http proxy fails to resolve name when accessed from client in another kubernetes namespace

Viewed 319

the problem can be summarized in this way:

a client (curl) is deployed in a namespace "tx" and both a HTTP proxy (squid) and a server (nginx) are deployed in a namespace "rx".

Squid has been installed with default configuration and listens to port 3128. I consider the test successful when curl return 200 and prints the nginx welcome message.

This command executes successfully from the client pod:

curl http://nginx.tx.svc.cluster.local

and this one does not - as expected because the requested service is another namespace:

curl http://nginx

This command however executes successfully from the squid proxy because it is in the same namespace:

curl http://nginx

Finally this command fails when it is run from the client pod:

curl --proxy <squid-proxy-IP>:3128 http://nginx

Output is:

...
<p>The DNS server returned:</p>
<blockquote id="data">
<pre>Name Error: The domain name does not exist.</pre>
</blockquote>

<p>This means that the cache was not able to resolve the hostname presented in the URL. Check if the address is correct.</p>
...
<hr>
<div id="footer">
<p>Generated Mon, 09 Aug 2021 13:15:51 GMT by squid-photon-65fff6d4bd-cwclg (squid)</p>
<!-- ERR_DNS_FAIL -->
</div>
</body></html>

To recap: why the host "nginx" can be resolved when executing curl from the squid pod but the same host cannot be resolved by the http proxy executing in the same pod ?

Thanks

0 Answers
Related