• Icon: Sub-task Sub-task
    • Resolution: Done
    • Icon: Major Major
    • maistra-2.1.0
    • None
    • None
    • None
    • Sprint 9, Sprint 10, Sprint 11

      DNS capture is not correct when using CNI. It's capturing packets which the destination is the server found in /etc/resolv.conf. Since with CNI the iptables binary runs on the node, it's getting the contents of resolv.conf from the node, not from the container. Upstream fixed this in https://github.com/istio/istio/issues/29511 which we need to backport in some way.

              jsantana@redhat.com Jonh Wendell
              jsantana@redhat.com Jonh Wendell
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: