Uploaded image for project: 'Maistra'
  1. Maistra
  2. MAISTRA-608

CNI doesn't configure iptables if multiple control planes are deployed

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • maistra-0.12.0
    • maistra-0.12.0
    • CNI, operator
    • None
    • Maistra TP sprint 12

      If you deploy a control plane with CNI enabled and then a control plane with CNI disabled, the operator deletes the ClusterRole and ClusterRoleBinding used by the CNI plugin. The plugin then can't retrieve the Pod data from the API server and doesn't configure iptables for the pod.

      Similarly, if you deploy multiple control planes with CNI, only one of them will work properly, as only one of the istio CNI plugins will have the proper permission to retrieve the pod object from the API server.

              mluksa@redhat.com Marko Luksa
              mluksa@redhat.com Marko Luksa
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: