lab 3.5 step 23 gets error validating "cilium-cni.yaml"
I am working through lab 16.2, attempting to get 2 more control planes installed. I am working through the lab 3.5 instructions and keep getting this error when running the kubectl apply to install cilium.
error: error validating "cilium-cni.yaml": error validating data: failed to download openapi: Get "https://k8scp:6443/openapi/v2?timeout=32s": dial tcp: lookup k8scp on 127.0.0.53:53: server misbehaving; if you choose to ignore these errors, turn validation off with --validate=false
I have verified I am not installing as root. I have also tried the helm install method. Same error either way on two different VMs now. What am I missing?
Answers
-
Hi @don.perkins,
Assuming you already have an operational cluster, with Cilium CNI plugin active, there is no need to re-install it anywhere else. The very first control plane node operates the CNI plugin for the entire cluster. The CNI plugin agents and the Pod network will expand onto the additional control plane nodes as they join the HA.
Regards,
-Chris0 -
great! thanks. so working from the lab instructions from lab 3.5 (installing the first control plane), for the SECOND and THIRD control planes, can I stop at step 17 after installing kubeadm, kubectl and kubelet?
0 -
Yes, @don.perkins.
0 -
Hello @chrispokorni I'm facing a similar issue as this except mine is occurring on the cp.
error: error validating "/home/student/LFS258/SOLUTIONS/s_03/cilium-cni.yaml": error validating data: failed to download openapi: Get "http://localhost:8080/openapi/v2?timeout=32s": dial tcp 127.0.0.1:8080: connect: connection refused; if you choose to ignore these errors, turn validation off with --validate=falseI'm running the command as a regular user. My instance is a GCP one following the lab guide.
0 -
Hi @ackuakud,
What entries do you have in your
hostsfiles (cp and worker respectively)?
What are the specs of your cluster? Which cloud or hypervisor provisions your VMs? What OS, how much CPU, RAM, disk size (fully allocated or dynamic)? How many network interfaces per VM?
What are the private IP addresses of your VMs?Regards,
-Chris0 -
i'm having the same issue. The cluster seems to init ok, stay up for a while and then randomly die and crash reboot.
I've checked what the labs say and my config seems to be correct
0 -
Hi @Zen42_fo,
What are the specs of your cluster? Which cloud or hypervisor provisions your VMs? What OS, how much CPU, RAM, disk size (fully allocated or dynamic)? How many network interfaces per VM?
What are the entries in yourhostsfiles (cp and worker respectively)? What are the private IP addresses of your VMs?Regards,
-Chris0 -
Hello @chrispokorni
The attached image is a copy of my hosts file on the cp
. I have not done anything on the worker node yet. I just set up the VM.Hypervisor - Google cloud
OS - Ubuntu 20.04.06
CPU - e2-standard-2 (2 vCPU 1 core)
RAM - 8gb
The CP instance is attached to 1 network interface.Private IPs for the VMs master - 10.3.0.2 ; worker - 10.3.0.3
Thank you.
-Dan0 -
Hi @ackuakud,
On GCP I would take a second look at the VPC/firewall configuration, to ensure all inbound traffic is allowed to the VM(s). That timeout seems to be a networking issue. Also, ensure the VMs have enough disk space, a minimum of 15-20GB, and install the recommended Ubuntu 24.04 LTS release.
What is the output of:
ls -la /home/student/LFS258/SOLUTIONS/s_03/
Regards,
-Chris0 -
Hello @chrispokorni I just ran the ls command here is the output.

For the storage I have 20gb
. I will doublecheck my Firewall rules. Thank you!0 -
Hi @ackuakud,
With the GCE VM private IP addresses 10.3.0.x, I would recommend resetting your cluster (run
kubeadm resetcommand asrooton the control plane node) and re-initializing (run the fullkubeadm init ...command asroot) after making a minor edit to thecilium-cni.yamlmanifest:- around line 222 update the value of
cluster-pool-ipv4-cidr: "192.168.0.0/16" - this cidr value should match the
podSubnet: 192.168.0.0/16value in thekubeadm-config.yamlmanifest
This will ensure the networking is properly defined for the cluster, and IP ranges do not overlap between VMs, Services, and Pods.
Regards,
-Chris0 - around line 222 update the value of
Categories
- All Categories
- 178 LFX Mentorship
- 178 LFX Mentorship: Linux Kernel
- 772 Linux Foundation IT Professional Programs
- 382 Cloud Engineer IT Professional Program
- 175 Advanced Cloud Engineer IT Professional Program
- 75 DevOps IT Professional Program - Discontinued
- 7 DevOps & GitOps IT Professional Program
- 102 Cloud Native Developer IT Professional Program
- 7.6K Training Courses & Learning Paths
- 9 AI & ML Training
- 1 Blockchain & Decentralized Identity Training
- 28 Cloud & Containers Training
- 3 Cybersecurity Training
- 2 DevOps & Site-Reliability Training
- 1 Linux Kernel Development Training
- 2 Networking Training
- 2 Open Source Best Practice Training
- 5 System Administration Training
- 1 System Engineering Training
- 4 Web & Application Development Training
- 797 Hardware
- 202 Drivers
- 68 I/O Devices
- 37 Monitors
- 96 Multimedia
- 173 Networking
- 91 Printers & Scanners
- 91 Storage
- 771 Linux Distributions
- 81 Debian
- 68 Fedora
- 23 Linux Mint
- 13 Mageia
- 24 openSUSE
- 151 Red Hat Enterprise
- 31 Slackware
- 13 SUSE Enterprise
- 356 Ubuntu
- 469 Linux System Administration
- 31 Cloud Computing
- 73 Command Line/Scripting
- Github systems admin projects
- 101 Linux Security
- 79 Network Management
- 101 System Management
- 46 Web Management
- 148 Mobile Computing
- 20 Android
- 113 Development
- 1.2K New to Linux
- 1K Getting Started with Linux
- 404 Off Topic
- 126 Introductions
- 34 Study Material
- 1K Programming and Development
- 310 Kernel Development
- 716 Software Development
- 1K Software
- 416 Applications
- 182 Command Line
- 5 Compiling/Installing
- 71 Games
- 320 Installation
- Archived
- 183 Small Talk
- 2 LFD140 Class Forum
- 1.4K LFS258 Class Forum
Upcoming Training
-
August 20, 2018
Kubernetes Administration (LFS458)
-
August 20, 2018
Linux System Administration (LFS301)
-
August 27, 2018
Open Source Virtualization (LFS462)
-
August 27, 2018
Linux Kernel Debugging and Security (LFD440)