Server troubleshooting
Resolve Kubernetes, database, ingress and certificate problems.
| Symptom | Resolution |
|---|---|
Pods show ImagePullBackOff | Recreate the pull secret and confirm the install command includes it. |
| Pods cannot reach the database | Check the database host, password and SSL settings. Confirm externalPostgresCIDR covers the database and its firewall allows the cluster. |
| Browser shows 404 or 503 | Check the ingress class, DNS records and ingress controller labels. |
| Browser shows a certificate warning | Check the certificate issuer, and confirm the certificate includes the full chain and covers the host name. |
| Administrator sign-in fails with a cross-origin error | CORS_ORIGIN must exactly match the admin console address, with no trailing slash. |
| HTTP 429 errors | A per-address request limit was reached. Wait for the limit to reset or raise it. |
Pods stay Pending | The cluster lacks capacity. Add capacity or lower the resource requests. |
| Workstation cannot reach the license server | Confirm the installer properties, DNS, firewall access and certificate trust. |
| Workstation still uses the old address | Close and reopen SonicCloud. |
Investigate a failing pod
kubectl describe pod <pod-name> -n license
kubectl logs <pod-name> -n licenseHealth checks
| Endpoint | Meaning |
|---|---|
/livez | The process is running. |
/readyz | The server can reach its database and is ready for traffic. |
For workstation and licensing problems, see Troubleshooting.
