aibangjuxin / groovy

study groovy
1 stars 0 forks source link


iptables -t nat -A POSTROUTING -j LOG --log-prefix "NAT packet: " --log-level 4

- To monitor the network policy hit log for pods in Google Kubernetes Engine (GKE), you can follow these steps:

- Enable network policy logging by creating a new ConfigMap with the following settings:
apiVersion: v1
kind: ConfigMap
  name: kube-system/network-policy-logging
  namespace: kube-system
  loglevel: "5"

View the network policy hit logs by querying the Stackdriver Logging API using the command: gcloud logging read "resource.type=k8s_container AND resource.labels.cluster_name= AND resource.labels.namespace_name= AND resource.labels.pod_name= AND jsonPayload.event.reason=NetworkPolicyMatch" --limit= This will return a list of logs indicating which network policies matched and affected the pod. You can