-
Notifications
You must be signed in to change notification settings - Fork 2.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[FYI] Cilium not working on bottlerocket-v1.20 #32610
Comments
To add more detail on this issue, Bottlerocket moved from
This breaks module loading for Cilium between Bottlerocket versions. Is it possible for Cilium to use the host OS’s modprobe when it exists vs always using their own? |
We have the same issue with Cilium 1.15.3 |
Same issue like #32616 |
@vigh-m just posted a temporary fix for the latest bottlerocket release v1.20.1 at bottlerocket-os/bottlerocket#3968 (comment) . Can confirm that adding the following lines to
Maybe someone from cilium may track the issue over at bottlerocket? Its currently only a temp workaround and its said there will be a more permanent solution coming soon. |
@obirhuppertz We applied the fix, thanks for the hint!
Further investigation revealed that two nodes of type t3.medium fail to load the required modules during the startup:
After checking the node it turns out that the iptable_raw module is loaded, but still, the node has much less loaded module count than the other nodes. E.g. these modules are not loaded on the node: ip6table_raw, raw_diag. |
I applied @obirhuppertz fix in cilium helm and all my tests for our cilium ingresses worked fine using bottlerocket 1.20.1 and cilium 1.14.1 |
Is there an existing issue for this?
What happened?
Just letting you know so you may join the discussion over at bottlerocket-os/bottlerocket#3968
Something in bottlerocket-v1.20 seems to have changed preventing using cilium for now. Worked in v1.19.5. Seems to be a netfilter/module load issue resulting in DNS resolving issues on node where coredns is running.
Cilium Version
v1.14.9
Kernel Version
bottlerocket-v1.20
Kubernetes Version
v1.27.11-eks
Regression
No response
Sysdump
No response
Relevant log output
No response
Anything else?
No response
Cilium Users Document
Code of Conduct
The text was updated successfully, but these errors were encountered: