Uploaded image for project: 'OpenShift Service Mesh'
  1. OpenShift Service Mesh
  2. OSSM-11449

Support safe upgrades from iptables backend to nftables backend in ambient

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • None
    • Istio
    • None

      When an existing Istio Ambient deployment using the iptables backend is upgraded to the nftables backend, IstioCNI shouldn’t switch to nftables silently. Doing so leaves stale iptables rules/IPsets on the host. If this happens along with reconcileIptablesOnStartup setting, the pod network namespaces end up with both nftables rules and the old iptables rules. In both cases, the stale iptables rules can cause issues until the node is rebooted. 

       

      Acceptance Criteria:

      Support safe upgrade from iptables to nftables for pods in ambient mode.

              sgaddam@redhat.com Gaddam Sridhar
              sgaddam@redhat.com Gaddam Sridhar
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: