New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[release-4.9] Bug 2090624: Masquerade in cluster traffic that is marked for egress IP #433
[release-4.9] Bug 2090624: Masquerade in cluster traffic that is marked for egress IP #433
Conversation
…luster network. In a scenario where an ExternalIP/LoadBalancer is used by a pod with an egress IP configured the packets will be marked and redirected to the egress node using ovs flows. On the egress node, the traffic will be DNATed to an IP that is in the cluster network. Instead of SNATing to an egress IP masquerade the outgoing packets to ensure that the response traffic is sent back through the same node. Signed-off-by: Patryk Diak <pdiak@redhat.com> (cherry picked from commit caa3f51)
This is needed for egress IP traffic that is DNATed to a local IP(ExternalIP/LoadBalancer). This type of traffic traverses KUBE-FIREWALL chain which drops packets marked with the default drop bit. Signed-off-by: Patryk Diak <pdiak@redhat.com> (cherry picked from commit ce6a051)
@openshift-cherrypick-robot: Bugzilla bug 2082451 has been cloned as Bugzilla bug 2090624. Retitling PR to link against new bug. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
@openshift-cherrypick-robot: This pull request references Bugzilla bug 2090624, which is invalid:
Comment In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
/bugzilla refresh |
@kyrtapz: This pull request references Bugzilla bug 2090624, which is valid. The bug has been moved to the POST state. The bug has been updated to refer to the pull request using the external bug tracker. 6 validation(s) were run on this bug
Requesting review from QA contact: In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
/label qe-approved |
/cherry-pick release-4.8 |
@kyrtapz: once the present PR merges, I will cherry-pick it on top of release-4.8 in a new PR and assign it to you. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
/retest |
1 similar comment
/retest |
@openshift-cherrypick-robot: all tests passed! Full PR test history. Your PR dashboard. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
/lgtm |
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: danwinship, openshift-cherrypick-robot The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
/label cherry-pick-approved |
@openshift-cherrypick-robot: All pull requests linked via external trackers have merged: Bugzilla bug 2090624 has been moved to the MODIFIED state. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
@kyrtapz: new pull request created: #435 In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
This is an automated cherry-pick of #430
/assign kyrtapz