-
Notifications
You must be signed in to change notification settings - Fork 7.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
v1.22.0 ambient inject iptables rules in pod failed for CentOS 7 #51030
Comments
I think you need xt_connmark https://istio.io/latest/docs/setup/platform-setup/prerequisites/#kernel-module-requirements-on-cluster-nodes. Note that doc will need to be updated to say it's needed for ambient as well |
oops, missed where you said you have that |
cc @bleggett |
This is an extremely old version of linux/iptables (1.4 is from 2012), and centos7 is ~1 month away from EOL. It might be because the container iptables binary and the host kernel are just too far out of skew. I'll see if I can repro locally with Centos7 |
Hi @escoffier - given centOS 7 is going to be end of life soon, could you reproduce it on a newer centOS version? Also, do you have this prob for sidecars? |
I can't repro this in a centos7 Docker image, with iptables
Naturally, since it's a docker image, the underlying kernel is much newer ( Since @escoffier unless you can repro this with a kernel/OS that's not on the verge of being EOL'd, we probably aren't going to fix this. |
thanks, i‘am trying to upgrade kernel. |
Thanks for responding. it works fine on newer centOS version and for sidecar. |
Thanks @escoffier! Seems we should document this as a limitation for centOS 7 under https://istio.io/latest/docs/ambient/install/platform-prerequisites/? PR would be welcome! |
No, we need to update https://istio.io/latest/docs/setup/platform-setup/prerequisites/#kernel-module-requirements-on-cluster-nodes as @howardjohn mentioned. Also, this isn't ambient specific, really. I can do a pass on that doc. Edit: istio/istio.io#15109 |
Doc PR: istio/istio.io#15121 |
Closing this as WONTFIX for centos7 specifically - doc PR is merged. |
Is this the right place to submit this?
Bug Description
When adding a pod into ambient mesh, istio-cni-node log the follwing err:
node os version:
CentOS Linux 7 (Core) 3.10.0-1160.el7.x86_64
node iptables version:
connmark module is loaded
Version
Additional Information
No response
The text was updated successfully, but these errors were encountered: