🌐 502 debug path (nginx → ingress → pod)
Follow checks in order when users see Bad Gateway. · ~15 min
Reviewed: ·Tested on: Kubernetes 1.29, Terraform 1.8, Ubuntu 22.04
If you're on Kubernetes 1.27 or older
- Ingress: networking.k8s.io/v1 is required — v1beta1 removed in 1.22+
- Pod Security: PodSecurityPolicy removed in 1.25 — use Pod Security Admission (PSA) labels
- HPA v2 autoscaling/v2 is stable — check API version in manifests
If you're on Kubernetes 1.28
- Sidecar containers (1.29+) change init-container ordering — review sidecar docs before upgrade
- Verify metrics-server and HPA after control plane bump
If you're on Terraform 1.7 or older
- S3 native locking (use_lockfile) differs from DynamoDB — don't mix backends mid-migration
- Provider version constraints: run terraform init -upgrade after bump
- terraform test (1.6+) replaces some external test harness patterns
1. Reproduce and isolate
curl -I https://app.example.com curl -I http://localhost:8080 # after port-forward
2. Ingress + endpoints
kubectl get ingress,svc,endpoints -n <ns> kubectl describe ingress <name> -n <ns>
3. Pod health
kubectl get pods -n <ns> kubectl logs <pod> -n <ns> --tail=50 kubectl describe pod <pod> -n <ns>
4. Nginx / ingress controller logs
kubectl logs -n ingress-nginx -l app.kubernetes.io/name=ingress-nginx --tail=100 sudo tail -f /var/log/nginx/error.log
Related runbook: Open runbook →