# Drone Server docker image cannot make SSL requests

**URL:** <https://drone.discourse.group/t/drone-server-docker-image-cannot-make-ssl-requests/11148>\
**Category:** Drone Support\
**Created:** [August 5, 2020, 5:57pm UTC](https://drone.discourse.group/t/drone-server-docker-image-cannot-make-ssl-requests/11148 "2020-08-05T17:57:13Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mattouille](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/mattouille/32/5746_2.png) [@mattouille](https://drone.discourse.group/u/mattouille)\
**Post date:** [August 5, 2020, 5:57pm UTC](https://drone.discourse.group/t/drone-server-docker-image-cannot-make-ssl-requests/11148/1 "2020-08-05T17:57:13Z")

</div>

Hey folks, I spun up a drone server on Kubernetes using both Helm and some custom created manifests. I discovered rather quickly that in either scenario SSL/TLS based outbound calls are failing. This was especially evident when I was trying to get OAuth setup between Gitea and Drone.

Upon further inspection, I obtained a shell to the container, installed curl and wget and was unable to make calls to Gitea:

```
/ # curl https://git.domain.io -v
* Trying <ip address>:443...
* TCP_NODELAY set
* Connected to git.domain.io (<ip address>) port 443 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* successfully set certificate verify locations:
* CAfile: /etc/ssl/certs/ca-certificates.crt
  CApath: none
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to git.domain.io:443 
* Closing connection 0
curl: (35) OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to git.domain.io:443 

```

Drone consistently reports “connection reset by peer” and I think this may be the source.

Gitea Version: 1.11.5  
Drone Version: 1.8.1

---

<div class="post-metadata">

**Author:** ![mattouille](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/mattouille/32/5746_2.png) [@mattouille](https://drone.discourse.group/u/mattouille)\
**Post date:** [August 5, 2020, 10:20pm UTC](https://drone.discourse.group/t/drone-server-docker-image-cannot-make-ssl-requests/11148/2 "2020-08-05T22:20:14Z")

</div>

@bradrydzewski can we move this back to bug? I’ve at least proved that something is wrong with the docker image.

---

<div class="post-metadata">

**Author:** ![bradrydzewski](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/bradrydzewski/32/3513_2.png) [@bradrydzewski](https://drone.discourse.group/u/bradrydzewski)\
**Post date:** [August 5, 2020, 10:47pm UTC](https://drone.discourse.group/t/drone-server-docker-image-cannot-make-ssl-requests/11148/3 "2020-08-05T22:47:42Z")

</div>

Hi @mattouille can you please provide more information? We run the Drone server image at [cloud.drone.io](http://cloud.drone.io) and we do not have any issues with SSL.

---

<div class="post-metadata">

**Author:** ![mattouille](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/mattouille/32/5746_2.png) [@mattouille](https://drone.discourse.group/u/mattouille)\
**Post date:** [August 5, 2020, 10:54pm UTC](https://drone.discourse.group/t/drone-server-docker-image-cannot-make-ssl-requests/11148/4 "2020-08-05T22:54:03Z")

</div>

@bradrydzewski I’m honestly a bit stuck in what to troubleshoot next.

For instance:

```
/ # openssl s_client -connect git.domain.io:443 -servername git.domain.io
CONNECTED(00000003)
write:errno=104
---
no peer certificate available
---
No client certificate CA names sent
---
SSL handshake has read 0 bytes and written 320 bytes
Verification: OK
---
New, (NONE), Cipher is (NONE)
Secure Renegotiation IS NOT supported
No ALPN negotiated
Early data was not sent
Verify return code: 0 (ok) 

```

To me, it looks like everything is fine with my certificate. I am using LetsEncrypt for this domain, and that’s managed by cert-manager.

---

<div class="post-metadata">

**Author:** ![mattouille](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/mattouille/32/5746_2.png) [@mattouille](https://drone.discourse.group/u/mattouille)\
**Post date:** [August 5, 2020, 11:28pm UTC](https://drone.discourse.group/t/drone-server-docker-image-cannot-make-ssl-requests/11148/5 "2020-08-05T23:28:37Z")

</div>

It looks like openssl may not be detecting my certificate, but outside services do. I’m going to keep my troubleshooting scoped to the container, as that seems to be the problem.

---

<div class="post-metadata">

**Author:** ![mattouille](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/mattouille/32/5746_2.png) [@mattouille](https://drone.discourse.group/u/mattouille)\
**Post date:** [August 5, 2020, 11:51pm UTC](https://drone.discourse.group/t/drone-server-docker-image-cannot-make-ssl-requests/11148/6 "2020-08-05T23:51:56Z")

</div>

I’m happy to pay for support if it’ll get me some help in troubleshooting this. None of the other applications on my cluster suffer from this, including applications I’ve written myself.
