nxsbi opened a new issue #4637:
URL: https://github.com/apache/cloudstack/issues/4637
<!--
Verify first that your issue/request is not already reported on GitHub.
Also test if the latest release and master branch are affected too.
Always add information AFTER of these HTML comments, but no need to delete
the comments.
-->
##### ISSUE TYPE
<!-- Pick one below and delete the rest -->
* Bug Report
##### COMPONENT NAME
<!--
Categorize the issue, e.g. API, VR, VPN, UI, etc.
-->
~~~
Kubernetes Service
~~~
##### CLOUDSTACK VERSION
<!--
New line separated list of affected versions, commit ID for issues on master
branch.
-->
~~~
4.15.0
~~~
##### CONFIGURATION
<!--
Information about the configuration if relevant, e.g. basic network,
advanced networking, etc. N/A otherwise
-->
Base install of 4.15.0 (upgraded from 4.11)
Kubernetes Service enabled
CoreOS template
community Kubernetes ISO (tried multiple from v 1.11.4 to 1.16.3)
Using Advanced Networking
User account uses Isolated Network (not L2 or Shared)
SSL is enabled for CS GUI, and System VMs
##### OS / ENVIRONMENT
<!--
Information about the environment if relevant, N/A otherwise
-->
CentOS 7 for Management Server
##### SUMMARY
<!-- Explain the problem/feature briefly -->
On a freshly upgraded version to Cloudstack 4.15 (from 4.11), when I create
Kubernetes Cluster (regardless of which version), the master and worker VMs are
getting created and running successfully, but after the Timeout setting
(default 3600 seconds) expires I see the state - "Error". Further more, under
the "Access" tab, I see "Kubernetes cluster kubeconfig not available
currently". I cannot download the config file/never becomes available.
This happens in Isolated Networks with source NAT enabled. I also tested on
a Shared Network on a VLAN directly on the router.
It seems the VMs are getting setup but something is getting blocked when
trying to check the status of the service. I have opened all ports for egress
in the Isolated Network. ( I can see the data load of 200+MB taking place on
the master and worker node via CS GUI)


##### STEPS TO REPRODUCE
<!--
For bugs, show exactly how to reproduce the problem, using a minimal
test-case. Use Screenshots if accurate.
For new features, show how the feature would be used.
-->
<!-- Paste example playbooks or commands between quotes below -->
~~~
~~~
<!-- You can also paste gist.github.com links for larger files -->
##### EXPECTED RESULTS
<!-- What did you expect to happen when running the steps above? -->
~~~
Kubernetes Service should show as Active
~~~
##### ACTUAL RESULTS
<!-- What actually happened? -->
<!-- Paste verbatim command output between quotes below -->
~~~
Kubernetes Service Shows as Error
~~~
----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
For queries about this service, please contact Infrastructure at:
[email protected]