# Kubeadm ImagePull during init fails

**URL:** <https://discuss.kubernetes.io/t/kubeadm-imagepull-during-init-fails/24793>\
**Category:** General Discussions\
**Created:** [July 13, 2023, 4:42pm UTC](https://discuss.kubernetes.io/t/kubeadm-imagepull-during-init-fails/24793 "2023-07-13T16:42:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Keith\_Christopher](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/keith_christopher/32/12886_2.png) [@Keith\_Christopher](https://discuss.kubernetes.io/u/Keith_Christopher)\
**Post date:** [July 13, 2023, 4:42pm UTC](https://discuss.kubernetes.io/t/kubeadm-imagepull-during-init-fails/24793/1 "2023-07-13T16:42:41Z")

</div>

Asking for help? Comment out what you need so we can get more information to help you!

### Cluster information:

Kubernetes version: 1.26.1  
Cloud being used: (put bare-metal if not on a public cloud)  
Installation method: manual  
Host OS: Redhat v8  
CNI and version:  
CRI and version: 1.27.0

I am inside a protected network and use a http/https proxy.. When running the kubeadm init it is not able to find/connect to [dl.k8s.io](http://dl.k8s.io) or [release.k8s.io](http://release.k8s.io). It doesn’t seem to start the apiserver on 6443 so it just tries to connect until it errors out, and a kubectl errors on 8080 connecting. I’m new and I’m completely lost.

Please help

---

<div class="post-metadata">

**Author:** ![mrbobbytables](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/mrbobbytables/32/7_2.png) [@mrbobbytables](https://discuss.kubernetes.io/u/mrbobbytables)\
**Post date:** [July 13, 2023, 5:34pm UTC](https://discuss.kubernetes.io/t/kubeadm-imagepull-during-init-fails/24793/2 "2023-07-13T17:34:58Z")

</div>

You will have to mirror the images for you to use, see the stability guarantee here:

> **[GitHub - kubernetes/registry.k8s.io: This project is the repo for...](https://github.com/kubernetes/registry.k8s.io#stability)**
>
> This project is the repo for registry.k8s.io, the production OCI registry service for Kubernetes' container image artifacts - GitHub - kubernetes/registry.k8s.io: This project is the repo for r...

There have been several blogs published on [Kubernetes Blog | Kubernetes](http://k8s.io/blog) the subject if you’re looking for any further specific guidance.

---

<div class="post-metadata">

**Author:** ![Keith\_Christopher](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/keith_christopher/32/12886_2.png) [@Keith\_Christopher](https://discuss.kubernetes.io/u/Keith_Christopher)\
**Post date:** [July 14, 2023, 5:19am UTC](https://discuss.kubernetes.io/t/kubeadm-imagepull-during-init-fails/24793/3 "2023-07-14T05:19:06Z")

</div>

thanks for the feedback, the problem I’ve narrowed it down to is when connecting out it is not sending valid host headers and the firewall/proxy is rejecting these requests. On RHEL 7, HTTP\_PROXY=… works like a champ. Also to note CURL does not work unless you put the proxy in the curl command line.  
e.g. curl -x :

So for some reason the connection out via kubeadm and curl using the env vars is sending bad or no host headers.

oh yeah and this also affected GIT an was resolved by adding the proxy info into the git conf

curiouser and curiouser.

I should mention I’m working on RHEL 8 using crio.
