DEX and Amazonn ALB Load Balancer Controller and Argo Workflows

Viewed 21

I'm trying to build ALB -> Kube -> Dex using Load Balancer Controller. As a result, I have ALB with correctly binding instances into the target group, but the instance is Unhealthy.

The load Balancer Controller uses the 31845 as a health check port. A tried the port 5556, but still unhealthy.

So I can assume the setting is correct. But I'm not sure. Another possibility, the DEX container isn't set up correctly. And yet another version, I configured everything in the wrong way.

Does anyone have already configured DEX in this way and can prompt me?

Dex service

apiVersion: v1
kind: Service
metadata:
  name: dex
...
spec:
  ports:
    - name: http
      protocol: TCP
      appProtocol: http
      port: 5556
      targetPort: http
      nodePort: 31845
...
  selector:
    app.kubernetes.io/instance: dex
    app.kubernetes.io/name: dex
  clusterIP: 172.20.97.132
  clusterIPs:
    - 172.20.97.132
  type: NodePort
  sessionAffinity: None
  externalTrafficPolicy: Cluster
  ipFamilies:
    - IPv4
  ipFamilyPolicy: SingleStack
  internalTrafficPolicy: Cluster

DEX pod

  containerStatuses:
    - name: dex
      state:
        running:
          startedAt: '2022-09-19T17:41:43Z'
...
 containers:
    - name: dex
      image: ghcr.io/dexidp/dex:v2.34.0
      args:
        - dex
        - serve
        - '--web-http-addr'
        - 0.0.0.0:5556
        - '--telemetry-addr'
        - 0.0.0.0:5558
        - /etc/dex/config.yaml
      ports:
        - name: http
          containerPort: 5556
          protocol: TCP
        - name: telemetry
          containerPort: 5558
          protocol: TCP
      env:
        - name: ARGO_WORKFLOWS_SSO_CLIENT_SECRET

load Balancer Controller

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: ${name_http_ingress}
  namespace: ${namespace}
  labels:
    app.kubernetes.io/component: server
    app.kubernetes.io/instance: argo-cd
    app.kubernetes.io/part-of: argocd
    app.kubernetes.io/name: argocd-server
  annotations:
    alb.ingress.kubernetes.io/ingress.class: alb
    alb.ingress.kubernetes.io/backend-protocol: HTTP
    alb.ingress.kubernetes.io/backend-protocol-version: HTTP1
    alb.ingress.kubernetes.io/healthcheck-protocol: HTTP
    alb.ingress.kubernetes.io/healthcheck-port: traffic-port
    alb.ingress.kubernetes.io/healthcheck-path: /
    alb.ingress.kubernetes.io/healthcheck-timeout-seconds: '10'
    alb.ingress.kubernetes.io/unhealthy-threshold-count: '3'
    alb.ingress.kubernetes.io/success-codes: 200,301,302,307
    alb.ingress.kubernetes.io/conditions.argogrpc: >-
      [{"field":"http-header","httpHeaderConfig":{"httpHeaderName": "Content-Type", "values":["^application/grpc.*$"]}}]
    alb.ingress.kubernetes.io/listen-ports: '[{"HTTP": 80}, {"HTTPS": 443}]'
    alb.ingress.kubernetes.io/actions.ssl-redirect: >-
      {"type":"redirect","redirectConfig":{"port":"443","protocol":"HTTPS","statusCode":"HTTP_301"}}
    # external-dns.alpha.kubernetes.io/hostname: ${domain_name_public}
    alb.ingress.kubernetes.io/certificate-arn: ${domain_certificate}
    # alb.ingress.kubernetes.io/ssl-policy: ELBSecurityPolicy-TLS-1-2-Ext-2018-06
    alb.ingress.kubernetes.io/scheme: internet-facing
    alb.ingress.kubernetes.io/load-balancer-name: ${name_http_ingress}
    alb.ingress.kubernetes.io/target-type: instance
    # alb.ingress.kubernetes.io/target-type: ip # require to enable sticky sessions ,stickiness.enabled=true,stickiness.lb_cookie.duration_seconds=60
    alb.ingress.kubernetes.io/target-group-attributes: load_balancing.algorithm.type=least_outstanding_requests
    alb.ingress.kubernetes.io/target-node-labels: ${tolerations_key}=${tolerations_value}
    alb.ingress.kubernetes.io/tags: Environment=${tags_env},Restricted=false,Customer=customer,Project=ops,Name=${name_http_ingress}
    alb.ingress.kubernetes.io/load-balancer-attributes: routing.http2.enabled=true,idle_timeout.timeout_seconds=180

spec:
  ingressClassName: alb
  tls:
  - hosts:
    - ${domain_name_public}
    - ${domain_name_public_dex}
  rules:
    - host: ${domain_name_public}
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: ssl-redirect
                port:
                  name: use-annotation
    - host: ${domain_name_public_dex}
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: ssl-redirect
                port:
                  name: use-annotation

    - host: ${domain_name_public_dex}
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: dex
                port:
                  number: 5556
0 Answers
Related