{ Community }
  • Academy
  • Docs
  • Developers
  • Resources
    • Community Articles
    • Apigee on GitHub
    • Code Samples
    • Videos & eBooks
    • Accelerator Methodology
  • Support
  • Ask a Question
  • Spaces
    • Product Announcements
    • General
    • Edge/API Management
    • Developer Portal (Drupal-based)
    • Developer Portal (Integrated)
    • API Design
    • APIM on Istio
    • Extensions
    • Business of APIs
    • Academy/Certification
    • Adapter for Envoy
    • Analytics
    • Events
    • Hybrid
    • Integration (AWS, PCF, Etc.)
    • Microgateway
    • Monetization
    • Private Cloud Deployment
    • 日本語コミュニティ
    • Insights
    • IoT Apigee Link
    • BaaS/Usergrid
    • BaaS Transition/Migration
    • Apigee-127
    • New Customers
    • Topics
    • Questions
    • Articles
    • Ideas
    • Leaderboard
    • Badges
  • Log in
  • Sign up

Get answers, ideas, and support from the Apigee Community

  • Home /
  • Hybrid /
avatar image
0
Question by Sunny Sehrawat · Jan 14 at 05:58 AM · 59 Views apigee hybrid

Apigee Hybrid Installation Issues Version 1.4 (GKE on AWS)

security-group-inbound-rules.jpg@ Google @yuriyl @Dino-at-Google @Anil Sagar @RadhikaApigeek @Aakash Sharma @ylesyuk @Basavaraj Dhanashetti @RajeshMishra@Google Paul Williams

We are installing Apigee Hybrid Version 1.4 on (GKE on AWS) but facing various issues after the installation step and not able to proceed further.

Below are the issues on which we are stuck and not able to proceed further,

1. When trying the test API on the set up from within the cluster getting below error,

curl: (35) Unknown SSL protocol error in connection to {host:port}

Curl command used-

curl --cacert /tmp/usr/local/bin/apigee-hybrid/hybrid-files/certs/keystore.pem https://example.com:port/test -v -- resolve "example.com:port:IP" --http1.1

2. When we are debugging to resolve above issues, noticed few mismatch in the Number of target groups created by google provided scripts in all the environments/instances.

And these target groups are in unhealthy state, probable root cause mentioned in next point below.

3. Also,we have observed that NodePorts of Istio Ingress gateway are different from the ports of Target Group and Security Group in AWS. These gaps are rendering Target Groups in Unhealthy state.

Ports in Ingress-Gateway

15021:30730/TCP,80:30966/TCP,443:32549/TCP,15443:30181/TCP

Ports in Security Group

we have observed is that NodePorts of Istio Ingress gateway are different from the ports of Target Group and Security Group in AWS. These gaps are rendering Target Groups in Unhealthy state. Looking forward to a quick short discussion and guidance.

Ports in Ingress-Gateway

15021:30730/TCP,80:30966/TCP,443:32549/TCP,15443:30181/TCP

-->(Attached the Security Group Inbound Rules)

Kindly provide your feedback, if anyone faced the similar issues or can help in with any expertise on the same.

security-group-inbound-rules.jpg (60.2 kB)
Comment
Add comment
10 |5000 characters needed characters left characters exceeded
▼
  • Viewable by all users
  • Viewable by Apigeeks only
  • Viewable by the original poster
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Viewable by all users

Close

0 Answers

  • Sort: 

Follow this Question

Answers Answers and Comments

40 People are following this question.

avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image

Related Questions

Apigee Hybrid - Management Plane security risk 0 Answers

Send custom logs on Stackdriver with Apigee Hybrid 0 Answers

Apigee Hybrid setup - Internal error while applying overrides 1 Answer

Unable to access API using hybrid runtime istio ingress gateway --- SSL error 2 Answers

istio is not enabled for apigee hybrid runtime components 0 Answers

  • Products
    • Edge - APIs
    • Insights - Big Data
    • Plans
  • Developers
    • Overview
    • Documentation
  • Resources
    • Overview
    • Blog
    • Apigee Institute
    • Academy
    • Documentation
  • Company
    • Overview
    • Press
    • Customers
    • Partners
    • Team
    • Events
    • Careers
    • Contact Us
  • Support
    • Support Overview
    • Documentation
    • Status
    • Edge Support Portal
    • Privacy Policy
    • Terms & Conditions
© 2021 Apigee Corp. All rights reserved. - Apigee Community Terms of Use - Powered by AnswerHub
  • Anonymous
  • Sign in
  • Create
  • Ask a question
  • Create an article
  • Post an idea
  • Spaces
  • Product Announcements
  • General
  • Edge/API Management
  • Developer Portal (Drupal-based)
  • Developer Portal (Integrated)
  • API Design
  • APIM on Istio
  • Extensions
  • Business of APIs
  • Academy/Certification
  • Adapter for Envoy
  • Analytics
  • Events
  • Hybrid
  • Integration (AWS, PCF, Etc.)
  • Microgateway
  • Monetization
  • Private Cloud Deployment
  • 日本語コミュニティ
  • Insights
  • IoT Apigee Link
  • BaaS/Usergrid
  • BaaS Transition/Migration
  • Apigee-127
  • New Customers
  • Explore
  • Topics
  • Questions
  • Articles
  • Ideas
  • Badges