New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

kube-proxy is broken by iptables 1.6.1 -> 1.6.2 #35544

srhb opened this Issue Feb 25, 2018 · 2 comments


None yet
2 participants

srhb commented Feb 25, 2018

Issue description

This is mostly a reminder to follow up on what upstream decides to do.

Since iptables 1.6.2, iptables-restore fails instead of ignoring erroneous arguments, specifically -w5 which kube-proxy has been (erroneously) using instead of -w 5. This causes its firewall rules to fail along with k8s networking in general.


Steps to reproduce

Run eg. the dns.multinode test.

@srhb srhb self-assigned this Feb 25, 2018


This comment has been minimized.


srhb commented Mar 9, 2018

More tracking links:


I might go ahead and patch this or include an older iptables-restore with kube-proxy if this doesn't get resolved upstream in time for 18.03


This comment has been minimized.


cstrahan commented Mar 17, 2018

Resolved in #36739.

@cstrahan cstrahan closed this Mar 17, 2018

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment