Skip to content
Browse files

Revert "Add instructions for switching to iptables-legacy (#16271)" (#…


This reverts commit 9cdaf4e.

As of kube 1.17, kubeadm is compatible with iptables-nft
  • Loading branch information
danwinship committed Mar 26, 2020
1 parent 737af65 commit 8830000213d1e969eb87ad3cc7f2c6693ca7c461
Showing with 0 additions and 32 deletions.
  1. +0 −32 content/en/docs/setup/production-environment/tools/kubeadm/
@@ -68,38 +68,6 @@ Make sure that the `br_netfilter` module is loaded before this step. This can be
For more details please see the [Network Plugin Requirements]( page.

## Ensure iptables tooling does not use the nftables backend

In Linux, nftables is available as a modern replacement for the kernel's iptables subsystem. The
`iptables` tooling can act as a compatibility layer, behaving like iptables but actually configuring
nftables. This nftables backend is not compatible with the current kubeadm packages: it causes duplicated
firewall rules and breaks `kube-proxy`.

If your system's `iptables` tooling uses the nftables backend, you will need to switch the `iptables`
tooling to 'legacy' mode to avoid these problems. This is the case on at least Debian 10 (Buster),
Ubuntu 19.04, Fedora 29 and newer releases of these distributions by default. RHEL 8 does not support
switching to legacy mode, and is therefore incompatible with current kubeadm packages.

{{< tabs name="iptables_legacy" >}}
{{% tab name="Debian or Ubuntu" %}}
# ensure legacy binaries are installed
sudo apt-get install -y iptables arptables ebtables
# switch to legacy versions
sudo update-alternatives --set iptables /usr/sbin/iptables-legacy
sudo update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy
sudo update-alternatives --set arptables /usr/sbin/arptables-legacy
sudo update-alternatives --set ebtables /usr/sbin/ebtables-legacy
{{% /tab %}}
{{% tab name="Fedora" %}}
update-alternatives --set iptables /usr/sbin/iptables-legacy
{{% /tab %}}
{{< /tabs >}}

## Check required ports

### Control-plane node(s)

0 comments on commit 8830000

Please sign in to comment.
You can’t perform that action at this time.