# Upstream connect error with Pomerium Ingress Controller

**URL:** <https://discuss.pomerium.com/t/upstream-connect-error-with-pomerium-ingress-controller/43>\
**Category:** Support\
**Tags:** k8s\
**Created:** [December 10, 2021, 5:56pm UTC](https://discuss.pomerium.com/t/upstream-connect-error-with-pomerium-ingress-controller/43 "2021-12-10T17:56:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rguichard](https://yyz1.discourse-cdn.com/flex031/user_avatar/discuss.pomerium.com/rguichard/32/25_2.png) [@rguichard](https://discuss.pomerium.com/u/rguichard)\
**Post date:** [December 10, 2021, 5:56pm UTC](https://discuss.pomerium.com/t/upstream-connect-error-with-pomerium-ingress-controller/43/1 "2021-12-10T17:56:49Z")

</div>

Hi everyone,

I’m having trouble migrating from Helm chart `24.0` to `25.0` with the new Ingress Controller. After being authenticated with my IdP and after ~5sec of loading, I get `upstream connect error or disconnect/reset before headers. reset reason: connection failure`. Worked well with Traefik without Pomerium or with Pomerium as forwardauth (chart version 24) but not as an Ingress Controller.

```auto
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  annotations:
    cert-manager.io/cluster-issuer: letsencrypt-dns
    ingress.pomerium.io/allowed_domains: '["mydomain.tld"]'
    ingress.pomerium.io/pass_identity_headers: "true"
    ingress.pomerium.io/preserve_host_header: "true"
  name: app
spec:
  ingressClassName: pomerium-external
  rules:
  - host: app.mydomain.tld
    http:
      paths:
      - backend:
          service:
            name: app
            port:
              number: 8080
        path: /
        pathType: Prefix
  tls:
  - hosts:
    - app.mydomain.tld
    secretName: app.mydomain.tld

```

```auto
---
apiVersion: v1
kind: Service
metadata:
  name: app
spec:
  clusterIP: 10.100.195.194
  clusterIPs:
  - 10.100.195.194
  ports:
  - name: http
    port: 8080
    protocol: TCP
    targetPort: http
  selector:
    app.kubernetes.io/name: app
  type: ClusterIP

```

The tricky point is that it works with others upstream apps so the problem might come from my app (Python/Flask/Gunicorn application with pretty every, by default, parameters, unfortunately, I can’t provide the Dockerfile). But so far, I have been unable to find what does not make it work…

Thx for all your help !

---

<div class="post-metadata">

**Author:** ![denis](https://avatars.discourse-cdn.com/v4/letter/d/5e9695/32.png) [@denis](https://discuss.pomerium.com/u/denis)\
**Post date:** [December 13, 2021, 5:57pm UTC](https://discuss.pomerium.com/t/upstream-connect-error-with-pomerium-ingress-controller/43/2 "2021-12-13T17:57:35Z")

</div>

Here are steps to troubleshoot the connection between pomerium proxy and your service:

A proxy would make an HTTP (or HTTPS, in case [`secure_upstream` annotation is set](https://www.pomerium.com/docs/k8s/ingress.html)) to `service.namespace.svc.cluster.local:port`

Run an interactive debug container in the same namespace you’re running your pomerium proxy:

```bash
kubectl run -i --tty busybox --image=busybox --restart=Never -- sh

```

From there, use `curl` to make sure your service responds.

```auto
curl -v http://app.default.svc.cluster.local:8080/

```

Note that you requested `pass_identity_headers: true` which would make pomerium proxy set `Host` HTTP header to `app.mydomain.tld` - make sure your service is configured to in fact respond to that.

---

<div class="post-metadata">

**Author:** ![alex](https://yyz1.discourse-cdn.com/flex031/user_avatar/discuss.pomerium.com/alex/32/9_2.png) [@alex](https://discuss.pomerium.com/u/alex)\
**Post date:** [December 21, 2021, 8:22pm UTC](https://discuss.pomerium.com/t/upstream-connect-error-with-pomerium-ingress-controller/43/3 "2021-12-21T20:22:37Z")

</div>

Hey @rguichard, did you ever find the solve for this issue?
