This repository has been archived by the owner on Apr 17, 2019. It is now read-only.
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #1612 from jlebon/pr/adapt-for-iptables-mode
Automatic merge from submit-queue iptables: adapt for new iptables mode In the new "iptables" mode of kube-proxy, packets addressed for a node port will get DNAT'ed to one of the endpoints. If that endpoint does not reside on the node, then flannel needs to be able to do the proxying to the endpoint. We generalize and add flannel rules for this. If the endpoint does reside on the node, then the packet will be addressed to the docker bridge, in which case we need to allow it. We modify the node rules for this. The previous node rules there are no longer needed (they were only relevant in the "userspace" mode).
- Loading branch information
Showing
4 changed files
with
39 additions
and
5 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters