🌐 502 debug path (nginx → ingress → pod)

Follow checks in order when users see Bad Gateway. · ~15 min

Reviewed: ·Tested on: Kubernetes 1.29, Terraform 1.8, Ubuntu 22.04

If you're on Kubernetes 1.27 or older

  • Ingress: networking.k8s.io/v1 is required — v1beta1 removed in 1.22+
  • Pod Security: PodSecurityPolicy removed in 1.25 — use Pod Security Admission (PSA) labels
  • HPA v2 autoscaling/v2 is stable — check API version in manifests

If you're on Kubernetes 1.28

  • Sidecar containers (1.29+) change init-container ordering — review sidecar docs before upgrade
  • Verify metrics-server and HPA after control plane bump

If you're on Terraform 1.7 or older

  • S3 native locking (use_lockfile) differs from DynamoDB — don't mix backends mid-migration
  • Provider version constraints: run terraform init -upgrade after bump
  • terraform test (1.6+) replaces some external test harness patterns

1. Reproduce and isolate

curl -I https://app.example.com
curl -I http://localhost:8080  # after port-forward

2. Ingress + endpoints

kubectl get ingress,svc,endpoints -n <ns>
kubectl describe ingress <name> -n <ns>

3. Pod health

kubectl get pods -n <ns>
kubectl logs <pod> -n <ns> --tail=50
kubectl describe pod <pod> -n <ns>

4. Nginx / ingress controller logs

kubectl logs -n ingress-nginx -l app.kubernetes.io/name=ingress-nginx --tail=100
sudo tail -f /var/log/nginx/error.log

Related runbook: Open runbook →