# Kong ingress controller with k3s, "forwarded\_ip" not forwarded

**URL:** <https://discuss.konghq.com/t/kong-ingress-controller-with-k3s-forwarded-ip-not-forwarded/7013>\
**Category:** Questions\
**Created:** [August 31, 2020, 5:26pm UTC](https://discuss.konghq.com/t/kong-ingress-controller-with-k3s-forwarded-ip-not-forwarded/7013 "2020-08-31T17:26:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dlmn](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@dlmn](https://discuss.konghq.com/u/dlmn)\
**Post date:** [August 31, 2020, 5:26pm UTC](https://discuss.konghq.com/t/kong-ingress-controller-with-k3s-forwarded-ip-not-forwarded/7013/1 "2020-08-31T17:26:50Z")

</div>

Hi all

The installation is based on k3s on a bare metal debian instance.

```
export INSTALL_K3S_VERSION=v1.18.8+k3s1;
curl -sfL https://get.k3s.io | INSTALL_K3S_EXEC="server --disable traefik" sh

```

The installation of kong ingress was done according to the file [https://bit.ly/k4k8s](https://bit.ly/k4k8s) with a few adoptions:

```
spec:
  containers:
    - env:
        - name: KONG_TRUSTED_IPS
          value: 0.0.0.0/0,::/0
        - name: KONG_REAL_IP_RECURSIVE
          value: "on"

```

I deployed the echo service and configured a route accordingly. However, the ip address is still not the external one.

x-forwarded-for=10.42.0.1  
x-real-ip=10.42.0.1

Also the variable “kong.client.get\_forwarded\_ip()” is 10.42.0.1 in the serverless function context.

What did I miss here? I haven’t found more information on that topic. Any help is appreciated, as knowing the ip is crutial for the application due to geolocation features (currencies, etc.).

Thank you!

---

<div class="post-metadata">

**Author:** ![hbagdi](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/hbagdi/32/562_2.png) [@hbagdi](https://discuss.konghq.com/u/hbagdi)\
**Post date:** [August 31, 2020, 5:55pm UTC](https://discuss.konghq.com/t/kong-ingress-controller-with-k3s-forwarded-ip-not-forwarded/7013/2 "2020-08-31T17:55:56Z")

</div>

This guide might be useful to you: [https://github.com/Kong/kubernetes-ingress-controller/blob/master/docs/guides/preserve-client-ip.md](https://github.com/Kong/kubernetes-ingress-controller/blob/master/docs/guides/preserve-client-ip.md)

---

<div class="post-metadata">

**Author:** ![dlmn](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@dlmn](https://discuss.konghq.com/u/dlmn)\
**Post date:** [August 31, 2020, 6:22pm UTC](https://discuss.konghq.com/t/kong-ingress-controller-with-k3s-forwarded-ip-not-forwarded/7013/3 "2020-08-31T18:22:02Z")

</div>

Thanks Harry,

I don’t have (yet) a loadbalancer in front of the k3s installation and I’m aware that that’s not the purpose of distributed systems. So in my case, client requests hit port 80/443 of k3s with kong for the time being.

As traefik is disabled I assumed kong would have the information of the client request.

I haven’t found more information about this topic so far: [Design](https://github.com/Kong/kubernetes-ingress-controller/blob/main/docs/concepts/design.md)

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![hbagdi](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/hbagdi/32/562_2.png) [@hbagdi](https://discuss.konghq.com/u/hbagdi)\
**Post date:** [September 1, 2020, 4:13pm UTC](https://discuss.konghq.com/t/kong-ingress-controller-with-k3s-forwarded-ip-not-forwarded/7013/4 "2020-09-01T16:13:37Z")

</div>

In that case, you need to figure out how is traffic being routed to the Kong pod running inside the k3s cluster and then see how to preserve the IP address.

ExternalTrafficPolicy setting on Service might help in this case.

---

<div class="post-metadata">

**Author:** ![dlmn](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@dlmn](https://discuss.konghq.com/u/dlmn)\
**Post date:** [September 1, 2020, 6:09pm UTC](https://discuss.konghq.com/t/kong-ingress-controller-with-k3s-forwarded-ip-not-forwarded/7013/5 "2020-09-01T18:09:43Z")

</div>

I found the solution based on your reply. The traffic policy was indeed missing. I assumed that this was not supported by k3s. By adding

` externalTrafficPolicy: Local`

to the kong-proxy service, I got it working.

Thank you very much!
