Delayed identity cleanup on operator restart #28339
Labels
affects/v1.12
This issue affects v1.12 branch
kind/bug
This is a bug in the Cilium logic.
kind/community-report
This was reported by a user in the Cilium community, eg via Slack.
sig/agent
Cilium agent related.
sig/policy
Impacts whether traffic is allowed or denied based on user-defined policies.
stale
The stale bot thinks this issue is old. Add "pinned" label to prevent this from becoming stale.
Is there an existing issue for this?
What happened?
On operator start up, all identities are marked as alive irrespective of whether an identity has the delete annotation
cilium/operator/identitygc/crd_gc.go
Line 52 in bb6decf
The delete annotation is added on an identity in
cilium/operator/identitygc/crd_gc.go
Line 125 in bb6decf
As the default heartbeat timeout is 30 minutes, an identity that was marked for deletion with an annotation is marked alive on operator start up and delays the cleanup by 30 minutes.
I think an identity with the deletion annotation should not marked alive again. Is there an issue with this?.
Cilium Version
1.12
Kernel Version
not applicable
Kubernetes Version
1.27
Sysdump
No response
Relevant log output
No response
Anything else?
No response
Code of Conduct
The text was updated successfully, but these errors were encountered: