Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
don't forward GCP health checkers traffic
The way that Openshift configures the VIPs differs from GCP, and instead uses DNAT with conntrack. The GCP health checkers poll the VMs with LB backends to know its status. This traffic is wrongly DNATed sometimes, and it create stale entries in conntrack that cause network interruptions. The healthcheck traffic can never be forwarded inside the VM, so we just drop it, allowing only it when is directed to the host. Signed-off-by: Antonio Ojea <aojea@redhat.com>
- Loading branch information