OnCallReady

OpenShiftKubernetesNetworking · 1 min read

OpenShift "Application is not available": the 503 and its three causes

The grey router page means the router could not hand the request to a pod. Wrong host or path, no ready endpoints, or a Route pointing at the wrong port - and the commands that tell them apart.

Users get a grey page: "Application is not available", HTTP 503. Your pods are Running. The page comes from the OpenShift router (HAProxy), not from your app. The router never reached a pod - the same shape as nginx's 502 Bad Gateway, one layer up. There are three ways that happens.

1. No Route matches the host (or the path)

A typo in the hostname, a Route in another project, or a path-based Route that doesn't cover the URL. Check the hosts the router knows about:

output
oc get route

The HOST/PORT column is what has to match exactly. Generated hosts follow <route>-<project>.apps.<cluster domain>, so the same Route in another project has a different host. Also check that the route was admitted: if admission refused it, the column shows the reason (for example, another route already claimed that host).

2. The Route matches, but there are no ready endpoints

The Service selects no pods, or none of them is Ready yet (a slow start, a failing readiness probe):

output
oc get endpoints web
oc rollout status deployment/web

An empty endpoints list means 503. That's also why curling a Route right after oc expose, before the rollout finishes, gives you a 503, and why a rollout without a readiness probe can drop requests on every deploy.

3. The Route points at the wrong port

spec.port.targetPort on a Route is matched against the Service's target port: the container port number, or the Service port's name. It isn't matched against the Service's own port. A Route created with --port=80 for a Service 80 -> 8080 matches no endpoint:

output
oc describe route web-bad
oc get svc web -o jsonpath='{.spec.ports}'

Use the port's name (oc expose svc/web copies it for you) or the pod's port, 8080.

Order of checks

Host (does a Route match?), endpoints (is anything ready behind it?), port (does the Route's targetPort select those endpoints?). Fixing those three covers almost every "Application is not available" you'll see.

OnCallReady is free, with no ads and no tracking. RSS · All posts