# K8s on premise: expose api to public

**URL:** <https://discuss.kubernetes.io/t/k8s-on-premise-expose-api-to-public/5686>\
**Category:** General Discussions\
**Created:** [March 27, 2019, 1:58pm UTC](https://discuss.kubernetes.io/t/k8s-on-premise-expose-api-to-public/5686 "2019-03-27T13:58:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![azer](https://avatars.discourse-cdn.com/v4/letter/a/f08c70/32.png) [@azer](https://discuss.kubernetes.io/u/azer)\
**Post date:** [March 27, 2019, 1:58pm UTC](https://discuss.kubernetes.io/t/k8s-on-premise-expose-api-to-public/5686/1 "2019-03-27T13:58:41Z")

</div>

Hi, forgive me for my bad english.

I have installed a k8s cluster using kubesparay on 5 servers (3 managers en 5 workers). I’d like to expose the k8s api to public. So i have an ingress to allow access to HTTPS api using the kubernetes service created by default by kubespray. It works for some command, but “exec” raise an error: “Upgrade request required”

So i have tried to plug a ladbalancer IP directly to the kubernetes service, but the IP is not reachable from outside (just for this service if i use this ip on another service, it works).

How can I expose kubernetes service to public using a loadbalancer IP (provisionned by metallb) ??

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![rata](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/rata/32/18244_2.png) [@rata](https://discuss.kubernetes.io/u/rata)\
**Post date:** [March 28, 2019, 4:06am UTC](https://discuss.kubernetes.io/t/k8s-on-premise-expose-api-to-public/5686/2 "2019-03-28T04:06:18Z")

</div>

> ![](https://us1.discourse-cdn.com/flex016/uploads/kubernetes/original/2X/b/b3e9f65e6c4f84b31a7f55b618b049a4ace1ae4b.png "azer")  
> [azer](https://discuss.kubernetes.io/u/azer)
> 
> ```
> March 27
> 
> ```
> 
> Hi, forgive me for my bad english.

> I have installed a k8s cluster using kubesparay on 5 servers (3 managers en 5 workers). I’d like to expose the k8s api to public. So i have an ingress to allow access to HTTPS api using the kubernetes service created by default by kubespray. It works for some command, but “exec” raise an error: “Upgrade request required”

Have you checked:

[https://stackoverflow.com/questions/51154911/kubectl-exec-results-in-error-unable-to-upgrade-connection-pod-does-not-exi](https://stackoverflow.com/questions/51154911/kubectl-exec-results-in-error-unable-to-upgrade-connection-pod-does-not-exi)

And

[https://github.com/kubernetes/kubernetes/issues/63702](https://github.com/kubernetes/kubernetes/issues/63702)

Most likely you need to specify the proper IP/network interface.

> So i have tried to plug a ladbalancer IP directly to the kubernetes service, but the IP is not reachable from outside (just for this service if i use this ip on another service, it works).How can I expose kubernetes service to public using a loadbalancer IP (provisionned by metallb) ??

Is the traffic not reaching the nodes? Can you run tcpdump, for example?

Also, are you using BGP or layer 2 mode? And are you using external Traffic Policy? If you are, I can imagine that the speaker component is not scheduled to master due to taints, for example.

But please share more about your setup so we can have a better understanding. Please try to narrow it down as far as you can, like is traffic reaching nodes (tcpdump for checking, for example)? Can you access using the nodeIP:nodePort? At which hops can you trace the request and where is being dropped?
