Skip to content

Commit

Permalink
corrected reference link to valid one (#9940)
Browse files Browse the repository at this point in the history
* corrected reference link to valid one

* Update calico.md

incorporated review comments
  • Loading branch information
kundan2707 authored Mar 29, 2023
1 parent e8f0fb8 commit e6eda9d
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion docs/calico.md
Original file line number Diff line number Diff line change
Expand Up @@ -187,7 +187,7 @@ The inventory above will deploy the following topology assuming that calico's

### Optional : Define default endpoint to host action

By default Calico blocks traffic from endpoints to the host itself by using an iptables DROP action. When using it in kubernetes the action has to be changed to RETURN (default in kubespray) or ACCEPT (see <https://github.com/projectcalico/felix/issues/660> and <https://github.com/projectcalico/calicoctl/issues/1389).> Otherwise all network packets from pods (with hostNetwork=False) to services endpoints (with hostNetwork=True) within the same node are dropped.
By default Calico blocks traffic from endpoints to the host itself by using an iptables DROP action. When using it in kubernetes the action has to be changed to RETURN (default in kubespray) or ACCEPT (see <https://docs.tigera.io/calico/latest/network-policy/hosts/protect-hosts#control-default-behavior-of-workload-endpoint-to-host-traffic> ) Otherwise all network packets from pods (with hostNetwork=False) to services endpoints (with hostNetwork=True) within the same node are dropped.

To re-define default action please set the following variable in your inventory:

Expand Down

0 comments on commit e6eda9d

Please sign in to comment.