Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

kube-proxy does not honor ipvs excludeCIDRs #85799

Closed
stephan2012 opened this issue Dec 2, 2019 · 4 comments

Comments

@stephan2012
Copy link

@stephan2012 stephan2012 commented Dec 2, 2019

What happened: kube-proxy does not honor excludeCIDRs for ipvs mode and deletes excluded services.

What you expected to happen: kube-proxy should not touch services listed in excludeCIDRs.

How to reproduce it (as minimally and precisely as possible): Configure IPVS, add some Real Server, configure excludeCIDRs. kube-proxy logs still show

I1202 12:59:10.451889       1 proxier.go:1694] Delete service 192.168.100.107:53/TCP
I1202 12:59:10.451957       1 proxier.go:1694] Delete service 192.168.100.107:53/UDP

Anything else we need to know?: This is exactly what is described in #76267 but happens in Kubernetes 1.15.4. Regression?

Environment:

  • Kubernetes version (use kubectl version): 1.15.4
  • Cloud provider or hardware configuration: N/A
  • OS (e.g: cat /etc/os-release): Ubuntu 18.04.3 LTS
  • Kernel (e.g. uname -a): inux n0200 5.0.0-36-generic #39~18.04.1-Ubuntu SMP Tue Nov 12 11:09:50 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
  • Install tools: kubeadm
  • Network plugin and version (if this is a network-related bug): Calico
  • Others:
@stephan2012

This comment has been minimized.

Copy link
Author

@stephan2012 stephan2012 commented Dec 2, 2019

@kubernetes/sig-network-bugs

@k8s-ci-robot k8s-ci-robot added sig/network and removed needs-sig labels Dec 2, 2019
@k8s-ci-robot

This comment has been minimized.

Copy link
Contributor

@k8s-ci-robot k8s-ci-robot commented Dec 2, 2019

@stephan2012: Reiterating the mentions to trigger a notification:
@kubernetes/sig-network-bugs

In response to this:

@kubernetes/sig-network-bugs

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@athenabot

This comment has been minimized.

Copy link

@athenabot athenabot commented Dec 2, 2019

/triage unresolved

Comment /remove-triage unresolved when the issue is assessed and confirmed.

🤖 I am a bot run by vllry. 👩‍🔬

@stephan2012

This comment has been minimized.

Copy link
Author

@stephan2012 stephan2012 commented Dec 4, 2019

Cannot reproduce it anymore, likely a syntax error in kube-proxy ConfigMap. Works for me.

@stephan2012 stephan2012 closed this Dec 4, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
3 participants
You can’t perform that action at this time.