Bug 1330201
| Summary: | atomic-openshift-node does not reconcile iptables rules when the iptables service is restarted | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | Matt Woodson <mwoodson> |
| Component: | Networking | Assignee: | Ravi Sankar <rpenta> |
| Status: | CLOSED ERRATA | QA Contact: | Meng Bo <bmeng> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 3.1.0 | CC: | aos-bugs, charles_sheridan, eparis, tdawson, twiest, xtian |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2016-09-27 09:31:24 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 1303130 | ||
|
Description
Matt Woodson
2016-04-25 15:23:45 UTC
This should be tested on latest OSE build. Please move it back once the changes are merged into OSE. This has been merged and is in OSE v3.3.0.8 or newer. Checked on aos build v3.3.0.17 The kubernetes iptables rules will not be recovered after deleted. Assign the bug back. Steps: 1. Delete the openshift iptables on node # iptables -D INPUT -i tun0 -m comment --comment "traffic from docker for internet" -j ACCEPT 2. Delete the kubernetes iptables on node # iptables -D OUTPUT -m comment --comment "kubernetes service portals" -j KUBE-SERVICES # iptables -t nat -D KUBE-SERVICES -d 172.31.0.1/32 -p tcp -m comment --comment "default/kubernetes:dns-tcp cluster IP" -m tcp --dport 53 -j KUBE-SVC-BA6I5HTZKAAAJT56 3. Watch the iptables rules Result: Only the openshift iptables rules are recovered. Commit pushed to master at https://github.com/openshift/origin https://github.com/openshift/origin/commit/5f8c0a2d71d5387fb6a37815d37e5044891e6f60 Bug 1330201 - Periodically sync k8s iptables rules This has been merged into ose and is in OSE v3.3.0.23 or newer. Checked on ose build v3.3.0.23. Issue has been fixed. Both OpenShift SDN iptables rules and k8s iptables rules can be restored automatically after deleted. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2016:1933 |