# How can I resolve "server gave HTTP response to HTTPS client"

**URL:** <https://forums.suse.com/t/how-can-i-resolve-server-gave-http-response-to-https-client/39225>\
**Category:** SUSE Rancher Prime\
**Created:** [October 15, 2022, 9:01am UTC](https://forums.suse.com/t/how-can-i-resolve-server-gave-http-response-to-https-client/39225 "2022-10-15T09:01:07Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![tvtoanit](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/tvtoanit/32/9533_2.png) [@tvtoanit](https://forums.suse.com/u/tvtoanit)\
**Post date:** [October 15, 2022, 9:01am UTC](https://forums.suse.com/t/how-can-i-resolve-server-gave-http-response-to-https-client/39225/1 "2022-10-15T09:01:07Z")

</div>

I have three server:  
1 master: 192.168.1.131  
1 node: 192.168.1.132  
1 rancher: 192.168.1.133  
I have create docker image (private registry docker) on node used 192.168.1.132:5000/test.  
Both master and node pushed and pulled to image. But used rancher deploy set image 192.168.1.132:5000/test then error:  
Failed to pull image “192.168.1.132:5000/test-demo”: rpc error: code = Unknown desc = failed to pull and unpack image “192.168.1.132:5000/test-demo:latest”: failed to resolve reference “192.168.1.132:5000/test-demo:latest”: failed to do request: Head “[https://192.168.1.132:5000/v2/test-demo/manifests/latest](https://192.168.1.132:5000/v2/test-demo/manifests/latest)”: http: server gave HTTP response to HTTPS client.

My image used  
http not https. But rancher send https.

 ![Screenshot 2022-10-15 160022](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/e/e5afd40e0a198f7b3ef199c83cd257cc776c5bd1.jpeg)

How can I resolve “server gave HTTP response to HTTPS client”

---

<div class="post-metadata">

**Author:** ![Beckham](https://avatars.discourse-cdn.com/v4/letter/b/838e76/32.png) [@Beckham](https://forums.suse.com/u/Beckham)\
**Post date:** [November 7, 2022, 2:41pm UTC](https://forums.suse.com/t/how-can-i-resolve-server-gave-http-response-to-https-client/39225/2 "2022-11-07T14:41:12Z")

</div>

HTTPS Client Authentication is a more secure method of authentication than either basic or form-based authentication . It uses HTTP over SSL (HTTPS), in which the server authenticates the client using the client’s Public Key Certificate (PKC).

Hopefully this will help anyone having issues getting the `insecure-registries` fix to work.  
Try below code.

Adding

`{ "insecure-registries":["host:port"] }`

to

` /etc/docker/daemon.json`

did not work for me until I created the file

`/etc/default/docker`

and put the line

`DOCKER_OPTS="--config-file=/etc/docker/daemon.json"`

in it and then restarted the docker daemon with

`sudo systemctl stop docker` and `sudo systemctl start docker`.

For some reason just doing a `sudo systemctl restart docker` did not work. It threw an error about trying to restart the service to quickly.

Also for `["host:port"]` I used the IP of my Docker registry as opposed to the hostname as I did not have DNS or a hosts file setup to be able to find the registry by hostname.

This drove me absolutely nuts until I stumbled upon the `/etc/default/docker` bit here  
I am new to Docker and so I don’t know if this is new requirement since this initial post was answered or if there was something else I missed when I first setup my registry. Though all I did was to follow the current docs on the Docker site itself.

---

<div class="post-metadata">

**Author:** ![Govind\_Avireddi](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/govind_avireddi/32/10940_2.png) [@Govind\_Avireddi](https://forums.suse.com/u/Govind_Avireddi)\
**Post date:** [February 7, 2024, 1:10pm UTC](https://forums.suse.com/t/how-can-i-resolve-server-gave-http-response-to-https-client/39225/3 "2024-02-07T13:10:37Z")

</div>

I tried your solution by adding " `DOCKER_OPTS="--config-file=/etc/docker/daemon.json"`" into /etc/default/docker. I still get the same error.

Is this Rancher specific issue or I should see with vanilla Kubernetes too?  
We setup Harbour Container registry without enabling https.

Any help is appreciated!

---

<div class="post-metadata">

**Author:** ![vaishnav](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vaishnav/32/10688_2.png) [@vaishnav](https://forums.suse.com/u/vaishnav)\
**Post date:** [February 8, 2024, 7:07am UTC](https://forums.suse.com/t/how-can-i-resolve-server-gave-http-response-to-https-client/39225/4 "2024-02-08T07:07:29Z")

</div>

Hi, Can you please give some more information:  
Cluster Type where you are deploying that image (RKE/RKE2.K3s)?  
How is it provisioned? (Using Rancher, or standalone and imported on rancher)?

The error points to some incorrect registries configuration. Looks like you have installed docker on the servers. Kubernetes uses containerd as it’s CRI. So adding insecure registries in your docker daemon.json will not help here. You have to tell the containerd that the registry is insecure(http) and not https. The way to do this, is configuring the registry correctly.

If this is a Cluster provisioned from Rancher UI (Not imported), then in the cluster config you’ll find a registries tab. Please configure the registry correctly there.

If this is a standalone cluster and imported in Rancher then please create a registries.yaml file with the registry config.

---

<div class="post-metadata">

**Author:** ![Govind\_Avireddi](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/govind_avireddi/32/10940_2.png) [@Govind\_Avireddi](https://forums.suse.com/u/Govind_Avireddi)\
**Post date:** [February 16, 2024, 12:57pm UTC](https://forums.suse.com/t/how-can-i-resolve-server-gave-http-response-to-https-client/39225/5 "2024-02-16T12:57:02Z")

</div>

@vaishnav we installed RKE 2.8 using bootstrap UI on local VMs.  
As you suggested we edited cluster config to add private registries as one of the mirrors.  
The private registry Harbour is configured only for http.  
We are still seeing same issue with ImageBackOff with message " gave HTTP response to HTTPS client".  
Is http supported by Rancher/Kubernetes for private registries?

---

<div class="post-metadata">

**Author:** ![sohil344](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/sohil344/32/10963_2.png) [@sohil344](https://forums.suse.com/u/sohil344)\
**Post date:** [February 16, 2024, 1:06pm UTC](https://forums.suse.com/t/how-can-i-resolve-server-gave-http-response-to-https-client/39225/6 "2024-02-16T13:06:45Z")

</div>

@vaishnav As Govind mentioned in config registries we have added our local registry ip in mirror section and also created regstriy secrets im attaching few images from config.yaml, error image from pods and also deployment yaml file images.

 ![image](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/8/88701b6548aeac3c9809f37164357b4c3a0a31b2.png)

this is yaml file where we are trying to fetch image

---

<div class="post-metadata">

**Author:** ![sohil344](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/sohil344/32/10963_2.png) [@sohil344](https://forums.suse.com/u/sohil344)\
**Post date:** [February 16, 2024, 1:07pm UTC](https://forums.suse.com/t/how-can-i-resolve-server-gave-http-response-to-https-client/39225/7 "2024-02-16T13:07:23Z")

</div>

![image](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/2/24573664e2dbd181bdb821383bd2543cdd1517aa.png)

this config cluster registries

---

<div class="post-metadata">

**Author:** ![vaishnav](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vaishnav/32/10688_2.png) [@vaishnav](https://forums.suse.com/u/vaishnav)\
**Post date:** [February 16, 2024, 1:07pm UTC](https://forums.suse.com/t/how-can-i-resolve-server-gave-http-response-to-https-client/39225/8 "2024-02-16T13:07:43Z")

</div>

Hi @Govind_Avireddi , Is this rke2 cluster? If yes after updating the registries, can you paste the output of the registries.yaml content from one the cluster nodes? you can find it in `/etc/rancher/rke2/registries.yaml`. Please feel free to mask the actual IPs. My guess is the registries might not be configured correctly.

---

<div class="post-metadata">

**Author:** ![vaishnav](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vaishnav/32/10688_2.png) [@vaishnav](https://forums.suse.com/u/vaishnav)\
**Post date:** [February 16, 2024, 1:11pm UTC](https://forums.suse.com/t/how-can-i-resolve-server-gave-http-response-to-https-client/39225/9 "2024-02-16T13:11:14Z")

</div>

Also in the snapshot you provided I can see that the top container registry is left blank and you have selected a secret for authentication? Can you please explain what it is? Because the registry is empty and you are providing authentication for the same. Can you put your rancher system-default-registry IP(if provided while installing rancher) there and check?

---

<div class="post-metadata">

**Author:** ![sohil344](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/sohil344/32/10963_2.png) [@sohil344](https://forums.suse.com/u/sohil344)\
**Post date:** [February 16, 2024, 1:16pm UTC](https://forums.suse.com/t/how-can-i-resolve-server-gave-http-response-to-https-client/39225/10 "2024-02-16T13:16:24Z")

</div>

> [@vaishnav](#):
>
> /etc/rancher/rke2/registries.yaml

file consist:

{“configs”:{“172.22.100.185”:{“auth”:{“username”:“user”,“password”:“Pass”,“auth”:“”,“identity\_token”:“”},“tls”:{“ca\_file”:“”,“cert\_file”:“”,“key\_file”:“”,“insecure\_skip\_verify”:true}}},“mirrors”:{“…100.185”:{“endpoint”:[“http://…100.185:8080”]}}}

---

<div class="post-metadata">

**Author:** ![vaishnav](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vaishnav/32/10688_2.png) [@vaishnav](https://forums.suse.com/u/vaishnav)\
**Post date:** [February 19, 2024, 5:24am UTC](https://forums.suse.com/t/how-can-i-resolve-server-gave-http-response-to-https-client/39225/11 "2024-02-19T05:24:44Z")

</div>

Hi @sohil344 , Do you have just one repository in your harbour registry where all your images are present? Also is this airgapped setup?  
Can you please add the registry that you used while installing rancher(system-default-registry) in the container registry field(The first field in the registry config snapshot in Rancher UI you sent above) which is currently empty? Also add it in the mirrors as well just like you added the other registry. **Please add the registry hostname as IP:PORT**. I can see in the snapshot you have added only the IP. In the config section please add both the registry hostnames and passwords and save the config.

If this does not work, request you to share the output of `/var/lib/rancher/rke2/agent/etc/containerd/config/toml` masking all the sensitive information.

---

<div class="post-metadata">

**Author:** ![Govind\_Avireddi](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/govind_avireddi/32/10940_2.png) [@Govind\_Avireddi](https://forums.suse.com/u/Govind_Avireddi)\
**Post date:** [February 19, 2024, 6:29am UTC](https://forums.suse.com/t/how-can-i-resolve-server-gave-http-response-to-https-client/39225/12 "2024-02-19T06:29:21Z")

</div>

We edited /etc/rancher/rke2/registries.yaml with following:

```yaml
configs:
  "xx.xx.100.185:8080":
    auth:
      username: sabc.yxz
      password: letmein@123
mirrors:
  xx.xx.100.185:8080:
    endpoint:
      - "http://xx.xx.100.185:8080"

```

After rebooting master and worker node, these changes were overwritten.  
We went to Rancher UI and edited cluster config in YAML format under “registries” section to add the same contents. After saving YAML changes in the UI, they get reverted back to old settings.

We also referred this link but our changes according to this page are getting overwritten: [Containerd Registry Configuration | RKE2](https://docs.rke2.io/install/containerd_registry_configuration)

---

<div class="post-metadata">

**Author:** ![Govind\_Avireddi](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/govind_avireddi/32/10940_2.png) [@Govind\_Avireddi](https://forums.suse.com/u/Govind_Avireddi)\
**Post date:** [February 19, 2024, 6:38am UTC](https://forums.suse.com/t/how-can-i-resolve-server-gave-http-response-to-https-client/39225/13 "2024-02-19T06:38:25Z")

</div>

After we made changes to mirror section using Rancher UI config form, we are able to create pods pulling images from private registry.  
Thank you very much @vaishnav for the help.

---

<div class="post-metadata">

**Author:** ![vaishnav](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vaishnav/32/10688_2.png) [@vaishnav](https://forums.suse.com/u/vaishnav)\
**Post date:** [February 19, 2024, 7:01am UTC](https://forums.suse.com/t/how-can-i-resolve-server-gave-http-response-to-https-client/39225/14 "2024-02-19T07:01:35Z")

</div>

Glad to know it worked @Govind_Avireddi . The reason the changes are getting overwritten is because this a rancher managed cluster. When you restart the service or reboot the node, all the configurations will be pulled from the Rancher Manager where the registry configuration might be different. Manually editing the registry.yaml should only be done if it is a standalone RKE2 cluster and not a Rancher Managed cluster since upon service restart it will the configurations which are configured from the UI.
