Closed V0idk closed 3 months ago
Hi @V0idk the periodic resync of the iptables rules is there to ensure that the rules created by flannel are not removed by another program. Normally, if the rules are not modified, iptables should not run again.
In any case, if the resync period is too short on your system, you can configure it through the --iptables-resync
flag.
See the doc here.
I see
getRules()
is alway not changed ifHasNerwork()
is false(not specfic optionuse-multi-cluster-cidr
), so can we reduce resync period or not resync when we are not usinguse-multi-cluster-cidr
?Motivation: iptable query occupy iptable lock too long when has many pod and service.