Empresas
Empleos
  • Sobre nosotros
  • Soluciones
    • Publicación de vacantes
      Publica tu vacante y recibe candidatos calificados en 48h.
    • Evaluación de candidatos
      500+ pruebas técnicas y psicológicas, más anti-fraude.
    • Headhunting
      Búsqueda ejecutiva a la medida de principio a fin.
    • Nómina + EOR
      Dispersión de nómina y EOR en más de 15 países de LATAM.
  • Precios
  • Empleos

0

557
Vistas
kOps 1.19 reports error "Unauthorized" when interfacing with AWS cluster

I'm following the kOps tutorial to set up a cluster on AWS. I am able to create a cluster with

kops create cluster
kops update cluster --yes

However, when validating whether my cluster is set up correctly with

kops validate cluster

I get stuck with error:

unexpected error during validation: error listing nodes: Unauthorized

The same error happens in many other kOps operations.

I checked my kOps/K8s version and it is 1.19:

> kops version
Version 1.19.1 (git-8589b4d157a9cb05c54e320c77b0724c4dd094b2)

> kubectl version
Client Version: version.Info{Major:"1", Minor:"20" ...
Server Version: version.Info{Major:"1", Minor:"19" ...

How can I fix this?

over 4 years ago · Santiago Trujillo
2 Respuestas
Responde la pregunta

0

As of kOps 1.19 there are two reasons you will suddenly get this error:

  1. If you delete a cluster and reprovision it, your old admin is not removed from the kubeconfig and kOps/kubectl tries to reuse it.
  2. New certificates have a TTL of 18h by default, so you need to reprovision them about once a day.

Both issues above are fixed by running kops export kubecfg --admin.

Note that using the default TLS credentials is discouraged. Consider things like using an OIDC provider instead.

over 4 years ago · Santiago Trujillo Denunciar

0

Kubernetes v1.19 removed basic auth support, incidentally making the default kOps credentials unable to authorize. To work around this, we will update our cluster to use a Network Load Balancer (NLB) instead of the default Classic Load Balancer (CLB). The NLB can be accessed with non-deprecated AuthZ mechanisms.

After creating your cluster, but before updating cloud resources (before running with --yes), edit its configuration to use a NLB:

kops edit cluster

Then update your load balancer class to Network:

spec:
  api:
    loadBalancer:
      class: Network

Now update cloud resources with

kops update cluster --yes

And you'll be able to pass AuthZ with kOps on your cluster.

Note that there are several other advantages to using an NLB as well, check the AWS docs for a comparison.

If you have a pre-existing cluster you want to update to a NLB, there are more steps to follow to ensure clients don't start failing AuthZ, to delete old resources, etc. You'll find a better guide for that in the kOps v1.19 release notes.

over 4 years ago · Santiago Trujillo Denunciar
Responde la pregunta
Encuentra empleos remotos

¡Descubre la nueva forma de encontrar empleo!

Top de empleos
Top categorías de empleo
Empresas
Publicar vacante Precios Comercial
Legal
Términos y condiciones Política de privacidad
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Recomiéndame algunas ofertas
Necesito ayuda