# CoreDNS \[ERROR\] plugin/errors: 2

**URL:** <https://discuss.kubernetes.io/t/coredns-error-plugin-errors-2/16106>\
**Category:** General Discussions\
**Tags:** coredns\
**Created:** [May 31, 2021, 12:03pm UTC](https://discuss.kubernetes.io/t/coredns-error-plugin-errors-2/16106 "2021-05-31T12:03:28Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![letran3691](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/letran3691/32/7758_2.png) [@letran3691](https://discuss.kubernetes.io/u/letran3691)\
**Post date:** [May 31, 2021, 12:03pm UTC](https://discuss.kubernetes.io/t/coredns-error-plugin-errors-2/16106/1 "2021-05-31T12:03:28Z")

</div>

Hello everyone

Kubernetes version:v1.21.1  
Cloud being used: LAB Private  
Installation method: repo install  
Host OS: centos7  
CNI: flannel

I’ve setup a LAB cluster with 3 node (node1, node2, node3), node 1 is master.  
I setup environment and join node to cluster done, nodes Ready, But I’ve issue with coredns. Coredns can’t nslookup name nodes  
logs pod coredns  
\> [ERROR] plugin/errors: 2 node3. A: read udp 10.244.0.25:43976-\>8.8.8.8:53: i/o timeout  
\> [ERROR] plugin/errors: 2 node3. A: read udp 10.244.0.25:55132-\>8.8.8.8:53: i/o timeout  
\> [ERROR] plugin/errors: 2 node3. A: read udp 10.244.0.25:42492-\>8.8.8.8:53: i/o timeout  
\> [ERROR] plugin/errors: 2 node3. AAAA: read udp 10.244.0.25:54212-\>8.8.8.8:53: i/o timeout

log metricbeat service

`2021-05-31T12:00:40.639Z WARN [transport] transport/tcp.go:52 DNS lookup failure "node3": lookup node3 on 10.96.0.10:53: read udp 10.244.2.45:59110->10.96.0.10:53: i/o timeout`

but services in cluster deployment did, still working with name services.

Topo  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/kubernetes/original/2X/4/4fb7af886b696e49536709183d80ced86be1779e.png)

wish everyone help me.  
thanks !

---

<div class="post-metadata">

**Author:** ![mrbobbytables](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/mrbobbytables/32/7_2.png) [@mrbobbytables](https://discuss.kubernetes.io/u/mrbobbytables)\
**Post date:** [May 31, 2021, 1:05pm UTC](https://discuss.kubernetes.io/t/coredns-error-plugin-errors-2/16106/2 "2021-05-31T13:05:46Z")

</div>

What CNI driver are you using? I’ve seen that sort of error before if theres a problem at the CNI level.

---

<div class="post-metadata">

**Author:** ![letran3691](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/letran3691/32/7758_2.png) [@letran3691](https://discuss.kubernetes.io/u/letran3691)\
**Post date:** [May 31, 2021, 1:12pm UTC](https://discuss.kubernetes.io/t/coredns-error-plugin-errors-2/16106/3 "2021-05-31T13:12:12Z")

</div>

yes! I’ve update CNI: flannel

---

<div class="post-metadata">

**Author:** ![letran3691](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/letran3691/32/7758_2.png) [@letran3691](https://discuss.kubernetes.io/u/letran3691)\
**Post date:** [May 31, 2021, 1:30pm UTC](https://discuss.kubernetes.io/t/coredns-error-plugin-errors-2/16106/4 "2021-05-31T13:30:09Z")

</div>

Seems like I’ve issue where. i checked configmap coredns and see it’s forward dns to /etc/resolv.conf. But i don’t have idea to fix, because my nodes is visual machine. I’ve fix hostname in file hosts, but issue not resolved yet.

---

<div class="post-metadata">

**Author:** ![protosam](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/protosam/32/7732_2.png) [@protosam](https://discuss.kubernetes.io/u/protosam)\
**Post date:** [May 31, 2021, 4:29pm UTC](https://discuss.kubernetes.io/t/coredns-error-plugin-errors-2/16106/5 "2021-05-31T16:29:28Z")

</div>

Quick question on this, are you expecting coredns to observe your node’s `/etc/hosts` file in this the case?

Where are node1, node2, and node3 setup DNS-wise?

---

<div class="post-metadata">

**Author:** ![letran3691](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/letran3691/32/7758_2.png) [@letran3691](https://discuss.kubernetes.io/u/letran3691)\
**Post date:** [May 31, 2021, 4:40pm UTC](https://discuss.kubernetes.io/t/coredns-error-plugin-errors-2/16106/6 "2021-05-31T16:40:23Z")

</div>

- Yes. I find method to use coredns hosts file, a idea but i don’t know it’s work [Using both hosts and kubernetes plugin doesn't seem working · Issue #1268 · coredns/coredns · GitHub](https://github.com/coredns/coredns/issues/1268)
- nodes config dns google(8.8.8.8)

---

<div class="post-metadata">

**Author:** ![protosam](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/protosam/32/7732_2.png) [@protosam](https://discuss.kubernetes.io/u/protosam)\
**Post date:** [May 31, 2021, 5:23pm UTC](https://discuss.kubernetes.io/t/coredns-error-plugin-errors-2/16106/7 "2021-05-31T17:23:41Z")

</div>

Containers don’t use the host’s `/etc/hosts` file. Each container has it’s own nsswitch configuration. You could probably do [something like this](https://hjrocha.medium.com/add-a-custom-host-to-kubernetes-a06472cedccb).

I’m a bit biased here though. If you need to connect to a node to do something on a node, you can just do it directly in a pod.

To illustrate how to do it, you might want to check out the krew plugin called `node-shell`.

All node-shell does is creates a pod that runs on the node that you want to do work on and attaches you to it. At that point if you’re thinking you needed to connect to a service, it’s now always going to be localhost.

---

<div class="post-metadata">

**Author:** ![akala515](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/akala515/32/8461_2.png) [@akala515](https://discuss.kubernetes.io/u/akala515)\
**Post date:** [August 27, 2021, 9:16am UTC](https://discuss.kubernetes.io/t/coredns-error-plugin-errors-2/16106/8 "2021-08-27T09:16:48Z")

</div>

May I know how did u fix it right?

Facing the same problem here.

---

<div class="post-metadata">

**Author:** ![Brandon\_Ojeda](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/brandon_ojeda/32/7323_2.png) [@Brandon\_Ojeda](https://discuss.kubernetes.io/u/Brandon_Ojeda)\
**Post date:** [September 23, 2021, 9:59pm UTC](https://discuss.kubernetes.io/t/coredns-error-plugin-errors-2/16106/9 "2021-09-23T21:59:28Z")

</div>

@akala515 - I found that my CNI was using iptables-legacy even though my debian 10 VMs were set to use nt\_tables. This was causing my rules for 10.96 to be applied to iptables-legacy and iptables-legacy -t nat for CNI and causing this breakage.

Resolution for me was to start over, remove all iptables for both legacy and nft, and start from scratch.  
kubeadm init…  
Followed by, instead of an install of calico directly from one of their manifest, you should pull it down and add  
- name: FELIX\_IPTABLESBACKEND  
value: “NFT”  
to the env vars. This will force NFT. After then installing calico from this updated version of it, it all worked for me and I had no iptables-legacy changes and everything lived in nft.

---

<div class="post-metadata">

**Author:** ![tillus](https://avatars.discourse-cdn.com/v4/letter/t/3bc359/32.png) [@tillus](https://discuss.kubernetes.io/u/tillus)\
**Post date:** [February 2, 2022, 12:49pm UTC](https://discuss.kubernetes.io/t/coredns-error-plugin-errors-2/16106/10 "2022-02-02T12:49:45Z")

</div>

@Brandon_Ojeda I managed to get it working with your instructions ([networking - Kubernetes: unreachable backend: read udp 10.200.0.9:46159-\>183.60.83.19:53: i/o timeout - Stack Overflow](https://stackoverflow.com/a/69307421/7892674)) + [HINFO: unreachable backend: read udp 10.200.0.9:46159-\>183.60.83.19:53: i/o timeout · Issue #2693 · coredns/coredns · GitHub](https://github.com/coredns/coredns/issues/2693#issuecomment-586649324) + rebooting my system at some point. I am still confused, but happy that it is working now. Thanks for that

---

<div class="post-metadata">

**Author:** ![rahgadda](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/rahgadda/32/9986_2.png) [@rahgadda](https://discuss.kubernetes.io/u/rahgadda)\
**Post date:** [May 3, 2022, 7:09pm UTC](https://discuss.kubernetes.io/t/coredns-error-plugin-errors-2/16106/11 "2022-05-03T19:09:02Z")

</div>

I faced the same issue and resolved it. Details are available [here](https://stackoverflow.com/questions/72048337/unable-to-connect-internet-google-com-from-pod-docker-and-k8-are-able-to-pull-i)

---

<div class="post-metadata">

**Author:** ![Parshva\_Shah](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/parshva_shah/32/12524_2.png) [@Parshva\_Shah](https://discuss.kubernetes.io/u/Parshva_Shah)\
**Post date:** [June 6, 2023, 6:06am UTC](https://discuss.kubernetes.io/t/coredns-error-plugin-errors-2/16106/12 "2023-06-06T06:06:22Z")

</div>

K8s :- V1.26.1  
OS : - RHEL 8.7  
VM is hosted using Azure cloud provider.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/kubernetes/original/2X/d/d75327cc42b3c946435bee400d8280e4e895c832.png)

Core dns logs :-  
CoreDNS-1.9.3  
linux/amd64, go1.18.2, 45b0a11  
[ERROR] plugin/errors: 2 2568389657905608835.8295431261288812352. HINFO: read udp 192.168.54.66:34391-\>168.63.129.16:53: read: no route to host  
[ERROR] plugin/errors: 2 2568389657905608835.8295431261288812352. HINFO: read udp 192.168.54.66:34275-\>168.63.129.16:53: read: no route to host  
[ERROR] plugin/errors: 2 2568389657905608835.8295431261288812352. HINFO: read udp 192.168.54.66:59435-\>168.63.129.16:53: read: no route to host

Unable to reach internet from inside the pod. nslookup fails with below error  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/kubernetes/original/2X/1/10cccdc6cdacb659f0ee5a261129ee83aa644c32.png)

---

<div class="post-metadata">

**Author:** ![Bo-Zi](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/bo-zi/32/13094_2.png) [@Bo-Zi](https://discuss.kubernetes.io/u/Bo-Zi)\
**Post date:** [August 17, 2023, 3:12am UTC](https://discuss.kubernetes.io/t/coredns-error-plugin-errors-2/16106/13 "2023-08-17T03:12:47Z")

</div>

That could be the case of proper firewall configuration:

- `firewall-cmd --add-masquerade --permanent` [Kubernetes on CentOS 7 with Firewalld | by Nilesh Jayanandana | Medium](https://nilesh93.medium.com/kubernetes-on-centos-7-with-firewalld-e7b53c1316af)

- (optionally) `firewall-cmd --permanent --zone={name} --add-interface=vxlan.calico` [Kubernetes cluster with firewall enabled on CentOS(calico) not working - Stack Overflow](https://stackoverflow.com/a/69553391/9969561)
