Unable to connect to the server: dial tcp <ip>:443: i/o timeout
kubectl can’t reach the API server at all — network path, VPN, firewall or a private endpoint you’re outside of.
Seen on:
Kubernetes
Meaning
i/o timeout means packets go unanswered: private EKS/AKS/GKE endpoints reachable only from the VPC, authorized-IP lists that don’t include you, a disconnected VPN, or a stopped local cluster.
Common causes
- Private API endpoint and you’re outside the network/VPN
- Your IP not in the authorized networks list
- Cluster stopped/deleted (minikube, kind, cloud)
- Stale kubeconfig pointing to an old IP
⚡ Quick fix
- Connect the VPN/bastion or enable the public endpoint for your IP
- Check the cluster is running
- Regenerate kubeconfig
Detailed fix by platform
Shell
- bash
kubectl config view --minify -o jsonpath='{.clusters[0].cluster.server}' nc -vz <api-host> 443
How to diagnose
- Endpoint — Server URL in kubeconfig
- Reach — nc/curl to it
- Cluster — Running?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Kubernetes
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026