This repository has been archived by the owner on Oct 24, 2023. It is now read-only.
chore: upgrade ip-masq-agent addon to v2.8.0 #5023
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Reason for Change:
The base image of the current
ip-masq-agent
addon uses aniptables
version (v1.6) that does not support--random-fully
rules. These rules prevent a known kernel race condition that drops packages when doing SNAT (details).It was recently determined that an on-prem workload was impacted by this race condition.
Upgrading to the latest release of the addon also upgrades the base image to the same base image used to build
kube-proxy
(iptables v1.8) which includes support forrandom-fully
.Issue Fixed:
Credit Where Due:
Does this change contain code from or inspired by another project?
If "Yes," did you notify that project's maintainers and provide attribution?
Requirements:
Notes: