failed calling webhook ☸️ Kubernetes

Internal error occurred: failed calling webhook "x": ... connection refused / context deadline exceeded

The API server couldn’t reach an admission webhook’s service, so it rejected the request (failurePolicy: Fail).

Seen on: Kubernetes

Meaning

Webhooks run as pods (cert-manager, ingress-nginx, Istio, Kyverno). If those pods are down, uninstalled without removing the webhook configuration, blocked by a firewall from the control plane (common on private GKE/EKS), or have an expired CA bundle, every matching create/update fails.

Common causes

  • Webhook pods not running
  • Operator uninstalled but its webhook configuration left behind
  • Control plane can’t reach the webhook port (firewall/NetworkPolicy)
  • Expired or mismatched caBundle (x509 errors)

⚡ Quick fix

  1. Check the webhook service’s pods
  2. Delete orphaned Validating/MutatingWebhookConfiguration objects
  3. Open the control-plane → node firewall port (e.g. 8443/9443)

Detailed fix by platform

Kubernetes

  1. bash
    kubectl get validatingwebhookconfigurations,mutatingwebhookconfigurations
    kubectl get endpoints -n cert-manager cert-manager-webhook
    kubectl delete validatingwebhookconfiguration old-operator-webhook   # only if the operator is gone

How to diagnose

  1. Webhook — Name and service in the error
  2. Pods — Running and ready?
  3. Network — Reachable from control plane?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.