-
Notifications
You must be signed in to change notification settings - Fork 2.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CIS scan 1.4 does not work on a multi node cluster #27652
Comments
Analysis of the problem so far with @leodotcloud :
|
This should be resolved by PR here: kubernetes/kubernetes#92354. Waiting for the next k8s patch release. |
This issue is still reproducible with k8s - 1.18.5, 1.17.8, 1.16.12. Note: |
This issue is not being caused by kubernetes/kubernetes#92354 UDP service resolution from the host network to a non-local node (in the case where kube-dns is run on 2/3 nodes and you try to resolve using the service portal from the third) does not work:
What does work is TCP resolution, i.e.
|
This upstream issues seems very relevant: kubernetes/kubernetes#87852 |
Reverting the same cluster to |
Running
|
This is the exact workaround mentioned here kubernetes/kubernetes#87852 (comment) |
Verified with 2.4.5 and KDM pointing to dev-v2.4
|
What kind of request is this (question/bug/enhancement/feature request): bug
Steps to reproduce (least amount of steps as possible):
Expected Result:
The scan should finish and the report should be generated successfully.
Other details that may be helpful:
Note:
Environment information
rancher/rancher
/rancher/server
image tag or shown bottom left in the UI): 2.4.5-rc8Cluster information
kubectl version
):gz#13130
gz#13356
The text was updated successfully, but these errors were encountered: