Okta Access Gateway Admin UI Is Inaccessible From Worker Nodes
Last Updated:
Overview
Okta Access Gateway (OAG) restricts Admin UI access to the admin node by design, preventing access from worker nodes. Administrators must configure DNS entries to point the Admin UI public domain directly to the admin node, rather than using a load balancer. When an administrator attempts to access the OAG Admin UI from a worker node, Okta displays one of two error messages depending on the accessed application.
Okta displays the following error when an administrator accesses the local admin application.
The Admin dashboard is not available on this worker node
Okta displays the following error when an administrator accesses the Admin UI Security Assertion Markup Language (SAML) application.
Admin UI service is not Available
The backend web Application 'Admin UI console' is not receiving user requests from Access Gateway and not available for usage.
Accessing the Admin UI from the admin node functions correctly.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Access Gateway (OAG)
- Admin UI
Cause
Okta restricts Admin UI access exclusively to the admin node by design.
Solution
How is the Okta Access Gateway Admin UI access issue resolved?
Configure the DNS entries to point the Admin UI public domain directly to the admin node by following these guidelines.
- Do not use a load balancer for the Admin UI public domain.
- Create DNS entries or modify the host file of the client to point the Admin UI public domain directly to the admin node.
