Unable to connect to the server: dial tcp i/o timeout ☸️ Kubernetes

Unable to connect to the server: dial tcp <ip>:443: i/o timeout

kubectl can’t reach the API server at all — network path, VPN, firewall or a private endpoint you’re outside of.

Seen on: Kubernetes

Meaning

i/o timeout means packets go unanswered: private EKS/AKS/GKE endpoints reachable only from the VPC, authorized-IP lists that don’t include you, a disconnected VPN, or a stopped local cluster.

Common causes

  • Private API endpoint and you’re outside the network/VPN
  • Your IP not in the authorized networks list
  • Cluster stopped/deleted (minikube, kind, cloud)
  • Stale kubeconfig pointing to an old IP

⚡ Quick fix

  1. Connect the VPN/bastion or enable the public endpoint for your IP
  2. Check the cluster is running
  3. Regenerate kubeconfig

Detailed fix by platform

Shell

  1. bash
    kubectl config view --minify -o jsonpath='{.clusters[0].cluster.server}'
    nc -vz <api-host> 443

How to diagnose

  1. Endpoint — Server URL in kubeconfig
  2. Reach — nc/curl to it
  3. Cluster — Running?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.