# Kubectl logs \<pod\> throws forbidden error

**URL:** <https://discuss.kubernetes.io/t/kubectl-logs-pod-throws-forbidden-error/6633>\
**Category:** General Discussions\
**Created:** [June 4, 2019, 3:05pm UTC](https://discuss.kubernetes.io/t/kubectl-logs-pod-throws-forbidden-error/6633 "2019-06-04T15:05:48Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.kubernetes.io/u/asp)\
**Post date:** [June 4, 2019, 3:05pm UTC](https://discuss.kubernetes.io/t/kubectl-logs-pod-throws-forbidden-error/6633/1 "2019-06-04T15:05:48Z")

</div>

### Cluster information:

Kubernetes version: 1.14.2  
Cloud being used: bare-metal  
Installation method: manual  
Host OS: Centos 7  
CNI and version: calico  
CRI and version: docker

Hi,

I am trying to implement GlusterFS as persistent storage solution in kubernetes. The heketi pod does not come up, so I thought, lets check the pod’s logs.

I tried the following:

```
$ kubectl get pod
NAME READY STATUS RESTARTS AGE
glusterfs-7ftp9 1/1 Running 1 82m
glusterfs-mk5l4 1/1 Running 1 82m
heketi-74cc7bb45c-448w8 0/1 ContainerCreating 0 7m53s

$ kubectl logs heketi-74cc7bb45c-448w8
Error from server: Get https://x.x.x.x:10250/containerLogs/default/heketi-74cc7bb45c-448w8/heketi: Forbidden

```

What do I need to to to get permission?

---

<div class="post-metadata">

**Author:** ![schms](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/schms/32/2678_2.png) [@schms](https://discuss.kubernetes.io/u/schms)\
**Post date:** [June 5, 2019, 7:44am UTC](https://discuss.kubernetes.io/t/kubectl-logs-pod-throws-forbidden-error/6633/2 "2019-06-05T07:44:51Z")

</div>

A Google search provides a few links. Have you already read them?

> <https://serverfault.com/questions/943336/kubernetes-upgrade-to-1-13-0-gives-forbidden-error-on-kubectl-logs>

  

> <https://github.com/kubernetes/kubeadm/issues/211>

  

> <https://github.com/kubernetes/kops/issues/5706>

---

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.kubernetes.io/u/asp)\
**Post date:** [June 6, 2019, 12:41pm UTC](https://discuss.kubernetes.io/t/kubectl-logs-pod-throws-forbidden-error/6633/3 "2019-06-06T12:41:36Z")

</div>

Hi @schms,  
thanks a lot, it was your first link. I’ve setup no\_proxy for hostname, but not for IP.

Now after updating `/etc/kubernetes/manifests/kube-apiserver.yaml` I can see the logs on other nodes.

Regards, Andreas
