aibangjuxin / groovy

study groovy
1 stars 0 forks source link

iptables

iptables -t nat -A POSTROUTING -j LOG --log-prefix "NAT packet: " --log-level 4


- To monitor the network policy hit log for pods in Google Kubernetes Engine (GKE), you can follow these steps:

- Enable network policy logging by creating a new ConfigMap with the following settings:
```yaml
apiVersion: v1
kind: ConfigMap
metadata:
  name: kube-system/network-policy-logging
  namespace: kube-system
data:
  loglevel: "5"

View the network policy hit logs by querying the Stackdriver Logging API using the command: gcloud logging read "resource.type=k8s_container AND resource.labels.cluster_name= AND resource.labels.namespace_name= AND resource.labels.pod_name= AND jsonPayload.event.reason=NetworkPolicyMatch" --limit= This will return a list of logs indicating which network policies matched and affected the pod. You can