-
Notifications
You must be signed in to change notification settings - Fork 24
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Configure conntrack cache table size #280
Conversation
1f52315
to
bf64bc5
Compare
28efb0d
to
2b3a698
Compare
PR updated.. |
|
||
Network Policy agent maintains a local conntrack cache. This configuration (in seconds) will determine how fast the local conntrack cache should be cleaned up from stale/expired entries. Based on the time interval set, network policy agent checks every entry in the local conntrack cache with kernel conntrack table and determine if the entry has to be deleted. | ||
|
||
#### `conntrack-table-cache-size` (from v1.1.3+) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@jayanthvn There's a typo in README.md
.
It should be --conntrack-cache-table-size
, not --conntrack-table-cache-size
to avoid falling into CrashLoopBackOff status.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks, will fix this up
Issue #, if available: n/a
Description of changes: Provide a mechanism to increase conntrack cache size to match kernel conntrack table size
Note, this configuration should be made on new nodes before enabling network policy or if network policy is already enabled this would need a reload of the nodes. Dynamic update of conntrack map size would lead to traffic disruption hence we won't support it now..
We also have a floor and ceil for the configuration -
By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.