sudo vi /etc/nginx/nginx.conf
stream {
include /etc/nginx/stream-enabled/*;
}
sudo mkdir /etc/nginx/stream-enabled/
sudo mkdir /etc/nginx/stream-available/
sudo vi /etc/nginx/stream-available/kubernetes
upstream kubernetes {
server 10.100.0.117:6443;
server 10.100.0.118:6443;
}
server {
listen 6443;
proxy_pass kubernetes;
}
$ netstat -nptl
roto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 891/sshd
tcp 0 0 0.0.0.0:6443 0.0.0.0:* LISTEN 27342/nginx -g daem
$ curl -k https://localhost:6443
{
"kind": "Status",
"apiVersion": "v1",
"metadata": {
},
"status": "Failure",
"message": "forbidden: User \"system:anonymous\" cannot get path \"/\"",
"reason": "Forbidden",
"details": {
},
"code": 403
}