New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Kata: Mention incompatibility with host-reachable services or strict KPR in documentation #15589
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for documenting this. Couple of minor nits.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I meant to request changes, but with those small fixups sorted we can merge this.
Switching back to draft while @qmonnet is out. |
Host-reachable services are not supported with Kata containers at this time. This is because they use socket-based load-balancing which requires hooking in the kernel at the socket level in the pods, but Kata containers are VMs with their own kernels, making it impossible. Kube-proxy replacement in strict mode implies host-reachable services, and is therefore not supported either. Update the documentation accordingly, to avoid users stumbling on it. Signed-off-by: Quentin Monnet <quentin@isovalent.com>
Host-reachable services are not supported with Kata containers at this time. This is because they use socket-based load-balancing which requires hooking in the kernel at the socket level in the pods, but Kata containers are VMs with their own kernels, making it impossible.
Kube-proxy replacement in strict mode implies host-reachable services, and is therefore not supported either.
Update the documentation accordingly, to avoid users stumbling on it.
Preview: