forked from cilium/cilium
-
Notifications
You must be signed in to change notification settings - Fork 1
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
bpf: Encap with cilium_{vxlan,geneve} before passing to WG
So that a src security ID can be transferred to a remote node (e.g., for netpol checks). This commit changes a pkt path when WireGuard + tunneling are enabled AND the newly introduced --wireguard-encapsulate is set. Previously, we had the following: ┌──────┐ 1. ┌──────┐ 4. │ lxc0 ├──────────────► eth0 ├──────► └──────┘ └─┬───▲┘ │ │ │ │ 2.│ │ 3. │ │ ┌───────────────┐ ┌───▼───┴────┐ │ cilium_vxlan │ │cilium_wg0 │ └───────────────┘ └────────────┘ With this change: ┌──────┐ ┌──────┐ │ lxc0 │ ┌──────────► eth0 ├─────► └───┬──┘ │ └─┬───▲┘ 5. │ │ │ │ │ │ │ │ 1.│ 2.│ 3. │ │ 4. │ │ │ │ ┌─────▼──────┴──┐ ┌───▼───┴────┐ │ cilium_vxlan │ │cilium_wg0 │ └───────────────┘ └────────────┘ A side effect of this change is that host-to-remote-pod traffic is going to be encrypted (previously it was not). The change was first made available in v1.14 [1] (controlled w/ --wireguard-encapsulate, which defaults to false). To avoid breaking connections during an upgrade from v1.14 to v1.15 (due to missing node IPs within allowed-ips), in v1.14 we populate those IPs regardless whether the feature is enabled. [1]: cilium#28917 Signed-off-by: Martynas Pumputis <m@lambda.lt>
- Loading branch information
Showing
4 changed files
with
45 additions
and
22 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters