Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1937008

Summary: Configuring ingress netpol prevent ingress traffic on route to reach pod
Product: OpenShift Container Platform Reporter: Simon Belmas-Gauderic <sbelmasg>
Component: NetworkingAssignee: Andrew Stoycos <astoycos>
Networking sub component: ovn-kubernetes QA Contact: Anurag saxena <anusaxen>
Status: CLOSED DUPLICATE Docs Contact:
Severity: high    
Priority: unspecified CC: aconstan, fpan, joboyer, openshift-bugs-escalate
Version: 4.6.z   
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-03-19 14:47:59 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Comment 1 Simon Belmas-Gauderic 2021-03-09 16:39:42 UTC
This Bug is created on engineering demand on escalation EN-38753.

Comment 3 Andrew Stoycos 2021-03-09 17:05:53 UTC
Hi, 

Based on the first few lines of the customer case I see `endpointPublishingStrategy is set to HostNetwork` therefore this is most likely a dupe of https://bugzilla.redhat.com/show_bug.cgi?id=1927841. 

To summarize... 

If an ingresscontroller specifies "spec.endpointPublishingStrategy.type: HostNetwork" then the ingress router pods are host networked due to the fact that bare metal does not support cloud load balancers, and using the host network means that an external load-balancer can be easily configured to use ports 80/443/1936 on the nodes hosting router pods. 

There is no supported way to apply network policy to host-networked pods in OVN-kubernetes, in both versions 4.7 and 4.6. The workaround regarding the addition of a label in the default namespace (https://docs.openshift.com/container-platform/4.6/post_installation_configuration/network-configuration.html) is an Openshift-SDN specific oddity and needs to be documented as such. 

Note: There is an upstream enhancement targeting 4.8 that provide the requested behavior -> https://github.com/openshift/enhancements/blob/master/enhancements/network/allow-from-router-networkpolicy.md  


Thanks, 
Andrew

Comment 4 Andrew Stoycos 2021-03-19 14:47:59 UTC

*** This bug has been marked as a duplicate of bug 1927841 ***