kubectl "Context Deadline Exceeded" — API Server Too Slow or Unreachable

kubectl gave up waiting on the API server. Two flavors: unreachable entirely (network/firewall/cert) or reachable-but-slow (overloaded control plane, huge list requests).

What you'll see

Root causes

Wrong or unreachable endpoint

kubectl config view --minify shows the actual server URL; the cluster IP may be private (VPN off), the port moved (kind/minikube restart), or a corporate proxy intercepts the connection.

Control plane overloaded or a huge request

kubectl get all or fetching many objects with -o wide across a big cluster hits the default request timeout. The API is reachable; the request is just heavy.

Fix it

  1. Check which endpoint kubectl is actually using
    kubectl config current-context && kubectl config view --minify | grep server
  2. Test raw reachability to that endpoint
    nc -zv -w 5 <server-host> 6443 ; curl -k --max-time 5 https://<server>:6443/version
  3. Extend timeouts for known-heavy operations
    kubectl get pods --all-namespaces --request-timeout=60s --v=8 2>&1 | tail -5
  4. Local clusters: verify the cluster/container runtime is actually up
    docker ps | grep -E 'kind|kindest|minikube' ; minikube status 2>/dev/null || kind get clusters 2>/dev/null

Field note

kubectl's default request timeout is none for gets (waits on the server) — the 'context deadline exceeded' you see in CI usually comes from --request-timeout set explicitly, or the client SDK's deadline. After a VPN switch, cached cluster IPs may route differently: re-run with --v=8 and read where the TCP dial actually goes.

Common questions

Why do small commands work but 'kubectl get all' times out?

get all issues many list requests; on a loaded control plane or huge cluster the aggregate exceeds the timeout. Scope namespaces, raise --request-timeout, or use the watch/server-side methods instead.

How do I tell network problems from a slow API server?

curl -k https://<server>:6443/version — instant answer = network fine, it's request weight. Connection timeout = network/routing/VPN. Then dig into the failing layer, not kubectl.

Ship it right the first time

Kustomize base with probes, PDBs, and zero-downtime rollouts already wired.

Kubernetes Production Blueprints — $27 →

One-time. Yours to modify. Instant download from the NinjaOps template store.