Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-55112

[pre-merge][BGP][UDN L3/L2]Nodeport with ipv6 address is not working after advertised for different network and different node

XMLWordPrintable

    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • Critical
    • No
    • None
    • None
    • Rejected
    • CORENET Sprint 276
    • 1
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      nodePort with different network and different node after advertisement,  ipv4:nodePort can work  but ipv6:nodePort not

      1 we have two CUDN and two namespace 

       

      # oc get net-attach-def -n z7
      NAME   AGE
      blue   33h
      # oc get net-attach-def -n z8
      NAME   AGE
      red    30h
      
      

      2.  there is nodePort svc with ETP=Cluster in namespace z7

       

      # oc get pod -n z7
      NAME            READY   STATUS    RESTARTS   AGE
      test-rc-8cn7f   1/1     Running   0          33h
      test-rc-fjvb9   1/1     Running   0          33h
      
      
      # oc get svc hello-pod -n z7 -o yaml
      apiVersion: v1
      kind: Service
      metadata:
        creationTimestamp: "2025-04-16T04:15:42Z"
        labels:
          name: hello-pod
        name: hello-pod
        namespace: z7
        resourceVersion: "1245272"
        uid: 83256f76-2b6f-41e7-bc4b-0a6707a8828a
      spec:
        clusterIP: 172.30.86.22
        clusterIPs:
        - 172.30.86.22
        - fd02::da8a
        externalTrafficPolicy: Cluster
        internalTrafficPolicy: Cluster
        ipFamilies:
        - IPv4
        - IPv6
        ipFamilyPolicy: PreferDualStack
        ports:
        - name: http
          nodePort: 32704
          port: 27017
          protocol: TCP
          targetPort: 8080
        selector:
          name: test-pods
        sessionAffinity: None
        type: NodePort
      status:
        loadBalancer: {}
       

        3 . Before advertise CUDN,  ipv4 and ipv6 are working except same node which is expected

       

      # oc rsh -n z8 test-rc-w4c2q
      ~ $ curl 192.168.111.23:32704
      Hello OpenShift!
      ~ $ curl 192.168.111.24:32704
      Hello OpenShift!
      ~ $ curl 192.168.111.25:32704     ###same node is not working, expected
      ^C
      ~ $ curl 192.168.111.25:32704^C
      ~ $ curl [fd2e:6f44:5dd8:c956::17]:32704
      Hello OpenShift!
      ~ $ curl [fd2e:6f44:5dd8:c956::18]:32704
      Hello OpenShift!
      ~ $ curl [fd2e:6f44:5dd8:c956::19]:32704
      ^C
       

      4.  After advertise cudn

      # oc get ra
      NAME      STATUS
      cudn      Accepted
       

      5.   one issue is ipv4 still working with different node and different network, but ipv6 cannot

            another issue is same node ipv4 and ipv6 became working. 

      # oc rsh -n z8 test-rc-w4c2q
      ~ $ 
      ~ $ curl 192.168.111.23:32704
      Hello OpenShift!
      ~ $  curl 192.168.111.24:32704
      Hello OpenShift!
      ~ $  curl 192.168.111.25:32704
      Hello OpenShift!
      ~ $ curl [fd2e:6f44:5dd8:c956::17]:32704
      ^C
      ~ $ curl [fd2e:6f44:5dd8:c956::18]:32704
      ^C
      ~ $ 
      ~ $ curl [fd2e:6f44:5dd8:c956::19]:32704
      Hello OpenShift!
       

       

       

       

      Version-Release number of selected component (if applicable):

      How reproducible:

      Steps to Reproduce:

      1.

      2.

      3.

      Actual results:

      Expected results:

      Additional info:

      Please fill in the following template while reporting a bug and provide as much relevant information as possible. Doing so will give us the best chance to find a prompt resolution.

      Affected Platforms:

      Is it an

      1. internal CI failure
      2. customer issue / SD
      3. internal RedHat testing failure

      If it is an internal RedHat testing failure:

      • Please share a kubeconfig or creds to a live cluster for the assignee to debug/troubleshoot along with reproducer steps (specially if it's a telco use case like ICNI, secondary bridges or BM+kubevirt).

      If it is a CI failure:

      • Did it happen in different CI lanes? If so please provide links to multiple failures with the same error instance
      • Did it happen in both sdn and ovn jobs? If so please provide links to multiple failures with the same error instance
      • Did it happen in other platforms (e.g. aws, azure, gcp, baremetal etc) ? If so please provide links to multiple failures with the same error instance
      • When did the failure start happening? Please provide the UTC timestamp of the networking outage window from a sample failure run
      • If it's a connectivity issue,
      • What is the srcNode, srcIP and srcNamespace and srcPodName?
      • What is the dstNode, dstIP and dstNamespace and dstPodName?
      • What is the traffic path? (examples: pod2pod? pod2external?, pod2svc? pod2Node? etc)

      If it is a customer / SD issue:

      • Provide enough information in the bug description that Engineering doesn’t need to read the entire case history.
      • Don’t presume that Engineering has access to Salesforce.
      • Do presume that Engineering will access attachments through supportshell.
      • Describe what each relevant attachment is intended to demonstrate (failed pods, log errors, OVS issues, etc).
      • Referring to the attached must-gather, sosreport or other attachment, please provide the following details:
        • If the issue is in a customer namespace then provide a namespace inspect.
        • If it is a connectivity issue:
          • What is the srcNode, srcNamespace, srcPodName and srcPodIP?
          • What is the dstNode, dstNamespace, dstPodName and dstPodIP?
          • What is the traffic path? (examples: pod2pod? pod2external?, pod2svc? pod2Node? etc)
          • Please provide the UTC timestamp networking outage window from must-gather
          • Please provide tcpdump pcaps taken during the outage filtered based on the above provided src/dst IPs
        • If it is not a connectivity issue:
          • Describe the steps taken so far to analyze the logs from networking components (cluster-network-operator, OVNK, SDN, openvswitch, ovs-configure etc) and the actual component where the issue was seen based on the attached must-gather. Please attach snippets of relevant logs around the window when problem has happened if any.
      • When showing the results from commands, include the entire command in the output.  
      • For OCPBUGS in which the issue has been identified, label with “sbr-triaged”
      • For OCPBUGS in which the issue has not been identified and needs Engineering help for root cause, label with “sbr-untriaged”
      • Do not set the priority, that is owned by Engineering and will be set when the bug is evaluated
      • Note: bugs that do not meet these minimum standards will be closed with label “SDN-Jira-template”
      • For guidance on using this template please see
        OCPBUGS Template Training for Networking  components

       
       
       

              sdn-team-bot sdn-team bot
              zzhao1@redhat.com Zhanqi Zhao
              None
              None
              Zhanqi Zhao Zhanqi Zhao
              None
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: