Troubleshoot ALB Ingress Controller add-on update precheck failures

Updated at:

A precheck runs before the ALB Ingress Controller add-on is updated, and it fails when the configurations on the Application Load Balancer (ALB) console no longer match your AlbConfig or Ingress resources. Use the reported error message to identify the cause and apply the corresponding fix.

Usage notes

Before the add-on update

Before you update the ALB Ingress Controller add-on, review the new features of the add-on. For more information, see ALB Ingress controller.

  1. Before you run the precheck, run the kubectl get event command to check whether reconciliation failure events exist in the cluster. If such events exist, fix the failures and make sure that reconciliation completes. If you cannot identify the cause of a reconciliation failure, submit a ticket to contact technical support.

  2. Make sure that the configurations on the ALB console are consistent with the AlbConfig resource and the Ingress resource. If you manually modify resources such as Application Load Balancer (ALB) instances, listeners, forwarding rules, network access control lists (ACLs), or server groups on the ALB console before the precheck, the configurations on the ALB console become inconsistent with the AlbConfig or Ingress resource, and the precheck fails. If the two sides are inconsistent, align them in one of the following ways before you start the update:

    • To use the configurations on the ALB console, modify the AlbConfig or Ingress resource to match the configurations on the ALB console.

    • To use the configurations in the AlbConfig or Ingress resource, update the ALB console in one of the following ways:

      • Run the kubectl edit command and modify a non-critical field in the AlbConfig or Ingress resource to trigger a reconciliation. The configurations on the ALB console are updated accordingly.

      • Modify the configurations on the ALB console to match the AlbConfig or Ingress resource. After you modify the configurations on the ALB console, you must enable the configuration read-only mode for the ALB instance. For more information, see Enable or disable the configuration read-only mode.

During the add-on update

During the precheck, do not modify the AlbConfig or Ingress resource. Otherwise, the precheck result may be inaccurate. If you have modified either resource, rerun the precheck. If the precheck still fails after multiple attempts, submit a ticket for assistance.

Precheck errors and solutions

The following tables group the error messages by ALB resource type. Each error message has two solutions, and which one applies depends on whether the affected resource was modified manually on the ALB console before the precheck. After you apply a solution and rerun the precheck, view the Check Report again to confirm the result. The two scenarios are as follows:

  • Scenario 1: no manual changes — The affected resource was not modified manually on the ALB console before the precheck. Rerun the precheck and do not modify the resource during the precheck.

  • Scenario 2: manual changes — The affected resource was modified manually on the ALB console before the precheck. Align the configurations on the ALB console with the AlbConfig or Ingress resource, and then rerun the precheck.

ALB instance-related errors

Error message

Cause

Solution (scenario 1: no manual changes)

Solution (scenario 2: manual changes)

CreateALB, ReuseALB, UnReuseALB, DeleteALB

The configuration of the ALB instance is inconsistent with the AlbConfig resource.

Rerun the precheck and do not modify the AlbConfig resource during the precheck.

Align the configuration of the ALB instance with the AlbConfig resource, and then rerun the precheck.

UpdateALBAttribute

The Attribute configuration of the ALB instance, which includes the ALB instance name and the configuration read-only mode status, is inconsistent with the AlbConfig resource.

Rerun the precheck and do not modify the AlbConfig resource during the precheck.

Run the kubectl describe albconfig [$Albconfig_Name] command to compare the Attribute configurations of the ALB instance and the AlbConfig resource. Restore the Attribute configuration of the ALB instance on the ALB console, and then rerun the precheck.

UpdateALBDeletionProtection

The deletion protection configuration of the ALB instance is inconsistent with the AlbConfig resource.

Rerun the precheck and do not modify the AlbConfig resource during the precheck.

Run the kubectl describe albconfig [$Albconfig_Name] command to compare the deletion protection status of the ALB instance with the AlbConfig resource. Restore the deletion protection configuration of the ALB instance on the ALB console, and then rerun the precheck.

UpdateALBAccessLog

The access log configuration of the ALB instance is inconsistent with the AlbConfig resource.

Rerun the precheck and do not modify the AlbConfig resource during the precheck.

Align the access log configuration of the ALB instance with the AlbConfig resource, and then rerun the precheck. To use the access log configuration on the ALB console instead, run the kubectl edit albconfig [$Albconfig_Name] command to update the access log configuration in the AlbConfig resource, and then rerun the precheck.

UpdateALBEdition

The edition of the ALB instance, which is Standard or WAF Enabled, is inconsistent with the AlbConfig resource.

Rerun the precheck and do not modify the AlbConfig resource during the precheck.

Align the edition of the ALB instance with the AlbConfig resource, and then rerun the precheck.

UpdateALBResourceGroup

The resource group configuration of the ALB instance is inconsistent with the AlbConfig resource.

Rerun the precheck and do not modify the AlbConfig resource during the precheck.

Align the resource group configuration of the ALB instance with the AlbConfig resource, and then rerun the precheck.

UpdateALBTag

The tag configuration of the ALB instance is inconsistent with the AlbConfig resource.

Rerun the precheck and do not modify the AlbConfig resource during the precheck.

Align the tag configuration of the ALB instance with the AlbConfig resource, and then rerun the precheck.

UpdateALBAddressType

The network type configuration of the ALB instance is inconsistent with the AlbConfig resource.

Rerun the precheck and do not modify the AlbConfig resource during the precheck.

Align the network type of the ALB instance with the AlbConfig resource, and then rerun the precheck. To use the network type on the ALB console instead, run the kubectl edit albconfig [$Albconfig_Name] command to modify the AlbConfig resource, and then rerun the precheck. Before you change the network type, review the warning that follows this table.

UpdateALBBandWidthPackage

The shared bandwidth package configuration of the ALB instance is inconsistent with the AlbConfig resource.

Rerun the precheck and do not modify the AlbConfig resource during the precheck.

Align the shared bandwidth package configuration of the ALB instance with the AlbConfig resource, and then rerun the precheck. To use the shared bandwidth package configuration on the ALB console instead, run the kubectl edit albconfig [$Albconfig_Name] command to modify the AlbConfig resource, and then rerun the precheck.

Important

Changing the network type of the ALB instance from a private network to a public network involves changes to Elastic IP Addresses (EIPs) and incurs fees. Changing the network type from a public network to a private network disassociates all EIPs and modifies DNS resolution. Proceed with caution in both directions.

Listener-related errors

Error message

Cause

Solution (scenario 1: no manual changes)

Solution (scenario 2: manual changes)

CreateALBListener

The listener configuration of the ALB instance is inconsistent with the AlbConfig resource.

Rerun the precheck and do not modify the listener during the precheck.

Add the deleted listener back to the ALB instance, and then rerun the precheck. To use the listener configuration on the ALB console instead, run the kubectl edit albconfig [$Albconfig_Name] command to delete the listener from the AlbConfig resource, and then rerun the precheck.

UpdateALBListenerExtraCertificates

The additional certificate configuration of the listener on the ALB instance is inconsistent with the AlbConfig resource.

Rerun the precheck and do not modify the listener during the precheck.

Align the additional certificate configuration of the listener with the AlbConfig resource, and then rerun the precheck. To use the additional certificate configuration on the ALB console instead, run the kubectl edit albconfig [$Albconfig_Name] command to modify the AlbConfig resource, and then rerun the precheck.

UpdateALBListenerAttribute

The listener attribute configuration of the ALB instance is inconsistent with the AlbConfig resource.

Rerun the precheck and do not modify the listener during the precheck.

Identify the inconsistent listener attributes, such as the certificate, compression algorithm, access control policy, idle connection timeout, and XForwardedForConfig, and then rerun the precheck. To use the listener configuration on the ALB console instead, run the kubectl edit albconfig [$Albconfig_Name] command to modify the listener configuration in the AlbConfig resource, and then rerun the precheck.

DeleteALBListener

The listener configuration of the ALB instance is inconsistent with the AlbConfig resource.

Rerun the precheck and do not modify the listener during the precheck.

On the ALB console, delete the listener that was added, and then rerun the precheck. To use the listener configuration on the ALB console instead, run the kubectl edit albconfig [$Albconfig_Name] command to add the listener to the AlbConfig resource, and then rerun the precheck.

Network ACL-related errors

Error message

Cause

Solution (scenario 1: no manual changes)

Solution (scenario 2: manual changes)

CreateAcl, DeleteAcl, AddEntriesToAcl, RemoveEntriesFromAcl, AssociateAclWithListener, DisassociateAclWithListener

The network ACL configuration is inconsistent with the access control policy configuration in the AlbConfig resource.

Rerun the precheck and do not modify the network ACL during the precheck.

Align the network ACL configuration on the ALB console with the AlbConfig resource, and then rerun the precheck. To use the access control policy configuration of the network ACL on the ALB console instead, run the kubectl edit albconfig [$Albconfig_Name] command to update the corresponding access control policy group in the AlbConfig resource, and then rerun the precheck.

Forwarding rule-related errors

Error message

Cause

Solution (scenario 1: no manual changes)

Solution (scenario 2: manual changes)

CreateALBListenerRules

The forwarding rule configuration of the ALB instance is inconsistent with the Ingress resource.

Rerun the precheck and do not modify the forwarding rules during the precheck.

Add the deleted forwarding rule back, and then rerun the precheck.

UpdateALBListenerRules

The forwarding rule configuration of the ALB instance is inconsistent with the Ingress resource.

Rerun the precheck and do not modify the forwarding rules during the precheck.

Align the forwarding rule configuration of the ALB instance with the Ingress resource, and then rerun the precheck. To use the forwarding rule configuration on the ALB console instead, run the kubectl -n [$Namespace] edit ingress [$Ingress_Name] command to update the forwarding rule of the corresponding Ingress resource, and then rerun the precheck.

DeleteALBListenerRules

The forwarding rule configuration of the ALB instance is inconsistent with the Ingress resource.

Rerun the precheck and do not modify the forwarding rules during the precheck.

Delete the added forwarding rule, and then rerun the precheck.

Server group-related errors

Error message

Cause

Solution (scenario 1: no manual changes)

Solution (scenario 2: manual changes)

CreateALBServerGroup

The server group configuration of the ALB instance is inconsistent with the Ingress resource.

Rerun the precheck and do not modify the server group during the precheck.

Add the deleted server group back, and then rerun the precheck.

UpdateALBServerGroup

The server group configuration of the ALB instance is inconsistent with the Ingress resource.

Rerun the precheck and do not modify the server group during the precheck.

Align the server group configuration of the ALB instance with the Ingress resource, and then rerun the precheck. To use the server group configuration on the ALB console instead, run the kubectl -n [$Namespace] edit ingress [$Ingress_Name] command to update the server group configuration of the corresponding Ingress resource, and then rerun the precheck.

DeleteALBServerGroup

The server group configuration of the ALB instance is inconsistent with the Ingress resource.

Rerun the precheck and do not modify the server group during the precheck.

Delete the added server group, and then rerun the precheck.

Backend server-related errors

Error message

Cause

Solution (scenario 1: no manual changes)

Solution (scenario 2: manual changes)

RegisterALBServers, DeregisterALBServers, ReplaceALBServers

The Endpoints configuration of the cluster is inconsistent with the backend server configuration of the ALB instance.

Rerun the precheck and do not modify the backend servers during the precheck.

Restore the backend server configuration of the ALB instance so that it is consistent with the Endpoints configuration of the cluster, and then rerun the precheck.