haproxy for k8s api server returns PR_END_OF_FILE_ERRORHAProxy returns Bad Request (Invalid Host) for seemingly no reasonHAProxy: API on the same subdomain as frontendHAProxy usage with kubernetesHAProxy route based on API versionsHAProxy as reverse proxy for AWS API GatewayKube dns wont connect to the Kubernetes api processHow to configure API rate limit on HAproxy?metrics-server CrashLoopBackOff on k8s v1.11.1504 Gateway timeout Error when using SSL/K8S/fission serverlessEnable CORS for GKE Kubernetes API

Can the poison from Kingsmen be concocted?

How to project 3d image in the planes xy, xz, yz?

Taxi Services at Didcot

What risks are there when you clear your cookies instead of logging off?

Is using haveibeenpwned to validate password strength rational?

How to build suspense or so to establish and justify xenophobia of characters in the eyes of the reader?

Why doesn't Adrian Toomes give up Spider-Man's identity?

What makes Ada the language of choice for the ISS's safety-critical systems?

How much salt (or any other substance one can find in a kitchen) do I need to add to make water boil at 104 °C?

Trapping Rain Water

Argon vs nitrogen for preserving wine

Can a black dragonborn's acid breath weapon destroy objects?

Genetic limitations to learn certain instruments

Are "living" organ banks practical?

How did they achieve the Gunslinger's shining eye effect in Westworld?

Soft question: Examples where lack of mathematical rigour cause security breaches?

Do any instruments not produce overtones?

What is the giant octopus in the torture chamber for?

Why would future John risk sending back a T-800 to save his younger self?

Did the ending really happen in Baby Driver?

How to chain Python function calls so the behaviour is as follows

Why doesn’t a normal window produce an apparent rainbow?

Can an Aarakocra use a shield while flying?

How water is heavier than petrol eventhough its molecular weight less than petrol?



haproxy for k8s api server returns PR_END_OF_FILE_ERROR


HAProxy returns Bad Request (Invalid Host) for seemingly no reasonHAProxy: API on the same subdomain as frontendHAProxy usage with kubernetesHAProxy route based on API versionsHAProxy as reverse proxy for AWS API GatewayKube dns wont connect to the Kubernetes api processHow to configure API rate limit on HAproxy?metrics-server CrashLoopBackOff on k8s v1.11.1504 Gateway timeout Error when using SSL/K8S/fission serverlessEnable CORS for GKE Kubernetes API






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








0















I'm setting up haproxy for k8s api servers.
The configuration for haproxy is:



frontend k8s-https
log /dev/log local0 debug
option tcplog
bind 0.0.0.0:8443
mode tcp
default_backend k8s-https

backend k8s-https
mode tcp
balance roundrobin
server master-1 192.168.59.101:6443 check
server master-2 192.168.59.102:6443 check
server master-3 192.168.59.103:6443 check



When I curl port 6443, the api server response:



$ curl -1 -vvv -k https://192.168.59.101:6443/
* About to connect() to 192.168.59.101 port 6443 (#0)
* Trying 192.168.59.101...
* Connected to 192.168.59.101 (192.168.59.101) port 6443 (#0)
* Initializing NSS with certpath: sql:/etc/pki/nssdb
* skipping SSL peer certificate verification
* NSS: client certificate not found (nickname not specified)
* SSL connection using TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
* Server certificate:
* subject: CN=kube-apiserver,OU=Admin,O=Kubernetes,L=Beijing,ST=Bejing,C=CN
* start date: May 21 05:01:00 2019 GMT
* expire date: Apr 27 05:01:00 2119 GMT
* common name: kube-apiserver
* issuer: CN=Kubernetes,OU=CA,O=Kubernetes,L=Beijing,ST=Bejing,C=CN
> GET / HTTP/1.1
> User-Agent: curl/7.29.0
> Host: 192.168.59.101:6443
> Accept: */*
>
< HTTP/1.1 403 Forbidden
< Content-Type: application/json
< X-Content-Type-Options: nosniff
< Date: Tue, 21 May 2019 11:05:54 GMT
< Content-Length: 233
<

"kind": "Status",
"apiVersion": "v1",
"metadata":

,
"status": "Failure",
"message": "forbidden: User "system:anonymous" cannot get path "/"",
"reason": "Forbidden",
"details":

,
"code": 403
* Connection #0 to host 192.168.59.101 left intact



However, If I access the api through port 8443 (which the haproxy is listening on), it gives end of file error



$ curl -1 -vvv -k https://192.168.59.101:8443/
* About to connect() to 192.168.59.101 port 8443 (#0)
* Trying 192.168.59.101...
* Connected to 192.168.59.101 (192.168.59.101) port 8443 (#0)
* Initializing NSS with certpath: sql:/etc/pki/nssdb
* NSS error -5938 (PR_END_OF_FILE_ERROR)
* Encountered end of file
* Closing connection 0
curl: (35) Encountered end of file


Why the haproxy does not work?










share|improve this question




























    0















    I'm setting up haproxy for k8s api servers.
    The configuration for haproxy is:



    frontend k8s-https
    log /dev/log local0 debug
    option tcplog
    bind 0.0.0.0:8443
    mode tcp
    default_backend k8s-https

    backend k8s-https
    mode tcp
    balance roundrobin
    server master-1 192.168.59.101:6443 check
    server master-2 192.168.59.102:6443 check
    server master-3 192.168.59.103:6443 check



    When I curl port 6443, the api server response:



    $ curl -1 -vvv -k https://192.168.59.101:6443/
    * About to connect() to 192.168.59.101 port 6443 (#0)
    * Trying 192.168.59.101...
    * Connected to 192.168.59.101 (192.168.59.101) port 6443 (#0)
    * Initializing NSS with certpath: sql:/etc/pki/nssdb
    * skipping SSL peer certificate verification
    * NSS: client certificate not found (nickname not specified)
    * SSL connection using TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
    * Server certificate:
    * subject: CN=kube-apiserver,OU=Admin,O=Kubernetes,L=Beijing,ST=Bejing,C=CN
    * start date: May 21 05:01:00 2019 GMT
    * expire date: Apr 27 05:01:00 2119 GMT
    * common name: kube-apiserver
    * issuer: CN=Kubernetes,OU=CA,O=Kubernetes,L=Beijing,ST=Bejing,C=CN
    > GET / HTTP/1.1
    > User-Agent: curl/7.29.0
    > Host: 192.168.59.101:6443
    > Accept: */*
    >
    < HTTP/1.1 403 Forbidden
    < Content-Type: application/json
    < X-Content-Type-Options: nosniff
    < Date: Tue, 21 May 2019 11:05:54 GMT
    < Content-Length: 233
    <

    "kind": "Status",
    "apiVersion": "v1",
    "metadata":

    ,
    "status": "Failure",
    "message": "forbidden: User "system:anonymous" cannot get path "/"",
    "reason": "Forbidden",
    "details":

    ,
    "code": 403
    * Connection #0 to host 192.168.59.101 left intact



    However, If I access the api through port 8443 (which the haproxy is listening on), it gives end of file error



    $ curl -1 -vvv -k https://192.168.59.101:8443/
    * About to connect() to 192.168.59.101 port 8443 (#0)
    * Trying 192.168.59.101...
    * Connected to 192.168.59.101 (192.168.59.101) port 8443 (#0)
    * Initializing NSS with certpath: sql:/etc/pki/nssdb
    * NSS error -5938 (PR_END_OF_FILE_ERROR)
    * Encountered end of file
    * Closing connection 0
    curl: (35) Encountered end of file


    Why the haproxy does not work?










    share|improve this question
























      0












      0








      0








      I'm setting up haproxy for k8s api servers.
      The configuration for haproxy is:



      frontend k8s-https
      log /dev/log local0 debug
      option tcplog
      bind 0.0.0.0:8443
      mode tcp
      default_backend k8s-https

      backend k8s-https
      mode tcp
      balance roundrobin
      server master-1 192.168.59.101:6443 check
      server master-2 192.168.59.102:6443 check
      server master-3 192.168.59.103:6443 check



      When I curl port 6443, the api server response:



      $ curl -1 -vvv -k https://192.168.59.101:6443/
      * About to connect() to 192.168.59.101 port 6443 (#0)
      * Trying 192.168.59.101...
      * Connected to 192.168.59.101 (192.168.59.101) port 6443 (#0)
      * Initializing NSS with certpath: sql:/etc/pki/nssdb
      * skipping SSL peer certificate verification
      * NSS: client certificate not found (nickname not specified)
      * SSL connection using TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
      * Server certificate:
      * subject: CN=kube-apiserver,OU=Admin,O=Kubernetes,L=Beijing,ST=Bejing,C=CN
      * start date: May 21 05:01:00 2019 GMT
      * expire date: Apr 27 05:01:00 2119 GMT
      * common name: kube-apiserver
      * issuer: CN=Kubernetes,OU=CA,O=Kubernetes,L=Beijing,ST=Bejing,C=CN
      > GET / HTTP/1.1
      > User-Agent: curl/7.29.0
      > Host: 192.168.59.101:6443
      > Accept: */*
      >
      < HTTP/1.1 403 Forbidden
      < Content-Type: application/json
      < X-Content-Type-Options: nosniff
      < Date: Tue, 21 May 2019 11:05:54 GMT
      < Content-Length: 233
      <

      "kind": "Status",
      "apiVersion": "v1",
      "metadata":

      ,
      "status": "Failure",
      "message": "forbidden: User "system:anonymous" cannot get path "/"",
      "reason": "Forbidden",
      "details":

      ,
      "code": 403
      * Connection #0 to host 192.168.59.101 left intact



      However, If I access the api through port 8443 (which the haproxy is listening on), it gives end of file error



      $ curl -1 -vvv -k https://192.168.59.101:8443/
      * About to connect() to 192.168.59.101 port 8443 (#0)
      * Trying 192.168.59.101...
      * Connected to 192.168.59.101 (192.168.59.101) port 8443 (#0)
      * Initializing NSS with certpath: sql:/etc/pki/nssdb
      * NSS error -5938 (PR_END_OF_FILE_ERROR)
      * Encountered end of file
      * Closing connection 0
      curl: (35) Encountered end of file


      Why the haproxy does not work?










      share|improve this question














      I'm setting up haproxy for k8s api servers.
      The configuration for haproxy is:



      frontend k8s-https
      log /dev/log local0 debug
      option tcplog
      bind 0.0.0.0:8443
      mode tcp
      default_backend k8s-https

      backend k8s-https
      mode tcp
      balance roundrobin
      server master-1 192.168.59.101:6443 check
      server master-2 192.168.59.102:6443 check
      server master-3 192.168.59.103:6443 check



      When I curl port 6443, the api server response:



      $ curl -1 -vvv -k https://192.168.59.101:6443/
      * About to connect() to 192.168.59.101 port 6443 (#0)
      * Trying 192.168.59.101...
      * Connected to 192.168.59.101 (192.168.59.101) port 6443 (#0)
      * Initializing NSS with certpath: sql:/etc/pki/nssdb
      * skipping SSL peer certificate verification
      * NSS: client certificate not found (nickname not specified)
      * SSL connection using TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
      * Server certificate:
      * subject: CN=kube-apiserver,OU=Admin,O=Kubernetes,L=Beijing,ST=Bejing,C=CN
      * start date: May 21 05:01:00 2019 GMT
      * expire date: Apr 27 05:01:00 2119 GMT
      * common name: kube-apiserver
      * issuer: CN=Kubernetes,OU=CA,O=Kubernetes,L=Beijing,ST=Bejing,C=CN
      > GET / HTTP/1.1
      > User-Agent: curl/7.29.0
      > Host: 192.168.59.101:6443
      > Accept: */*
      >
      < HTTP/1.1 403 Forbidden
      < Content-Type: application/json
      < X-Content-Type-Options: nosniff
      < Date: Tue, 21 May 2019 11:05:54 GMT
      < Content-Length: 233
      <

      "kind": "Status",
      "apiVersion": "v1",
      "metadata":

      ,
      "status": "Failure",
      "message": "forbidden: User "system:anonymous" cannot get path "/"",
      "reason": "Forbidden",
      "details":

      ,
      "code": 403
      * Connection #0 to host 192.168.59.101 left intact



      However, If I access the api through port 8443 (which the haproxy is listening on), it gives end of file error



      $ curl -1 -vvv -k https://192.168.59.101:8443/
      * About to connect() to 192.168.59.101 port 8443 (#0)
      * Trying 192.168.59.101...
      * Connected to 192.168.59.101 (192.168.59.101) port 8443 (#0)
      * Initializing NSS with certpath: sql:/etc/pki/nssdb
      * NSS error -5938 (PR_END_OF_FILE_ERROR)
      * Encountered end of file
      * Closing connection 0
      curl: (35) Encountered end of file


      Why the haproxy does not work?







      haproxy kubernetes






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked May 21 at 11:07









      cgcgbcbccgcgbcbc

      28427




      28427




















          1 Answer
          1






          active

          oldest

          votes


















          0














          Finally I figure out that the issue is caused by centos 7's default SELinux policy, by temporary disable it with sudo setenforce 0, it works.






          share|improve this answer























            Your Answer








            StackExchange.ready(function()
            var channelOptions =
            tags: "".split(" "),
            id: "2"
            ;
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function()
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled)
            StackExchange.using("snippets", function()
            createEditor();
            );

            else
            createEditor();

            );

            function createEditor()
            StackExchange.prepareEditor(
            heartbeatType: 'answer',
            autoActivateHeartbeat: false,
            convertImagesToLinks: true,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            imageUploader:
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            ,
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            );



            );













            draft saved

            draft discarded


















            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f968212%2fhaproxy-for-k8s-api-server-returns-pr-end-of-file-error%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown

























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes









            0














            Finally I figure out that the issue is caused by centos 7's default SELinux policy, by temporary disable it with sudo setenforce 0, it works.






            share|improve this answer



























              0














              Finally I figure out that the issue is caused by centos 7's default SELinux policy, by temporary disable it with sudo setenforce 0, it works.






              share|improve this answer

























                0












                0








                0







                Finally I figure out that the issue is caused by centos 7's default SELinux policy, by temporary disable it with sudo setenforce 0, it works.






                share|improve this answer













                Finally I figure out that the issue is caused by centos 7's default SELinux policy, by temporary disable it with sudo setenforce 0, it works.







                share|improve this answer












                share|improve this answer



                share|improve this answer










                answered May 21 at 11:21









                cgcgbcbccgcgbcbc

                28427




                28427



























                    draft saved

                    draft discarded
















































                    Thanks for contributing an answer to Server Fault!


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid


                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.

                    To learn more, see our tips on writing great answers.




                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function ()
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f968212%2fhaproxy-for-k8s-api-server-returns-pr-end-of-file-error%23new-answer', 'question_page');

                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    Popular posts from this blog

                    Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

                    Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

                    Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020