# \[Loadbalancer\] 503 Service Unavailable

**URL:** <https://forums.suse.com/t/loadbalancer-503-service-unavailable/2180>\
**Category:** Rancher 1.x\
**Created:** [March 27, 2016, 9:07am UTC](https://forums.suse.com/t/loadbalancer-503-service-unavailable/2180 "2016-03-27T09:07:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tle06](https://avatars.discourse-cdn.com/v4/letter/t/6f9a4e/32.png) [@tle06](https://forums.suse.com/u/tle06)\
**Post date:** [March 27, 2016, 9:07am UTC](https://forums.suse.com/t/loadbalancer-503-service-unavailable/2180/1 "2016-03-27T09:07:34Z")

</div>

Hello,

I’m currently using rancher with my own owncloud service. I’m trying to access it through the rancher loadbalancer with an HTTPS connection but when I try to reach the URL **[owncloud.mydomain.fr](http://owncloud.mydomain.fr)** I have the following error: **503 Service Unavailable No server is available to handle this request**.

Ping server: OK  
Ping URL: OK  
URL [https://ipOfNode1:44365](https://ipOfNode1:44365) : OK

I have a self signed certificate inside the owncloud container and I’m using a self signed certificate in my rancher loadbalancer

Loadbalancer config:

 ![](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/9/9f67c3d5b7bccafe7750eaedf64e0f5be8c487a0.png)

I don’t get it why it’s not working, any idea?

Thank you  
A++

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [March 27, 2016, 3:25pm UTC](https://forums.suse.com/t/loadbalancer-503-service-unavailable/2180/2 "2016-03-27T15:25:44Z")

</div>

The SSL box means the balancer does SSL _termination_, so the request to the target is plaintext (but over an encrypted IPSec tunnel for managed network). So you are sending a http request to a https listening port. The target doesn’t respond, and the balancer replies 503.

The same is true about the default target for listener port 443, it should probably be 80, though nothing is apparently using the default target anyway.

If the application supports it, change the target port to the plain HTTP one. If you need SSL to the backend the you currently need to do a TCP listened and not check the SSL box. This means you can’t do hostname routing rules though because the encrypted connection goes all the way to the target and the balancer doesn’t see the host header.

The redis rule also does nothing because there is no listener for 6379, and its protocol is not HTTP-based, and it has no equivalent of a Host header to match… But this is just as well because exposing Redis to the Internet is an [explicitly bad idea](http://redis.io/topics/security).

---

<div class="post-metadata">

**Author:** ![tle06](https://avatars.discourse-cdn.com/v4/letter/t/6f9a4e/32.png) [@tle06](https://forums.suse.com/u/tle06)\
**Post date:** [March 28, 2016, 8:36pm UTC](https://forums.suse.com/t/loadbalancer-503-service-unavailable/2180/3 "2016-03-28T20:36:44Z")

</div>

Hello Vincent,

Thank a lot for your explanations.  
Is it possible to route **[owc.domain.fr](http://owc.domain.fr)** to the container over SSL with a certificate in rancher and the loadbalancer feature? My goal will be to reach **[https://owc.domain.fr](https://owc.domain.fr)** and forward all the traffic to the container.

Thank you.

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [March 28, 2016, 11:37pm UTC](https://forums.suse.com/t/loadbalancer-503-service-unavailable/2180/4 "2016-03-28T23:37:23Z")

</div>

You cannot currently do hostname-based routing and TLS/SSL connections all the way to the container. To figure out the hostname the balancer needs to terminate the TLS connection. Even without TLS, the communication between the balancer and the target service is over an AES-encrypted IPSec tunnel.

If you want TLS all the way to the container then you just want TCP load balancing, but you will lose the ability to direct requests based on hostname:

 ![](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/9/961e8e68630d7ae983d31c46920dbd1f2ab00d90.png)

---

<div class="post-metadata">

**Author:** ![tle06](https://avatars.discourse-cdn.com/v4/letter/t/6f9a4e/32.png) [@tle06](https://forums.suse.com/u/tle06)\
**Post date:** [March 29, 2016, 9:36pm UTC](https://forums.suse.com/t/loadbalancer-503-service-unavailable/2180/5 "2016-03-29T21:36:08Z")

</div>

Ok, thank a lot for the explanation, now it’s clear.

A++
