-
Notifications
You must be signed in to change notification settings - Fork 7.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
cannot create new pod in an ambient labeled namespace in ebpf mode #47876
Comments
Interesting, could you provide some context and could this bug be reproduced? which pod was restarted? and where is the error message from? |
It's 100% reproducible, my CRI sandbox is cri-dockerd, CNI is calico 3.26.3, any pod cannot be successfully created if the namespace is injected by ambient, the error log is the retrieved from the pod's log, it can also be found in kubelet's journal. |
Try to stop calico, then restart, I think the problem may be from calico, something incompatible. I will give it a try |
Is ebpf mode comptabible with calico now, there is a issue saying calico can not work with ambient yet |
Calico works well with Istio Ambient in eBPF mode; however, in normal mode, it has network issues. |
@KfreeZ Have you followed these steps? https://github.com/istio/istio/tree/master/manifests/charts/istio-cni#calico |
@hzxuzhonghu @hanxiaop yes, eBPF mode is "half working" for me with the latest istio(1.20) and the |
I'm working on this and have found some clues. Will update later. |
Is this the right place to submit this?
Bug Description
I have an ambient mesh setup in ebpf redirection mode,
It works when I following this sequence,
But when I restart the application pod in the namespace (default), I encountered below error:
Version
Additional Information
No response
The text was updated successfully, but these errors were encountered: