Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.Sign up
Only run connection-rejecting rules on new connections #60306
Kube-proxy has two iptables chains full of rules to reject incoming connections to services that don't have any endpoints. Currently these rules get tested against all incoming packets, but that's unnecessary; if a connection to a given service has already been established, then we can't have been rejecting connections to that service. By only checking the first packet in each new connection, we can get rid of a lot of unnecessary checks on incoming traffic.
referenced this pull request
Feb 23, 2018
[APPROVALNOTIFIER] This PR is APPROVED
The full list of commands accepted by this bot can be found here.
The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing
On Sat, Feb 24, 2018, 3:44 PM k8s-ci-robot ***@***.***> wrote: @danwinship <https://github.com/danwinship>: The following test *failed*, say /retest to rerun them all: Test name Commit Details Rerun command pull-kubernetes-unit 2259416 <2259416> link <https://k8s-gubernator.appspot.com/build/kubernetes-jenkins/pr-logs/pull/60306/pull-kubernetes-unit/82538/> /test pull-kubernetes-unit Full PR test history <https://k8s-gubernator.appspot.com/pr/60306>. Your PR dashboard <https://k8s-gubernator.appspot.com/pr/danwinship>. Please help us cut down on flakes by linking to <https://git.k8s.io/community/contributors/devel/flaky-tests.md#filing-issues-for-flaky-tests> an open issue <https://github.com/kubernetes/kubernetes/issues?q=is:issue+is:open> when you hit one in your PR. Instructions for interacting with me using PR comments are available here <https://git.k8s.io/community/contributors/devel/pull-requests.md>. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra <https://github.com/kubernetes/test-infra/issues/new?title=Prow%20issue:> repository. I understand the commands that are listed here <https://go.k8s.io/bot-commands>. — You are receiving this because you were assigned. Reply to this email directly, view it on GitHub <#60306 (comment)>, or mute the thread <https://github.com/notifications/unsubscribe-auth/AFVgVBb5ZKUTbXUms7KviyeIOItzkX6Aks5tYJ7egaJpZM4SQ6CB> .