Bug 1933711

Summary: EgressDNS: Keep short lived records at most 30s
Product: OpenShift Container Platform Reporter: huirwang
Component: NetworkingAssignee: Juan Luis de Sousa-Valadas <jdesousa>
Networking sub component: openshift-sdn QA Contact: huirwang
Status: CLOSED ERRATA Docs Contact:
Severity: medium    
Priority: medium CC: aconstan, danw
Version: 4.8   
Target Milestone: ---   
Target Release: 4.8.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Cause: Egress networkpolicies with dnsName rules would refresh the IP list corresponding to that name once the TTL of the record expired. Consequence: The cache may expire before the record and the next query may return a different ip address list causing the new connection packets' to be dropped Fix: For records that last less than one hour, query them every 30 seconds. For records that last over an hour, query them ever 30 minutes. Result: The cache is less likely to expire making drops less likely as well. Besides because it happens every 30 seconds new connections that fail will probably wait less to be reopened.
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-07-27 22:48:44 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description huirwang 2021-03-01 14:18:40 UTC
Description of problem:

Use this bug to track PR:https://github.com/openshift/sdn/pull/263 , and seperate from DOC bug https://bugzilla.redhat.com/show_bug.cgi?id=1876376

Comment 5 errata-xmlrpc 2021-07-27 22:48:44 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: OpenShift Container Platform 4.8.2 bug fix and security update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2021:2438