Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
bpf: Preserve source identity for hairpin via stack
When Cilium is used in chaining mode with portmap, the hostPort is translated using iptables DNAT as inserted by the portmap plugin. When this happens all within a node, we can preserve the source identity for the reply traffic for correct visibility. The traffic will be allowed anyway based on the connection tracking state. Updates: #9784 Signed-off-by: Thomas Graf <thomas@cilium.io>
- Loading branch information