-
Notifications
You must be signed in to change notification settings - Fork 327
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat(transparent-proxy): deprecate argument 'redirect-inbound-port-v6' and introduce 'ip-family-mode' #8939
feat(transparent-proxy): deprecate argument 'redirect-inbound-port-v6' and introduce 'ip-family-mode' #8939
Conversation
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
… of IPv6 traffic to 15006, the same as ipv4 redirection port Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
pkg/plugins/runtime/k8s/webhooks/injector/testdata/inject.01.golden.yaml
Show resolved
Hide resolved
pkg/plugins/runtime/k8s/webhooks/injector/testdata/inject.33.input.yaml
Outdated
Show resolved
Hide resolved
pkg/plugins/runtime/k8s/webhooks/injector/testdata/inject.34.input.yaml
Outdated
Show resolved
Hide resolved
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
…d port onto dataplane objects Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Few suggestions around UPGRADE.md.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Just one nitpick.
…aplane.proto Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
…passthrough user set value for ipv6 on injector) Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
…direct port at entry level, they will be handled at execution layer(cni/transparentproxy/xds)
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
All of this works of course, but if we can expose ipv4 and v6 on the same port wouldn't it be simpler to just change the default here?
# Redirect port for inbound traffic.
redirectPortInbound: 15006 # ENV: KUMA_RUNTIME_KUBERNETES_INJECTOR_SIDECAR_CONTAINER_REDIRECT_PORT_INBOUND
# Redirect port for inbound traffic.
redirectPortInboundV6: 15010 # ENV: KUMA_RUNTIME_KUBERNETES_INJECTOR_SIDECAR_CONTAINER_REDIRECT_PORT_INBOUND_V6
so v6 and v4 is on the same port?
Technically yes, but it needs people to configure it and they don't know what will be the side effects of doing so. So I guess poeple would normally not do this. |
…rk whether ipv6 traffic redirection should be enabled Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
783a71b
to
2659937
Compare
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
2659937
to
7712abd
Compare
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
8f58fec
to
77f0c90
Compare
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
77f0c90
to
063bc90
Compare
…ipFamilyMode on dataplane Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
60b6b5f
to
9b079b6
Compare
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
6adea22
to
d44aee8
Compare
Signed-off-by: Jay Chen <1180092+jijiechen@users.noreply.github.com>
fixes #4562
Checklist prior to review
Deprecate support for
redirect-inbound-port-v6
#4562syscall.Mkfifo
have equivalent implementation on the other OSci/
labels to run additional/fewer testsUPGRADE.md
?