We did a bunch of patches upstream to make kube-proxy not do constant unnecessary iptables resyncs but then didn't notice that our hybrid proxier code was forcing unnecessary resyncs anyway.
- Cluster still works
- Services still work, still reflect new/changed/deleted endpoints promptly
- Service idling/unidling still works, still changes state promptly
- Monitoring the kubeproxy_sync_proxy_rules_last_timestamp_seconds metric on the sdn pod shows that it only changes when there are actual changes to services/endpoints, rather than automatically being updated every 30 seconds.
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.