Does the IBM Cloud Kubernetes Service Ingress annotation for public IP type work identically in local kind and production clusters?
0 reputation · 08 Aug 2021, 17:33 UTC
0 reputation · 08 Aug 2021, 17:33 UTC
Goal: Deploy a simple web service in an IBM Cloud Kubernetes Service cluster and expose it using an IBM Cloud Load Balancer (ALB) by setting the service annotation service.kubernetes.io/ibm-load-balancer-cloud-provider-ip-type: public. The same manifest works without error in a local kind cluster, where the service receives a routable IP and the application is reachable.
In the production IBM Cloud Kubernetes Service cluster, the service remains in a pending state or receives no external IP, and the application is not accessible despite the annotation being present. The cluster is configured with a standard VPC, worker nodes have public gateway enabled, and the IAM policy for the service account includes the Container Service Operator role.
What additional configuration or permissions are required for the annotation to take effect in IBM Cloud Kubernetes Service? Does the annotation behave differently based on the cluster's VPC or resource group? Are there known limitations or version‑specific behaviors for this annotation in IBM Cloud Kubernetes Service?
27025 reputation · 09 Aug 2021, 00:46 UTC
No, the service.kubernetes.io/ibm-load-balancer-cloud-provider-ip-type: public annotation does not produce identical behavior in a local kind cluster and an IBM Cloud Kubernetes Service (IKS) production cluster.
kind cluster has no cloud provider, so the annotation is ignored or treated as a no‑op unless a local shim (e.g., Metallb) is installed.Container Service Operator role scoped to the cluster’s resource group and VPC. Missing or mis‑scoped permissions cause the controller to stall the request.kind environment, a service of type LoadBalancer without an external load‑balancer shim remains pending or receives a node‑port, and IBM‑specific annotations are not processed.CreateLoadBalancer) when the annotation is valid; in kind, events reference the local shim or show no cloud‑provider action.Container Service Operator role scoped to the cluster’s resource group and VPC.Use comments to ask for clarification. Post a solution as an answer.
1,900 reputation · 08 Aug 2021, 23:51 UTC
service.kubernetes.io/ibm-load-balancer-cloud-provider-ip-type: public is only interpreted by the IBM Cloud ALB controller. It triggers a call to the VPC API to allocate a public IP from the cluster’s VPC pool. The request will fail silently if the service account is not granted the Container Service Operator role scoped to the cluster’s resource group and VPC.kind cluster the annotation is ignored unless you add a load‑balancer shim such as MetalLB and configure it to recognize the same annotation key. Without that shim the service stays Pending and no external IP is assigned.service.beta.kubernetes.io to service.kubernetes.io. Using the old key will work only on older clusters.