In this section you will find common problems and their solutions or workarounds. In general, it's always a good start to check the vcluster and syncer logs via kubectl:
The problem is that SSL termination does happen at the ingress controller level and not at vcluster itself. By default, vcluster uses client cert authentication, which will be sent to the ingress controller and the ingress controller will then forward the request to vcluster, but without the client cert, which causes the error. There are possible solutions to this problem:
- Use SSL pass through for your ingress controller as described here. Make sure you do not have
- Use service account authentication instead of client-cert and client-key described here
You have a folder or file called vcluster in the current working directory. This is a known helm problem, where helm thinks this is a chart directory. The solution is to install vcluster in a folder where no other folder or file with the name of vcluster is present.
Looks like this might be a problem with the kubelet configuration, you can find more information about this problem at the core dns documentation.
The solution is to disable ingress sync with a
And then either upgrading or recreating the vcluster with: