-
Notifications
You must be signed in to change notification settings - Fork 41.6k
[1.18] kubelet: block non-forwarded packets from crossing the localhost boundary #92038
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[1.18] kubelet: block non-forwarded packets from crossing the localhost boundary #92038
Conversation
|
/priority important-soon |
ccfde10 to
0fe4d09
Compare
…dary We set route_localnet so that host-network processes can connect to <127.0.0.1:NodePort> and it still works. This, however, is too permissive. So, block martians that are not already in conntrack. See: kubernetes#90259 Signed-off-by: Casey Callendrello <cdc@redhat.com>
0fe4d09 to
a8a673a
Compare
|
/test pull-kubernetes-integration |
|
/lgtm |
|
kubelet change is lgtm. /approve |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: derekwaynecarr, joelsmith The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
Cherry pick of #91569 on release-1.18.
#91569: kubelet: block non-forwarded packets from crossing the
For details on the cherry pick process, see the cherry pick requests page.