 Class Forum
- 1 LFS166 Class Forum
- 1 LFS167 Class Forum
- 3 LFS170 Class Forum
- 2 LFS171 Class Forum
- 1 LFS178 Class Forum
- 1 LFS180 Class Forum
- 1 LFS182 Class Forum
- 1 LFS183 Class Forum
- 29 LFS200 Class Forum
- 736 LFS201 Class Forum - Discontinued
- 2 LFS201-JP クラス フォーラム
- 14 LFS203 Class Forum
- 102 LFS207 Class Forum
- 1 LFS207-DE-Klassenforum
- 1 LFS207-JP クラス フォーラム
- 301 LFS211 Class Forum
- 55 LFS216 Class Forum
- 48 LFS241 Class Forum
- 42 LFS242 Class Forum
- 37 LFS243 Class Forum
- 15 LFS244 Class Forum
- LFS245 Class Forum
- LFS246 Class Forum
- 50 LFS250 Class Forum
- 1 LFS250-JP クラス フォーラム
- LFS251 Class Forum
- 154 LFS253 Class Forum
- LFS254 Class Forum
- LFS255 Class Forum
- 5 LFS256 Class Forum
- 1 LFS257 Class Forum
- 1.3K LFS258 Class Forum
- 10 LFS258-JP クラス フォーラム
- 111 LFS260 Class Forum
- 159 LFS261 Class Forum
- 41 LFS262 Class Forum
- 82 LFS263 Class Forum - Discontinued
- 15 LFS264 Class Forum - Discontinued
- 11 LFS266 Class Forum - Discontinued
- 20 LFS267 Class Forum
- 24 LFS268 Class Forum
- 29 LFS269 Class Forum
- 1 LFS270 Class Forum
- 199 LFS272 Class Forum
- 1 LFS272-JP クラス フォーラム
- LFS274 Class Forum
- 3 LFS281 Class Forum
- 9 LFW111 Class Forum
- 261 LFW211 Class Forum
- 182 LFW212 Class Forum
- 13 SKF100 Class Forum
- 1 SKF200 Class Forum
- 1 SKF201 Class Forum
- 782 Hardware
- 198 Drivers
- 68 I/O Devices
- 37 Monitors
- 96 Multimedia
- 174 Networking
- 91 Printers & Scanners
- 83 Storage
- 758 Linux Distributions
- 80 Debian
- 67 Fedora
- 15 Linux Mint
- 13 Mageia
- 23 openSUSE
- 143 Red Hat Enterprise
- 31 Slackware
- 13 SUSE Enterprise
- 348 Ubuntu
- 461 Linux System Administration
- 39 Cloud Computing
- 70 Command Line/Scripting
- Github systems admin projects
- 90 Linux Security
- 77 Network Management
- 101 System Management
- 46 Web Management
- 64 Mobile Computing
- 17 Android
- 34 Development
- 1.2K New to Linux
- 1K Getting Started with Linux
- 371 Off Topic
- 114 Introductions
- 174 Small Talk
- 19 Study Material
- 507 Programming and Development
- 285 Kernel Development
- 204 Software Development
- 1.8K Software
- 211 Applications
- 180 Command Line
- 3 Compiling/Installing
- 405 Games
- 309 Installation
- 97 All In Program
- 97 All In Forum
Upcoming Training
-
August 20, 2018
Kubernetes Administration (LFS458)
-
August 20, 2018
Linux System Administration (LFS301)
-
August 27, 2018
Open Source Virtualization (LFS462)
-
August 27, 2018
Linux Kernel Debugging and Security (LFD440)