Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-8279

RFE - Modify EgressFirewall TCP Deny Behavior to Return Immediate Connection Refused Instead of Timeout

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • openshift-4.16, openshift-4.17, openshift-4.18, openshift-4.19
    • Network - Core
    • None
    • Product / Portfolio Work
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Currently, an EgressFirewall with a Deny rule behaves like a black hole, silently dropping packets and causing connections to time out after the TCP timeout period.

      Instead, it should immediately respond with a TCP RST (reset) for denied connections. This would prevent applications from blocking on long timeouts, thereby reducing the number of hanging or blocked threads. When too many threads are tied up waiting, health checks (probes) may fail, potentially leading to unnecessary pod restarts.

              mcurry@redhat.com Marc Curry
              rhn-support-rsahoo Ramesh Sahoo
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                None
                None