LokiVLProxyBackendUnreachable
- Signal: sustained
502responses from proxy to clients. - Likely causes: VictoriaLogs outage, network/DNS path break, backend auth mismatch.
- Not every
502means the backend is down: raw metric queries that exceed-manual-range-metric-row-limitor the-max-stats-query-seriesseries cap during sample collection are rejected with502(errorType: unavailable). Check the error message before treating the backend as unreachable.
Triage​
kubectl -n <ns> exec <proxy-pod> -- wget -qO- http://<victorialogs>:9428/health- Validate
-backendURL, DNS resolution, and network policy. - Validate backend auth headers/credentials used by proxy.
- Check backend saturation and error logs.
- Search proxy logs for
request errorentries withlimit exceeded; if they dominate, the502s are execution-limit rejections for oversized queries, not backend unavailability. Narrow the offending queries (selector, range or grouping) rather than failing over the backend.
Mitigation​
- Restore backend service/network reachability.
- Fix backend auth credentials or forwarded headers.
- Fail over to healthy backend if your topology supports it.
Recovery Criteria​
502rate returns to baseline.- Proxy readiness remains stable.
- Circuit breaker closes and stays closed.
Prevention​
Apply Deployment And Scaling Best Practices for backend health probes, network path hardening, and failover readiness.