-
Bug
-
Resolution: Done-Errata
-
Critical
-
OSSM 2.4.9, OSSM 2.5.3, OSSM 2.6.0
-
None
Current implementation of the injection webhook does not ensure that proxy GID is unique within a pod, so in some cases, e.g. in privileged pods with UID,GID=0 we set overlapping GID for proxy and it results in broken iptables rule "no-redirect" that utilizes `--gid-owner` option and that breaks traffic interception.
More details can be found in the description of this PR: https://github.com/maistra/istio/pull/1057.
- impacts account
-
OSSM-6935 Service communication with mTLS doesn't work with SMCP 2.4, after upgrading the operator to 2.6 version
- Closed
- links to
-
RHBA-2024:139314 Red Hat OpenShift Service Mesh Containers for 2.6.2