Bug 1937008
| Summary: | Configuring ingress netpol prevent ingress traffic on route to reach pod | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | Simon Belmas-Gauderic <sbelmasg> |
| Component: | Networking | Assignee: | Andrew Stoycos <astoycos> |
| Networking sub component: | ovn-kubernetes | QA Contact: | Anurag saxena <anusaxen> |
| Status: | CLOSED DUPLICATE | Docs Contact: | |
| Severity: | high | ||
| Priority: | unspecified | CC: | aconstan, fpan, joboyer, openshift-bugs-escalate |
| Version: | 4.6.z | ||
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2021-03-19 14:47:59 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Comment 1
Simon Belmas-Gauderic
2021-03-09 16:39:42 UTC
Hi, Based on the first few lines of the customer case I see `endpointPublishingStrategy is set to HostNetwork` therefore this is most likely a dupe of https://bugzilla.redhat.com/show_bug.cgi?id=1927841. To summarize... If an ingresscontroller specifies "spec.endpointPublishingStrategy.type: HostNetwork" then the ingress router pods are host networked due to the fact that bare metal does not support cloud load balancers, and using the host network means that an external load-balancer can be easily configured to use ports 80/443/1936 on the nodes hosting router pods. There is no supported way to apply network policy to host-networked pods in OVN-kubernetes, in both versions 4.7 and 4.6. The workaround regarding the addition of a label in the default namespace (https://docs.openshift.com/container-platform/4.6/post_installation_configuration/network-configuration.html) is an Openshift-SDN specific oddity and needs to be documented as such. Note: There is an upstream enhancement targeting 4.8 that provide the requested behavior -> https://github.com/openshift/enhancements/blob/master/enhancements/network/allow-from-router-networkpolicy.md Thanks, Andrew *** This bug has been marked as a duplicate of bug 1927841 *** |