# Can't deploy to Digital Ocean

**URL:** <https://community.convox.com/t/cant-deploy-to-digital-ocean/661>\
**Category:** Rack (Version 3)\
**Created:** [November 29, 2019, 9:16am UTC](https://community.convox.com/t/cant-deploy-to-digital-ocean/661 "2019-11-29T09:16:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ben](https://avatars.discourse-cdn.com/v4/letter/b/df788c/32.png) [@ben](https://community.convox.com/u/ben)\
**Post date:** [November 29, 2019, 9:16am UTC](https://community.convox.com/t/cant-deploy-to-digital-ocean/661/1 "2019-11-29T09:16:41Z")

</div>

I’m a first time user of Convox, followed the instructions [here](https://github.com/convox/convox/tree/master/install/do) and received a number of permission errors from Kubernetes:

```
Error: clusterroles.rbac.authorization.k8s.io is forbidden: User "system:anonymous" cannot create resource "clusterroles" in API group "rbac.authorization.k8s.io" at the cluster scope

  on ../../terraform/api/k8s/atom.tf line 1, in resource "kubernetes_cluster_role" "atom":
   1: resource "kubernetes_cluster_role" "atom" {

Error: clusterroles.rbac.authorization.k8s.io is forbidden: User "system:anonymous" cannot create resource "clusterroles" in API group "rbac.authorization.k8s.io" at the cluster scope

  on ../../terraform/api/k8s/main.tf line 14, in resource "kubernetes_cluster_role" "api":
  14: resource "kubernetes_cluster_role" "api" {

Error: clusterroles.rbac.authorization.k8s.io is forbidden: User "system:anonymous" cannot create resource "clusterroles" in API group "rbac.authorization.k8s.io" at the cluster scope

  on ../../terraform/fluentd/k8s/main.tf line 9, in resource "kubernetes_cluster_role" "fluentd":
   9: resource "kubernetes_cluster_role" "fluentd" {

Error: serviceaccounts is forbidden: User "system:anonymous" cannot create resource "serviceaccounts" in API group "" in the namespace "kube-system"

  on ../../terraform/fluentd/k8s/main.tf line 39, in resource "kubernetes_service_account" "fluentd":
  39: resource "kubernetes_service_account" "fluentd" {

Error: Failed to create daemonset: daemonsets.apps is forbidden: User "system:anonymous" cannot create resource "daemonsets" in API group "apps" in the namespace "kube-system"

  on ../../terraform/fluentd/k8s/main.tf line 61, in resource "kubernetes_daemonset" "fluentd":
  61: resource "kubernetes_daemonset" "fluentd" {

Error: namespaces is forbidden: User "system:anonymous" cannot create resource "namespaces" in API group "" at the cluster scope

  on ../../terraform/rack/k8s/main.tf line 9, in resource "kubernetes_namespace" "system":
   9: resource "kubernetes_namespace" "system" {

Error: clusterroles.rbac.authorization.k8s.io is forbidden: User "system:anonymous" cannot create resource "clusterroles" in API group "rbac.authorization.k8s.io" at the cluster scope

  on ../../terraform/router/k8s/main.tf line 9, in resource "kubernetes_cluster_role" "router":
   9: resource "kubernetes_cluster_role" "router" {

```

I realise this is only beta but would be nice to try it out 🙂

---

<div class="post-metadata">

**Author:** ![ed\_convox](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.convox.com/ed_convox/32/101_2.png) [@ed\_convox](https://community.convox.com/u/ed_convox)\
**Post date:** [November 29, 2019, 9:32am UTC](https://community.convox.com/t/cant-deploy-to-digital-ocean/661/2 "2019-11-29T09:32:50Z")

</div>

Hi @ben,  
Is this output from the `terraform init` or `terraform apply` ? I installed a fresh Digital Ocean rack yesterday without any issues, so interested to know and what point you’re seeing this…

Thanks,  
Ed

---

<div class="post-metadata">

**Author:** ![ben](https://avatars.discourse-cdn.com/v4/letter/b/df788c/32.png) [@ben](https://community.convox.com/u/ben)\
**Post date:** [November 29, 2019, 11:55am UTC](https://community.convox.com/t/cant-deploy-to-digital-ocean/661/3 "2019-11-29T11:55:45Z")

</div>

Thanks for the quick response @ed_convox - it’s the output from `terraform apply`.

I’ve just rerun it and get the same result: full log is [here](https://gist.github.com/bs1180/f1d0d23259923f79336d7709c82e07ad).

Cheers.

---

<div class="post-metadata">

**Author:** ![ed\_convox](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.convox.com/ed_convox/32/101_2.png) [@ed\_convox](https://community.convox.com/u/ed_convox)\
**Post date:** [November 29, 2019, 8:11pm UTC](https://community.convox.com/t/cant-deploy-to-digital-ocean/661/4 "2019-11-29T20:11:34Z")

</div>

Thanks @ben, we’re looking into this, something may have changed recently on the DO side… 😊

---

<div class="post-metadata">

**Author:** ![cameron](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.convox.com/cameron/32/24_2.png) [@cameron](https://community.convox.com/u/cameron)\
**Post date:** [December 5, 2019, 4:42am UTC](https://community.convox.com/t/cant-deploy-to-digital-ocean/661/5 "2019-12-05T04:42:29Z")

</div>

Hi @ben thanks again for reporting this and sorry for the troubles. There were some changes on the Digital Ocean side of things and we had to make some updates. If you grab the latest version of [https://github.com/convox/convox/](https://github.com/convox/convox/) which is release `3.0.0.beta36` and re-run `terraform apply` you should be all set.
