Open christarazi opened 1 year ago
$ cilium connectivity test --flow-validation=disabled -p ... âšī¸ Skipping IPCache check đ Enabling Hubble telescope... âšī¸ Hubble is OK, flows: 2262/8190 âšī¸ Cilium version: 1.14.0 đ Running tests... [=] Test [no-policies] ........................ [=] Test [no-policies-extra] ........ [=] Test [allow-all-except-world] ....... âšī¸ đ Applying CiliumNetworkPolicy 'allow-all-except-world' to namespace 'cilium-test'.. [-] Scenario [allow-all-except-world/pod-to-pod] [.] Action [allow-all-except-world/pod-to-pod/curl-ipv4-0: cilium-test/client-6965d549d5-hpkqt (10.244.1.228) -> cilium-test/echo-other-node-f57db5457-9q9km (10.244.0.47:8080)] đ Following flows... [.] Action [allow-all-except-world/pod-to-pod/curl-ipv4-1: cilium-test/client-6965d549d5-hpkqt (10.244.1.228) -> cilium-test/echo-same-node-799c9b99f-xrz4t (10.244.1.116:8080)] đ Following flows... [.] Action [allow-all-except-world/pod-to-pod/curl-ipv4-2: cilium-test/client2-76f4d7c5bc-dnj57 (10.244.1.23) -> cilium-test/echo-other-node-f57db5457-9q9km (10.244.0.47:8080)] đ Following flows... [.] Action [allow-all-except-world/pod-to-pod/curl-ipv4-3: cilium-test/client2-76f4d7c5bc-dnj57 (10.244.1.23) -> cilium-test/echo-same-node-799c9b99f-xrz4t (10.244.1.116:8080)] đ Following flows... [-] Scenario [allow-all-except-world/client-to-client] [.] Action [allow-all-except-world/client-to-client/ping-ipv4-0: cilium-test/client-6965d549d5-hpkqt (10.244.1.228) -> cilium-test/client2-76f4d7c5bc-dnj57 (10.244.1.23:0)] đ Following flows... [.] Action [allow-all-except-world/client-to-client/ping-ipv4-1: cilium-test/client2-76f4d7c5bc-dnj57 (10.244.1.23) -> cilium-test/client-6965d549d5-hpkqt (10.244.1.228:0)] đ Following flows... [-] Scenario [allow-all-except-world/pod-to-service] [.] Action [allow-all-except-world/pod-to-service/curl-0: cilium-test/client-6965d549d5-hpkqt (10.244.1.228) -> cilium-test/echo-other-node (echo-other-node:8080)] đ Following flows... â command "curl -w %{local_ip}:%{local_port} -> %{remote_ip}:%{remote_port} = %{response_code} --silent --fail --show-error --output /dev/null --connect-timeout 2 --max-time 10 http://echo-other-node:8080" failed: command terminated with exit code 28 âšī¸ curl output: đ Flow logs for peer cilium-test/client-6965d549d5-hpkqt: â [0] May 31 04:58:52.009: cilium-test/client-6965d549d5-hpkqt -> cilium-test/client2-76f4d7c5bc-dnj57 from-endpoint FORWARDED TRAFFIC_DIRECTION_UNKNOWN DROP_REASON_UNKNOWN (ICMPv4 EchoReply) â [1] May 31 04:58:52.009: cilium-test/client-6965d549d5-hpkqt -> cilium-test/client2-76f4d7c5bc-dnj57 to-endpoint FORWARDED EGRESS DROP_REASON_UNKNOWN (ICMPv4 EchoReply) â [2] May 31 04:58:52.077: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/kube-dns:53 from-endpoint FORWARDED TRAFFIC_DIRECTION_UNKNOWN DROP_REASON_UNKNOWN (UDP) â [3] May 31 04:58:52.077: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/coredns-5d78c9869d-hgq6f:53 policy-verdict:none EGRESS DROPPED EGRESS POLICY_DENIED (UDP) â [4] May 31 04:58:52.077: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/coredns-5d78c9869d-hgq6f:53 Policy denied DROPPED EGRESS POLICY_DENIED (UDP) â [5] May 31 04:58:52.077: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/kube-dns:53 from-endpoint FORWARDED TRAFFIC_DIRECTION_UNKNOWN DROP_REASON_UNKNOWN (UDP) â [6] May 31 04:58:52.077: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/coredns-5d78c9869d-hgq6f:53 policy-verdict:none EGRESS DROPPED EGRESS POLICY_DENIED (UDP) â [7] May 31 04:58:52.077: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/coredns-5d78c9869d-hgq6f:53 Policy denied DROPPED EGRESS POLICY_DENIED (UDP) â [8] May 31 04:58:54.578: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/kube-dns:53 from-endpoint FORWARDED TRAFFIC_DIRECTION_UNKNOWN DROP_REASON_UNKNOWN (UDP) â [9] May 31 04:58:54.578: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/coredns-5d78c9869d-hgq6f:53 policy-verdict:none EGRESS DROPPED EGRESS POLICY_DENIED (UDP) â [10] May 31 04:58:54.578: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/coredns-5d78c9869d-hgq6f:53 Policy denied DROPPED EGRESS POLICY_DENIED (UDP) â [11] May 31 04:58:54.578: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/kube-dns:53 from-endpoint FORWARDED TRAFFIC_DIRECTION_UNKNOWN DROP_REASON_UNKNOWN (UDP) â [12] May 31 04:58:54.578: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/coredns-5d78c9869d-hgq6f:53 policy-verdict:none EGRESS DROPPED EGRESS POLICY_DENIED (UDP) â [13] May 31 04:58:54.578: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/coredns-5d78c9869d-hgq6f:53 Policy denied DROPPED EGRESS POLICY_DENIED (UDP) đ Flow logs for peer cilium-test/echo-other-node: â [0] May 31 04:58:52.009: cilium-test/client-6965d549d5-hpkqt -> cilium-test/client2-76f4d7c5bc-dnj57 from-endpoint FORWARDED TRAFFIC_DIRECTION_UNKNOWN DROP_REASON_UNKNOWN (ICMPv4 EchoReply) â [1] May 31 04:58:52.009: cilium-test/client-6965d549d5-hpkqt -> cilium-test/client2-76f4d7c5bc-dnj57 to-endpoint FORWARDED EGRESS DROP_REASON_UNKNOWN (ICMPv4 EchoReply) â [2] May 31 04:58:52.077: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/kube-dns:53 from-endpoint FORWARDED TRAFFIC_DIRECTION_UNKNOWN DROP_REASON_UNKNOWN (UDP) â [3] May 31 04:58:52.077: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/coredns-5d78c9869d-hgq6f:53 policy-verdict:none EGRESS DROPPED EGRESS POLICY_DENIED (UDP) â [4] May 31 04:58:52.077: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/coredns-5d78c9869d-hgq6f:53 Policy denied DROPPED EGRESS POLICY_DENIED (UDP) â [5] May 31 04:58:52.077: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/kube-dns:53 from-endpoint FORWARDED TRAFFIC_DIRECTION_UNKNOWN DROP_REASON_UNKNOWN (UDP) â [6] May 31 04:58:52.077: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/coredns-5d78c9869d-hgq6f:53 policy-verdict:none EGRESS DROPPED EGRESS POLICY_DENIED (UDP) â [7] May 31 04:58:52.077: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/coredns-5d78c9869d-hgq6f:53 Policy denied DROPPED EGRESS POLICY_DENIED (UDP) â [8] May 31 04:58:54.578: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/kube-dns:53 from-endpoint FORWARDED TRAFFIC_DIRECTION_UNKNOWN DROP_REASON_UNKNOWN (UDP) â [9] May 31 04:58:54.578: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/coredns-5d78c9869d-hgq6f:53 policy-verdict:none EGRESS DROPPED EGRESS POLICY_DENIED (UDP) â [10] May 31 04:58:54.578: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/coredns-5d78c9869d-hgq6f:53 Policy denied DROPPED EGRESS POLICY_DENIED (UDP) â [11] May 31 04:58:54.578: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/kube-dns:53 from-endpoint FORWARDED TRAFFIC_DIRECTION_UNKNOWN DROP_REASON_UNKNOWN (UDP) â [12] May 31 04:58:54.578: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/coredns-5d78c9869d-hgq6f:53 policy-verdict:none EGRESS DROPPED EGRESS POLICY_DENIED (UDP) â [13] May 31 04:58:54.578: cilium-test/client-6965d549d5-hpkqt:46559 -> kube-system/coredns-5d78c9869d-hgq6f:53 Policy denied DROPPED EGRESS POLICY_DENIED (UDP) Pausing after action failure, press the Enter key to continue: [.] Action [allow-all-except-world/pod-to-service/curl-1: cilium-test/client-6965d549d5-hpkqt (10.244.1.228) -> cilium-test/echo-same-node (echo-same-node:8080)] đ Following flows... ^CInterrupt received, cancelling tests... â command "curl -w %{local_ip}:%{local_port} -> %{remote_ip}:%{remote_port} = %{response_code} --silent --fail --show-error --output /dev/null --connect-timeout 2 --max-time 10 http://echo-same-node:8080" failed: context canceled âšī¸ curl output: đ No flows recorded for peer cilium-test/client-6965d549d5-hpkqt during action curl-1 đ No flows recorded for peer cilium-test/echo-same-node during action curl-1 Pausing after action failure, press the Enter key to continue: [.] Action [allow-all-except-world/pod-to-service/curl-2: cilium-test/client2-76f4d7c5bc-dnj57 (10.244.1.23) -> cilium-test/echo-other-node (echo-other-node:8080)] đ Following flows... đĨ Skipping command execution: context canceled âšī¸ đ Deleting CiliumNetworkPolicy 'allow-all-except-world' from namespace 'cilium-test'.. ^Cconnectivity test failed: context canceled
General Information
main
How to reproduce the issue
enable-well-known-identities: true
cilium connectivity test
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs.
Bug report
General Information
main
How to reproduce the issue
enable-well-known-identities: true
cilium connectivity test