Description of problem: After few days, the tcp-connections between newly created namespaces and already existing namespaces are failing, although the corresponding namespace-label and network-policy is correctly applied. A recreation of the destination pod seems to solve the issue though. This looks like a bug where the ovs-flow-table doesn't get updated reliably when a new namespace with a matching label gets deployed. Version-Release number of selected component (if applicable): OCP 3.7.42-1 How reproducible: It is random and after few days. Steps to Reproduce: 1. 2. 3. Actual results: Expected results: Additional info:
Any news about it?
Sorry there hasn't been any update here. The sosreport doesn't reveal much more than what the reporter already figured out; for some reason, nodes are sometimes missing OVS flows that they ought to have. At default debug levels there isn't enough information logged to figure out why. We'll have to try to reproduce this locally.
Weibin, can you please try to reproduce this?
Dan, Follow up your above steps, the final check failed in 3.7.70 but passed in 4.0. Thanks for your detailed information.
fixed in master, and the customer case is closed