kubectl: 'Connection Refused' on Port 6443

kubectl cannot reach the API server. Either your kubeconfig points at the wrong place, or the control plane is actually down.

What you'll see

Root causes

Wrong context / stale kubeconfig

kubecfg points at an old cluster endpoint or an IP that changed (common after node replacement).

Control plane or endpoint down

The API server pods are down, or the load balancer in front of them has no healthy backends.

Network/firewall block

VPN dropped, security group closed 6443 to your IP range.

Fix it

  1. Check which context you are actually on
    kubectl config current-context && kubectl cluster-info
  2. Compare the endpoint with what the provider says it should be
    kubectl config view --minify -o jsonpath='{.clusters[0].cluster.server}'
  3. Test raw reachability
    curl -k --max-time 5 https://<endpoint>:6443/healthz
  4. If the endpoint moved, update kubeconfig from the provider
    # e.g. for kops: kops export kubecfg --name cluster.example.com

Field note

If a plain curl to /healthz fails but the node itself is up, the problem is in front of the API server — LB or firewall — not in kubectl.

Common questions

Why is port 6443 refusing connections?

Nothing is listening at the address you're hitting: control plane down, wrong API endpoint in kubeconfig, or a firewall/security group blocking. Test the endpoint directly: nc -zv <api-host> 6443 distinguishes refused (not listening) from timeout (blocked).

It worked yesterday — what changed?

Common shifts: kubeconfig regenerated with a new endpoint, the control plane node restarted with a new IP, or a certificate expired and the API server is failing to start. kubectl config view + the cluster's control-plane logs resolve it in minutes.

Ship it right the first time

Kustomize base with probes, PDBs, and zero-downtime rollouts already wired.

Kubernetes Production Blueprints — $27 →

One-time. Yours to modify. Instant download from the NinjaOps template store.