# Helm Chart on RKE2 / Ingress configuration for Websocket

**URL:** <https://forum.mattermost.com/t/helm-chart-on-rke2-ingress-configuration-for-websocket/18194>\
**Category:** Troubleshooting\
**Created:** [March 19, 2024, 12:43pm UTC](https://forum.mattermost.com/t/helm-chart-on-rke2-ingress-configuration-for-websocket/18194 "2024-03-19T12:43:05Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![fcoulloudon](https://avatars.discourse-cdn.com/v4/letter/f/7ba0ec/32.png) [@fcoulloudon](https://forum.mattermost.com/u/fcoulloudon)\
**Post date:** [March 19, 2024, 12:43pm UTC](https://forum.mattermost.com/t/helm-chart-on-rke2-ingress-configuration-for-websocket/18194/1 "2024-03-19T12:43:05Z")

</div>

**Summary**  
Websocket connexion problem, is the problem coming from the ingress configuration?

**Steps to reproduce**  
Install RKE2 v2.7.4 (K8S v1.23.17) + Charts: mattermost-team-edition (6.6.49)

**Expected behavior**  
Have websocket working

**Observed behavior**  
Please check connection, Mattermost unreacheable. If issue persists, ask administrator to check WebSocket port.

 ![image](https://us1.discourse-cdn.com/flex020/uploads/mattermost/original/2X/1/15b9f1fbbef0c0179f554d656f025f85dc7803dd.png)

As many of you, we have a problem with the websockets.  
Probably from nginx/ingress configuration.

Here is the configuration:

```auto
ingress:
  annotations:
    cert-manager.io/cluster-issuer: keycloak-letsencrypt-prod
    kubernetes.io/ingress.class: nginx
    nginx.ingress.kubernetes.io/server-snippets: |
      location ~ /api/v[0-9]+/(users/)?websocket$ {
       proxy_set_header Upgrade $http_upgrade;
       proxy_set_header Connection "upgrade";
       client_max_body_size 50M;
       proxy_set_header Host $http_host;
       proxy_set_header X-Real-IP $remote_addr;
       proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
       proxy_set_header X-Forwarded-Proto $scheme;
       proxy_set_header X-Frame-Options SAMEORIGIN;
       proxy_buffers 256 16k;
       proxy_buffer_size 16k;
       client_body_timeout 60;
       send_timeout 300;
       lingering_timeout 5;
       proxy_connect_timeout 90;
       proxy_send_timeout 300;
       proxy_read_timeout 90s;
       proxy_http_version 1.1;
       proxy_pass http://mattermost-team-edition.mattermost.svc.cluster.local:8065;
      }

      location / {
       client_max_body_size 50M;
       proxy_set_header Connection "";
       proxy_set_header Host $http_host;
       proxy_set_header X-Real-IP $remote_addr;
       proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
       proxy_set_header X-Forwarded-Proto $scheme;
       proxy_set_header X-Frame-Options SAMEORIGIN;
       proxy_buffers 256 16k;
       proxy_buffer_size 16k;
       proxy_read_timeout 600s;
       proxy_http_version 1.1;
       proxy_pass http://mattermost-team-edition.mattermost.svc.cluster.local:8065;
      }
  className: ''
  enabled: true
  hosts:
    - mattermost.domain.net
  path: /
  tls:
    - hosts:
        - mattermost.domain.net
      secretName: mattermost.domain.net-tls

```

We have added those from the nginx configuration here: [Configure NGINX as a proxy for Mattermost server — Mattermost documentation](https://docs.mattermost.com/install/config-proxy-nginx.html)

Anyone has a working helm chart values to suggest to have our Ingress OK with websockets?

We have already spent a lot of time to make this work.  
Any suggestion would be highly appreciated 🙂

---

<div class="post-metadata">

**Author:** ![john.oliver](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/john.oliver/32/6436_2.png) [@john.oliver](https://forum.mattermost.com/u/john.oliver)\
**Post date:** [March 19, 2024, 4:06pm UTC](https://forum.mattermost.com/t/helm-chart-on-rke2-ingress-configuration-for-websocket/18194/2 "2024-03-19T16:06:32Z")

</div>

Mattermost 6.6.49? Are you sure? There was a 6.6.2 but that hasn’t been supported for two years. I’d strongly recommend getting a newer version from [Version Archive — Mattermost documentation](https://docs.mattermost.com/upgrade/version-archive.html#mattermost-team-edition)

One thing that might be involved is, last year we began enforcing a security setting around cross-origin requests. [Integrations configuration settings — Mattermost documentation](https://docs.mattermost.com/configure/integrations-configuration-settings.html#integrate-allowcorsfrom)

Did WebSockets ever work? It’s possible that network infrastructure or firewalls allow HTTP/HTTPS but not WS/WSS

---

<div class="post-metadata">

**Author:** ![fcoulloudon](https://avatars.discourse-cdn.com/v4/letter/f/7ba0ec/32.png) [@fcoulloudon](https://forum.mattermost.com/u/fcoulloudon)\
**Post date:** [March 31, 2024, 1:23pm UTC](https://forum.mattermost.com/t/helm-chart-on-rke2-ingress-configuration-for-websocket/18194/3 "2024-03-31T13:23:52Z")

</div>

@john.oliver

The helm chart version is mattermost-team-edition:6.6.49  
The Mattermost version is 9.5.2.

Did WebSockets ever work? not yet here… I’m quite interested to have an example of helm values that makes it work using the proper nginx configuration.

Thanks!

---

<div class="post-metadata">

**Author:** ![john.oliver](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/john.oliver/32/6436_2.png) [@john.oliver](https://forum.mattermost.com/u/john.oliver)\
**Post date:** [April 1, 2024, 2:25pm UTC](https://forum.mattermost.com/t/helm-chart-on-rke2-ingress-configuration-for-websocket/18194/4 "2024-04-01T14:25:48Z")

</div>

Are we certain there’s no RKE load balancer involved? Or any external network issue? Something between your RKE environment and the Internet?

---

<div class="post-metadata">

**Author:** ![fcoulloudon](https://avatars.discourse-cdn.com/v4/letter/f/7ba0ec/32.png) [@fcoulloudon](https://forum.mattermost.com/u/fcoulloudon)\
**Post date:** [April 3, 2024, 8:01pm UTC](https://forum.mattermost.com/t/helm-chart-on-rke2-ingress-configuration-for-websocket/18194/5 "2024-04-03T20:01:30Z")

</div>

Nothing… Maybe a firewall but TCP 80 and 443 are open.

---

<div class="post-metadata">

**Author:** ![fcoulloudon](https://avatars.discourse-cdn.com/v4/letter/f/7ba0ec/32.png) [@fcoulloudon](https://forum.mattermost.com/u/fcoulloudon)\
**Post date:** [April 4, 2024, 9:15am UTC](https://forum.mattermost.com/t/helm-chart-on-rke2-ingress-configuration-for-websocket/18194/6 "2024-04-04T09:15:20Z")

</div>

Anyone has managed to make the helm chart work?  
How can WS work if the default ingress configuration do not have the upgrade feature for WSS?  
Information is here:

> **[Using Websockets with the Nginx Kubernetes Ingress Controller - Civo.com](https://www.civo.com/learn/using-websockets-with-ingress-controller)**
>
> Learn how to set up WebSockets with the Nginx ingress controller in Civo Kubernetes to avoid the error code 426 Upgrade Required.

And also in the Nginx configuration from the Mattermort website here:  
[https://docs.mattermost.com/install/config-proxy-nginx.html](https://docs.mattermost.com/install/config-proxy-nginx.html)

---

<div class="post-metadata">

**Author:** ![john.oliver](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/john.oliver/32/6436_2.png) [@john.oliver](https://forum.mattermost.com/u/john.oliver)\
**Post date:** [April 4, 2024, 11:04pm UTC](https://forum.mattermost.com/t/helm-chart-on-rke2-ingress-configuration-for-websocket/18194/7 "2024-04-04T23:04:23Z")

</div>

> [@fcoulloudon](#):
>
> How can WS work if the default ingress configuration do not have the upgrade feature for WSS?

Not sure what you mean by this. You may want to get HTTP / WS working, then add in the certs and enable TLS. Sorry, I’m not a k8s expert… this probably is an nginx issue, maybe [https://forum.nginx.org/](https://forum.nginx.org/) can help?

---

<div class="post-metadata">

**Author:** ![fcoulloudon](https://avatars.discourse-cdn.com/v4/letter/f/7ba0ec/32.png) [@fcoulloudon](https://forum.mattermost.com/u/fcoulloudon)\
**Post date:** [April 8, 2024, 6:13am UTC](https://forum.mattermost.com/t/helm-chart-on-rke2-ingress-configuration-for-websocket/18194/8 "2024-04-08T06:13:35Z")

</div>

After investigation, WSS can reach the app.

But I get this error message:  
{“timestamp”:“2024-04-08 06:08:22.451 Z”,“level”:“debug”,“msg”:“Failed to upgrade websocket connection.”,“caller”:“web/context.go:111”,“path”:“/api/v4/websocket”,“request\_id”:“”,“ip\_addr”:“”,“user\_id”:",“method”:“GET”,“err\_where”:“connect”,“http\_code”:400,“error”:“connect: Failed to upgrade websocket connection., websocket: request origin not allowed by Upgrader.CheckOrigin”}

Continuing to see how to properly configure nginx in order to prevent “request origin not allowed by Upgrader.CheckOrigin”

---

<div class="post-metadata">

**Author:** ![john.oliver](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/john.oliver/32/6436_2.png) [@john.oliver](https://forum.mattermost.com/u/john.oliver)\
**Post date:** [April 8, 2024, 3:32pm UTC](https://forum.mattermost.com/t/helm-chart-on-rke2-ingress-configuration-for-websocket/18194/9 "2024-04-08T15:32:25Z")

</div>

[https://docs.mattermost.com/configure/integrations-configuration-settings.html#integrate-allowcorsfrom](https://docs.mattermost.com/configure/integrations-configuration-settings.html#integrate-allowcorsfrom)

---

<div class="post-metadata">

**Author:** ![fcoulloudon](https://avatars.discourse-cdn.com/v4/letter/f/7ba0ec/32.png) [@fcoulloudon](https://forum.mattermost.com/u/fcoulloudon)\
**Post date:** [April 8, 2024, 5:43pm UTC](https://forum.mattermost.com/t/helm-chart-on-rke2-ingress-configuration-for-websocket/18194/10 "2024-04-08T17:43:18Z")

</div>

Thank you…  
Still trying to figure out how to put something different than \*.  
Highly appreciated.

---

<div class="post-metadata">

**Author:** ![john.oliver](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/john.oliver/32/6436_2.png) [@john.oliver](https://forum.mattermost.com/u/john.oliver)\
**Post date:** [April 8, 2024, 5:59pm UTC](https://forum.mattermost.com/t/helm-chart-on-rke2-ingress-configuration-for-websocket/18194/11 "2024-04-08T17:59:56Z")

</div>

Start with “\*” and see if that resolves the issue.

Assuming it does, I asked and there was some confusing about comma-delineated vs. space delineated. Try:

`http.cors.allow-origin: "http://localhost,http://127.0.0.1"`

Or:

`http.cors.allow-origin: "http://localhost http://127.0.0.1`

And please LMK which or if both worked!

---

<div class="post-metadata">

**Author:** ![fcoulloudon](https://avatars.discourse-cdn.com/v4/letter/f/7ba0ec/32.png) [@fcoulloudon](https://forum.mattermost.com/u/fcoulloudon)\
**Post date:** [April 22, 2024, 12:27pm UTC](https://forum.mattermost.com/t/helm-chart-on-rke2-ingress-configuration-for-websocket/18194/12 "2024-04-22T12:27:36Z")

</div>

None of these worked in K8S. How can I see origin in the logs of the application?

---

<div class="post-metadata">

**Author:** ![john.oliver](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/john.oliver/32/6436_2.png) [@john.oliver](https://forum.mattermost.com/u/john.oliver)\
**Post date:** [April 23, 2024, 3:08pm UTC](https://forum.mattermost.com/t/helm-chart-on-rke2-ingress-configuration-for-websocket/18194/13 "2024-04-23T15:08:22Z")

</div>

Ctrl-Shift-J should open a Javascript console and show a lot of details. I’m not a developer and don’t “get” most of the output.

---

<div class="post-metadata">

**Author:** ![fcoulloudon](https://avatars.discourse-cdn.com/v4/letter/f/7ba0ec/32.png) [@fcoulloudon](https://forum.mattermost.com/u/fcoulloudon)\
**Post date:** [April 23, 2024, 4:00pm UTC](https://forum.mattermost.com/t/helm-chart-on-rke2-ingress-configuration-for-websocket/18194/14 "2024-04-23T16:00:43Z")

</div>

I mean from server side :-).  
I will investigate and share the information when/if I find something.

Regards,

Francois
