# Can not get client real ip in kubernetes on AWS ELB

**URL:** <https://discuss.konghq.com/t/can-not-get-client-real-ip-in-kubernetes-on-aws-elb/4925>\
**Category:** Questions\
**Tags:** kubernetes\
**Created:** [November 15, 2019, 12:59pm UTC](https://discuss.konghq.com/t/can-not-get-client-real-ip-in-kubernetes-on-aws-elb/4925 "2019-11-15T12:59:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mju](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/mju/32/922_2.png) [@Mju](https://discuss.konghq.com/u/Mju)\
**Post date:** [November 15, 2019, 12:59pm UTC](https://discuss.konghq.com/t/can-not-get-client-real-ip-in-kubernetes-on-aws-elb/4925/1 "2019-11-15T12:59:38Z")

</div>

We are using kong as our ingress controller with service type LoadBalancer. Kong is deployed using helm chart.

```auto
kind: Service
metadata:
  annotations:
    service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: '*'
  labels:
    app: kong
    chart: kong-0.23.0
    heritage: Tiller
    release: ota-kong
  name: ota-kong-kong-proxy
  namespace: default
spec:
  externalTrafficPolicy: Local
  healthCheckNodePort: 31645
  ports:
  - name: kong-proxy
    nodePort: 32767
    port: 80
    protocol: TCP
    targetPort: 8000
  - name: kong-proxy-tls
    nodePort: 32018
    port: 443
    protocol: TCP
    targetPort: 8443
  selector:
    app: kong
    component: app
    release: ota-kong
  sessionAffinity: None
  type: LoadBalancer

```

We still cannot see actual client IP in kong proxy logs. We also have set the following environment variables  
env:  
database: postgres  
proxy\_listen: 0.0.0.0:8000, 0.0.0.0:8443 ssl proxy\_protocol  
trusted\_ips: 0.0.0.0/0,::/0  
real\_ip\_recursive: “on”  
real\_ip\_header: X-Forwarded-For

The above environment variables are passed from the value.yaml file and I can confirm KONG\_TRSUTED\_IPS, KONG\_REAL\_IP\_RECURSIVE, KONG\_REAL\_IP\_HEADER are set inside the kong proxy pod.

---

<div class="post-metadata">

**Author:** ![Mju](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/mju/32/922_2.png) [@Mju](https://discuss.konghq.com/u/Mju)\
**Post date:** [November 16, 2019, 3:49pm UTC](https://discuss.konghq.com/t/can-not-get-client-real-ip-in-kubernetes-on-aws-elb/4925/2 "2019-11-16T15:49:27Z")

</div>

@hbagdi any suggestion on what might be wrong will be really helpful. Thanks in advance.

---

<div class="post-metadata">

**Author:** ![thatbenguy](https://avatars.discourse-cdn.com/v4/letter/t/77aa72/32.png) [@thatbenguy](https://discuss.konghq.com/u/thatbenguy)\
**Post date:** [November 21, 2019, 3:37am UTC](https://discuss.konghq.com/t/can-not-get-client-real-ip-in-kubernetes-on-aws-elb/4925/3 "2019-11-21T03:37:19Z")

</div>

Not sure this will work completely as I think some lua will need to be slung to fully take advantage of this… I am investigating further: [How to Forward Client's request IP](https://discuss.konghq.com/t/how-to-forward-clients-request-ip/384/2)

---

<div class="post-metadata">

**Author:** ![abenitovsc](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/abenitovsc/32/1521_2.png) [@abenitovsc](https://discuss.konghq.com/u/abenitovsc)\
**Post date:** [November 22, 2019, 10:59pm UTC](https://discuss.konghq.com/t/can-not-get-client-real-ip-in-kubernetes-on-aws-elb/4925/4 "2019-11-22T22:59:47Z")

</div>

Hi,

I have solved this issue recently, you should just setting two env variables in Kong.

real\_ip\_header: X-Forwarded-For (Right, you have it)  
trusted\_ips: “YOUR ELB VPC CIDR“

by this way Nginx uses the module ngx\_http\_realip\_module reading the Forwarded IP and updating the remote\_addr with the first IP (client IP). After this change, Nginx traces will displace client public IP instead of ELB IPs. Kong will only serve requests forwarded from you load balancer.

---

<div class="post-metadata">

**Author:** ![Mju](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/mju/32/922_2.png) [@Mju](https://discuss.konghq.com/u/Mju)\
**Post date:** [November 23, 2019, 1:29pm UTC](https://discuss.konghq.com/t/can-not-get-client-real-ip-in-kubernetes-on-aws-elb/4925/5 "2019-11-23T13:29:08Z")

</div>

Thanks @abenitovsc will give it a try and update here if i am able to get this working.

---

<div class="post-metadata">

**Author:** ![abenitovsc](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/abenitovsc/32/1521_2.png) [@abenitovsc](https://discuss.konghq.com/u/abenitovsc)\
**Post date:** [November 23, 2019, 3:17pm UTC](https://discuss.konghq.com/t/can-not-get-client-real-ip-in-kubernetes-on-aws-elb/4925/6 "2019-11-23T15:17:20Z")

</div>

Hi @Mju, i have just realized that trusted\_ips content was escaped with \<  
I have updated my last comment. Tell us with the feedback. You can deploy this app to check the headers.  
[https://hub.docker.com/r/brndnmtthws/nginx-echo-headers/](https://hub.docker.com/r/brndnmtthws/nginx-echo-headers/)

You will see that the X-Real-IP set by kong from the remote\_addr is the first IP in the forwarded-for header (clientIP) instead of the last one(IP from the ELB CIDR).
