You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Kubespray defaults FELIX_DEFAULTENDPOINTTOHOSTACTION to RETURN while calico's manifests or operator default it to ACCEPT It would be good to change it to ACCEPT as well.
Why is this needed:
The coarse-grained control provided by the FELIX_DEFAULTENDPOINTTOHOSTACTION option is superseded by wildcard host endpoints that can provide fine-grained policy-based control. When the FELIX_DEFAULTENDPOINTTOHOSTACTION is set to RETURN the wildcard HEPs trump this option in newer versions anyway. Unless kubespray uses this option to fall back to its or 3rd party's iptable rules, there is no reason to set it to RETURN.
In addition, it may be good not to default it in the calico-node daemonset but in felixconfiguration resource as the it cannot be set from the resource, which is the preferred way, see this calico issue In general, it might be better to set it in the default felixconfiguration, but that is a secondary issue to the main one here.
The text was updated successfully, but these errors were encountered:
What would you like to be added:
Kubespray defaults
FELIX_DEFAULTENDPOINTTOHOSTACTION
toRETURN
while calico's manifests or operator default it toACCEPT
It would be good to change it toACCEPT
as well.Why is this needed:
The coarse-grained control provided by the
FELIX_DEFAULTENDPOINTTOHOSTACTION
option is superseded by wildcard host endpoints that can provide fine-grained policy-based control. When theFELIX_DEFAULTENDPOINTTOHOSTACTION
is set toRETURN
the wildcard HEPs trump this option in newer versions anyway. Unless kubespray uses this option to fall back to its or 3rd party's iptable rules, there is no reason to set it toRETURN
.In addition, it may be good not to default it in the calico-node daemonset but in felixconfiguration resource as the it cannot be set from the resource, which is the preferred way, see this calico issue In general, it might be better to set it in the default felixconfiguration, but that is a secondary issue to the main one here.
The text was updated successfully, but these errors were encountered: