k8s:UNable to reach public /outisde netowrk unless custome tags are associated with __public__ netwrok
Affects | Status | Importance | Assigned to | Milestone | ||
---|---|---|---|---|---|---|
Juniper Openstack | Status tracked in Trunk | |||||
R5.0 |
Fix Released
|
High
|
Dinesh Bakiaraj | |||
Trunk |
Fix Committed
|
High
|
Dinesh Bakiaraj |
Bug Description
In case of the logical router enabled with SNAT ,pod reachability to the external networks(outside the cluster) is dropped unless we associate the custom tag to the __public__ vn
due to this, testcase :TestPod.
since association of the custom tag solving the issue ..hence not marking it as sanity blocker .
Build :5.0.263
Deployment :Ansible_deployer
HOST OS: CENTOS7.5
=======
Topology
==================
vrouter +k8s_node:
ip: nodec60
ip: nodec61
config +control+
ip: nodeg12(k8s_master)
ip: nodeg31
ip: nodec58
if __public__ is associated with custome tag namespace=default ...then it works fine .
letftnet(
pod -------
10.47.255.251
[root@nodeg12 ~]# kubectl get pods --all-namespaces -o wide
NAMESPACE NAME READY STATUS RESTARTS AGE IP NODE
ctest-namespace
434368<=>9744 10.47.255.251:204 1 (2)
(Gen: 1, K(nh):21, Action:F, Flags:, QOS:-1, S(nh):21, Stats:1/98, SPort 65505,
TTL 0, Sinfo 3.0.0.0)
359936<=>405536 10.84.5.120:186 1 (4)
(Gen: 1, K(nh):37, Action:F, Flags:, QOS:-1, S(nh):37, Stats:0/0, SPort 54224,
TTL 0, Sinfo 0.0.0.0)
86460<=>95204 10.204.221.164:132 1 (3)
(Gen: 1, K(nh):36, Action:D(FwPolicy), Flags:, QOS:-1, S(nh):36, Stats:3/294,
SPort 61117, TTL 0, Sinfo 5.0.0.0)
95204<=>86460 10.84.5.120:132 1 (3)
(Gen: 1, K(nh):36, Action:D(Unknown), Flags:, QOS:-1, S(nh):34, Stats:0/0,
SPort 63555, TTL 0, Sinfo 0.0.0.0)
tags: | added: contrail-security k8s |
summary: |
- k8s:UNable to reach public /outisde netowrk unless custome tag are + k8s:UNable to reach public /outisde netowrk unless custome tags are associated with __public__ netwrok |
description: | updated |
Review in progress for https:/ /review. opencontrail. org/46967
Submitter: Dinesh Bakiaraj (<email address hidden>)