-
Notifications
You must be signed in to change notification settings - Fork 7.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Pods with sidecar injection stuck in ContainerCreating status #15895
Comments
@mishaque Istio CNI logs into journalctl on the node. Can you grep for "nsenter" in journalctl logs? |
@mishaque more specifically look for a log containing "nsenter failed". |
@mishaque Also can you give more details about the kernel on your worker nodes? What version? Does it support iptables? nftables? |
Ok so IPv6 is disabled in your kernel? |
That is weird because the script attempts to setup ip6tables chains only if the pod has an IPv6 address. |
Thanks! So that means that the isIPv6 function in the istio-iptables.sh script is buggy. I'll fix that. |
@rlenglet is there a workaround for time being? |
@rlenglet, thanks for including this in the 1.3 milestone. I will try enabling the IPV6 on the Node as a workaround; I am not sure if this would solve the issue. Please let me know your recommendation/workaround. |
The
So there is no mis-detection of IPv6. That part is correct.
These commands are failing because of the retrying of the commands in this script. This bug is specific to Istio CNI's version of the |
No description provided.
The text was updated successfully, but these errors were encountered: