Troubleshoot ALB Ingress Controller add-on update precheck failures
A precheck runs before the ALB Ingress Controller add-on is updated, and it fails when the configurations on the Application Load Balancer (ALB) console no longer match your AlbConfig or Ingress resources. Use the reported error message to identify the cause and apply the corresponding fix.
Usage notes
Before the add-on update
Before you update the ALB Ingress Controller add-on, review the new features of the add-on. For more information, see ALB Ingress controller.
-
Before you run the precheck, run the
kubectl get eventcommand to check whether reconciliation failure events exist in the cluster. If such events exist, fix the failures and make sure that reconciliation completes. If you cannot identify the cause of a reconciliation failure, submit a ticket to contact technical support. -
Make sure that the configurations on the ALB console are consistent with the AlbConfig resource and the Ingress resource. If you manually modify resources such as Application Load Balancer (ALB) instances, listeners, forwarding rules, network access control lists (ACLs), or server groups on the ALB console before the precheck, the configurations on the ALB console become inconsistent with the AlbConfig or Ingress resource, and the precheck fails. If the two sides are inconsistent, align them in one of the following ways before you start the update:
-
To use the configurations on the ALB console, modify the AlbConfig or Ingress resource to match the configurations on the ALB console.
-
To use the configurations in the AlbConfig or Ingress resource, update the ALB console in one of the following ways:
-
Run the
kubectl editcommand and modify a non-critical field in the AlbConfig or Ingress resource to trigger a reconciliation. The configurations on the ALB console are updated accordingly. -
Modify the configurations on the ALB console to match the AlbConfig or Ingress resource. After you modify the configurations on the ALB console, you must enable the configuration read-only mode for the ALB instance. For more information, see Enable or disable the configuration read-only mode.
-
-
During the add-on update
During the precheck, do not modify the AlbConfig or Ingress resource. Otherwise, the precheck result may be inaccurate. If you have modified either resource, rerun the precheck. If the precheck still fails after multiple attempts, submit a ticket for assistance.
Precheck errors and solutions
The following tables group the error messages by ALB resource type. Each error message has two solutions, and which one applies depends on whether the affected resource was modified manually on the ALB console before the precheck. After you apply a solution and rerun the precheck, view the Check Report again to confirm the result. The two scenarios are as follows:
-
Scenario 1: no manual changes — The affected resource was not modified manually on the ALB console before the precheck. Rerun the precheck and do not modify the resource during the precheck.
-
Scenario 2: manual changes — The affected resource was modified manually on the ALB console before the precheck. Align the configurations on the ALB console with the AlbConfig or Ingress resource, and then rerun the precheck.
ALB instance-related errors
|
Error message |
Cause |
Solution (scenario 1: no manual changes) |
Solution (scenario 2: manual changes) |
|
CreateALB, ReuseALB, UnReuseALB, DeleteALB |
The configuration of the ALB instance is inconsistent with the AlbConfig resource. |
Rerun the precheck and do not modify the AlbConfig resource during the precheck. |
Align the configuration of the ALB instance with the AlbConfig resource, and then rerun the precheck. |
|
UpdateALBAttribute |
The Attribute configuration of the ALB instance, which includes the ALB instance name and the configuration read-only mode status, is inconsistent with the AlbConfig resource. |
Rerun the precheck and do not modify the AlbConfig resource during the precheck. |
Run the |
|
UpdateALBDeletionProtection |
The deletion protection configuration of the ALB instance is inconsistent with the AlbConfig resource. |
Rerun the precheck and do not modify the AlbConfig resource during the precheck. |
Run the |
|
UpdateALBAccessLog |
The access log configuration of the ALB instance is inconsistent with the AlbConfig resource. |
Rerun the precheck and do not modify the AlbConfig resource during the precheck. |
Align the access log configuration of the ALB instance with the AlbConfig resource, and then rerun the precheck. To use the access log configuration on the ALB console instead, run the |
|
UpdateALBEdition |
The edition of the ALB instance, which is Standard or WAF Enabled, is inconsistent with the AlbConfig resource. |
Rerun the precheck and do not modify the AlbConfig resource during the precheck. |
Align the edition of the ALB instance with the AlbConfig resource, and then rerun the precheck. |
|
UpdateALBResourceGroup |
The resource group configuration of the ALB instance is inconsistent with the AlbConfig resource. |
Rerun the precheck and do not modify the AlbConfig resource during the precheck. |
Align the resource group configuration of the ALB instance with the AlbConfig resource, and then rerun the precheck. |
|
UpdateALBTag |
The tag configuration of the ALB instance is inconsistent with the AlbConfig resource. |
Rerun the precheck and do not modify the AlbConfig resource during the precheck. |
Align the tag configuration of the ALB instance with the AlbConfig resource, and then rerun the precheck. |
|
UpdateALBAddressType |
The network type configuration of the ALB instance is inconsistent with the AlbConfig resource. |
Rerun the precheck and do not modify the AlbConfig resource during the precheck. |
Align the network type of the ALB instance with the AlbConfig resource, and then rerun the precheck. To use the network type on the ALB console instead, run the |
|
UpdateALBBandWidthPackage |
The shared bandwidth package configuration of the ALB instance is inconsistent with the AlbConfig resource. |
Rerun the precheck and do not modify the AlbConfig resource during the precheck. |
Align the shared bandwidth package configuration of the ALB instance with the AlbConfig resource, and then rerun the precheck. To use the shared bandwidth package configuration on the ALB console instead, run the |
Changing the network type of the ALB instance from a private network to a public network involves changes to Elastic IP Addresses (EIPs) and incurs fees. Changing the network type from a public network to a private network disassociates all EIPs and modifies DNS resolution. Proceed with caution in both directions.
Listener-related errors
|
Error message |
Cause |
Solution (scenario 1: no manual changes) |
Solution (scenario 2: manual changes) |
|
CreateALBListener |
The listener configuration of the ALB instance is inconsistent with the AlbConfig resource. |
Rerun the precheck and do not modify the listener during the precheck. |
Add the deleted listener back to the ALB instance, and then rerun the precheck. To use the listener configuration on the ALB console instead, run the |
|
UpdateALBListenerExtraCertificates |
The additional certificate configuration of the listener on the ALB instance is inconsistent with the AlbConfig resource. |
Rerun the precheck and do not modify the listener during the precheck. |
Align the additional certificate configuration of the listener with the AlbConfig resource, and then rerun the precheck. To use the additional certificate configuration on the ALB console instead, run the |
|
UpdateALBListenerAttribute |
The listener attribute configuration of the ALB instance is inconsistent with the AlbConfig resource. |
Rerun the precheck and do not modify the listener during the precheck. |
Identify the inconsistent listener attributes, such as the certificate, compression algorithm, access control policy, idle connection timeout, and |
|
DeleteALBListener |
The listener configuration of the ALB instance is inconsistent with the AlbConfig resource. |
Rerun the precheck and do not modify the listener during the precheck. |
On the ALB console, delete the listener that was added, and then rerun the precheck. To use the listener configuration on the ALB console instead, run the |
Network ACL-related errors
|
Error message |
Cause |
Solution (scenario 1: no manual changes) |
Solution (scenario 2: manual changes) |
|
CreateAcl, DeleteAcl, AddEntriesToAcl, RemoveEntriesFromAcl, AssociateAclWithListener, DisassociateAclWithListener |
The network ACL configuration is inconsistent with the access control policy configuration in the AlbConfig resource. |
Rerun the precheck and do not modify the network ACL during the precheck. |
Align the network ACL configuration on the ALB console with the AlbConfig resource, and then rerun the precheck. To use the access control policy configuration of the network ACL on the ALB console instead, run the |
Forwarding rule-related errors
|
Error message |
Cause |
Solution (scenario 1: no manual changes) |
Solution (scenario 2: manual changes) |
|
CreateALBListenerRules |
The forwarding rule configuration of the ALB instance is inconsistent with the Ingress resource. |
Rerun the precheck and do not modify the forwarding rules during the precheck. |
Add the deleted forwarding rule back, and then rerun the precheck. |
|
UpdateALBListenerRules |
The forwarding rule configuration of the ALB instance is inconsistent with the Ingress resource. |
Rerun the precheck and do not modify the forwarding rules during the precheck. |
Align the forwarding rule configuration of the ALB instance with the Ingress resource, and then rerun the precheck. To use the forwarding rule configuration on the ALB console instead, run the |
|
DeleteALBListenerRules |
The forwarding rule configuration of the ALB instance is inconsistent with the Ingress resource. |
Rerun the precheck and do not modify the forwarding rules during the precheck. |
Delete the added forwarding rule, and then rerun the precheck. |
Server group-related errors
|
Error message |
Cause |
Solution (scenario 1: no manual changes) |
Solution (scenario 2: manual changes) |
|
CreateALBServerGroup |
The server group configuration of the ALB instance is inconsistent with the Ingress resource. |
Rerun the precheck and do not modify the server group during the precheck. |
Add the deleted server group back, and then rerun the precheck. |
|
UpdateALBServerGroup |
The server group configuration of the ALB instance is inconsistent with the Ingress resource. |
Rerun the precheck and do not modify the server group during the precheck. |
Align the server group configuration of the ALB instance with the Ingress resource, and then rerun the precheck. To use the server group configuration on the ALB console instead, run the |
|
DeleteALBServerGroup |
The server group configuration of the ALB instance is inconsistent with the Ingress resource. |
Rerun the precheck and do not modify the server group during the precheck. |
Delete the added server group, and then rerun the precheck. |
Backend server-related errors
|
Error message |
Cause |
Solution (scenario 1: no manual changes) |
Solution (scenario 2: manual changes) |
|
RegisterALBServers, DeregisterALBServers, ReplaceALBServers |
The |
Rerun the precheck and do not modify the backend servers during the precheck. |
Restore the backend server configuration of the ALB instance so that it is consistent with the |