No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search


To have a better experience, please upgrade your IE browser.


HUAWEI CLOUD Stack 6.5.0 Alarm and Event Reference 04

Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
ALM-2017 IAM-Proxy Connection Error

ALM-2017 IAM-Proxy Connection Error


This alarm is generated when cse-config-center or cse-service-center fails to access the IAM-Proxy service.


Alarm ID

Alarm Severity

Alarm Type



Environmental alarm





Indicates the namespace of the service for which the alarm is generated.


Indicates the name of the service for which the alarm is generated.


Indicates the name of the service instance for which the alarm is reported.


Indicates the IP address of the host where the microservice instance is deployed.

Impact on the System

If an abnormality occurs during the access to IAM-Proxy, the AK/SHA (AK/SK) authentication request fails. As a result, the microservices that use this authentication mode cannot be registered and the dashboard information cannot be reported.

Possible Causes

  • IAM-Proxy is abnormal.
  • A network fault occurs.


  1. Use PuTTY to log in to the manage_lb1_ip node.

    The default username is paas, and the default password is QAZ2wsx@123!.

  2. Run the following command and enter the password of the root user to switch to the root user:

    su - root

    Default password: QAZ2wsx@123!

  3. Check the pod status of IAM-Proxy.

    Log in to the lb01 node and run the following command to check the service status.

    kubectl get pod -n fst-manage | grep iam

    If IAM-Proxy is abnormal, restart the IAM-Proxy instance to rectify the fault.

  4. Check whether the network is normal.

    1. Run the following command to access the pod of the CSE service for which the alarm is generated (cse-service-center-3608034112-ht6lx is used as an example):

      kubectl -n fst-manage exec -it cse-service-center-3608034112-ht6lx sh

    2. Check whether the network is normal.

      curl -kv https://iam-proxy.fst-manage.svc.cluster.local:30904

      The network is normal if information similar to the following is displayed.

      If the network is normal, go to the next step.

  5. View the domain name file to locate the fault.

    1. Check whether the permission and content of the /etc/resolv.conf domain name file in the alarm service pod are correct.

      If any user can read the /etc/resolv.conf file, the permission is normal.

      If the /etc/resolv.conf file contains the following information, the file content is normal:
      search fst-manage.svc.cluster.local svc.cluster.local cluster.local
      options ndots:4
    2. If the DNS resolution is normal but the network connection fails, restart the service pod.

      The following uses the pod of cse-service-center-3608034112-ht6lx as an example to describe how to restart a pod:

      kubectl delete pod -n fst-manage cse-service-center-3608034112-ht6lx

      After the command is executed, the pod of cse-service-center-3608034112-ht6lx is deleted and another pod whose name starts with cse-service-center is generated.

  6. Check whether the alarm is cleared.

    • If yes, no further action is required.
    • If no, contact technical support for assistance.

Alarm Clearing

This alarm is automatically cleared when IAM-Proxy recovers.

Related Information


Updated: 2019-08-30

Document ID: EDOC1100062365

Views: 38182

Downloads: 31

Average rating:
This Document Applies to these Products
Related Version
Related Documents
Previous Next