Skip to content

Troubleshooting / System Cannot Be Accessed from the External Network

The system itself is running normally, but when it cannot be accessed externally, it is usually a network issue.

Specifically:

  1. On the deployment server itself, curl -i http://127.0.0.1:8088 returns 302 redirect information:
HTTP
1
2
3
4
5
6
7
8
9
HTTP/1.1 302 Found
Location: /client-app
Vary: Accept
Content-Type: text/plain; charset=utf-8
Content-Length: 33
Date: Wed, 25 Aug 2021 14:23:02 GMT
Connection: keep-alive

Found. Redirecting to /client-app
  1. On the deployment server itself, curl http://127.0.0.1:8088/api/v1/do/ping returns 200 with normal data:
HTTP
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
HTTP/1.1 200 OK
Vary: Origin, Accept-Encoding
Access-Control-Allow-Credentials: true
X-Trace-Id: TRACE-D2B2A855-3C28-4566-8EC5-5A2EDD85856C
X-Request-Time: 2021-08-25T14:24:00.239Z
X-Response-Time: 2021-08-25T14:24:00.241Z
X-Request-Cost: 2
Content-Type: application/json; charset=utf-8
Content-Length: 192
ETag: W/"c0-Wb2YFtp16lA4mB7Xh7SpYumGNog"
Date: Wed, 25 Aug 2021 14:24:00 GMT
Connection: keep-alive

{"ok":true,"error":200,"message":"","data":"pong","traceId":"TRACE-D2B2A855-3C28-4566-8EC5-5A2EDD85856C","reqTime":"2021-08-25T14:24:00.239Z","respTime":"2021-08-25T14:24:00.241Z","reqCost":2}
  1. On other devices, curl -i http://{server-address}:8088 receives no response, or directly returns connection refused.

When such a problem occurs, it is mostly a network issue and has nothing to do with DataFlux Func itself.

The following is only a record of some possible solutions.

1. Incorrect IP / Domain Name Resolution

On another device, try to ping the server where DataFlux Func is located to confirm whether the IP address and domain name are correct.

This can be solved by modifying DNS or /etc/hosts configuration. The exact method depends on the actual network conditions.

2. Incorrect Firewall / Security Configuration

Including but not limited to:

  1. Incorrect firewall configuration
  2. Incorrect Alibaba Cloud ECS security group configuration
  3. Incorrect reverse proxy server or Alibaba Cloud SLB configuration

First, check the port exposed by the current deployment:

Bash
1
grep '8088' {installation-dir}/docker-stack.yaml

The output is:

Text Only
1
- "{exposed-port}:8088"

{exposed-port} defaults to 8088

Check and modify the network environment to allow external access to the server's port.

3. Conflict Between the Local Network and the Automatically Created ingress Subnet

You can use the following command to check:

Bash
1
sudo docker network inspect ingress

Check whether the IPAM.Config.Subnet value is the same as the local network:

JSON
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
[
    {
        "Name": "ingress",
        "Id": "adinmn5ww9q3vqo0wbse2jn1s",
        "Created": "2021-08-21T07:46:47.534343555Z",
        "Scope": "swarm",
        "Driver": "overlay",
        "EnableIPv6": false,
        "IPAM": {
            "Driver": "default",
            "Options": null,
            "Config": [
                {
                    "Subnet": "10.0.0.0/16",
                    "Gateway": "10.0.0.1"
                }
            ]
        }
    }
]

If they overlap, you can modify it in the following ways:

  1. Stop DataFlux Func
  2. Delete the existing network: sudo docker network rm ingress
  3. Recreate the network: docker network create --driver overlay --ingress --subnet 10.255.0.0/16 --gateway 10.255.0.1 ingress
  4. Start DataFlux Func

  5. Reference documentation: Docker Swarm Default Address Pool

  6. Reference documentation: Customizing the Docker ingress network

4. Missing Kernel Forwarding Configuration

This problem has been found on CentOS systems, but in most cases it has not been encountered.

You can check the forwarding configuration in the following ways:

Bash
1
cat /proc/sys/net/ipv4/ip_forward
  1. If the above command returns 1, forwarding is already enabled.
  2. Otherwise, you can enable the forwarding configuration as follows:
Bash
1
echo 1 > /proc/sys/net/ipv4/ip_forward