Closed sigurdblueface closed 1 year ago
Does this affect only pods on different nodes, or even pods on the same nodes? Have you tried switching to iptables-legacy instead of iptables-nft? Have you confirmed that the vxlan module is available and loaded? Are you able to find any errors in the k3s or containerd logs?
It affects pods on different nodes. Pods on the same node can connect.
Yes, I use iptables-legacy.
Regarding vxlan:
lsmod | grep vxlan
vxlan 86016 0
ip6_udp_tunnel 16384 1 vxlan
udp_tunnel 20480 1 vxlan
I see only errors regarding unability to connect to metrics-server even with --v 5 verbosity.
Did firewalld or ufw get accidentally re-enabled as part of the upgrade? Do you have anything else on the nodes that might be blocking vxlan traffic?
What sort of hardware is this on? There have been issues with hardware checksum offload corrupting vxlan packets on vmware when used with specific kernel versions.
@brandond, thank you very much, and I am sorry for wasting your time. I've managed to solve the issue. Found out that someone for some unclear reason enabled hypervisor-level firewall in Proxmox UI for nw devices... Unchecked that, performed reboot - everything works perfectly now.
Environmental Info: K3s Version:
Node(s) CPU architecture, OS, and Version:
Linux oa-node-0 5.15.0-52-generic #58-Ubuntu SMP Thu Oct 13 08:03:55 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux
Cluster Configuration:3 servers, 3 agents Describe the bug:
After update of host OS Ubuntu 20.04 -> 22.04 pods cannot connect to each other between nodes. Even within the same namespace. So NodePorts & Ingress do not properly work also. Steps To Reproduce:
Installed K3s: with custom ansible role. k3s config.yaml:
systemd unit:
.env file:
sysctl:
Expected behavior:
A perfectly working cluster Actual behavior:
Pods/services cannot interoperate while located on different nodes. One pod cannot ping other pod even within the same namespace. At the same time the service network is accessible. Attempts to access resources via ingresses lead to 5хх errors.
Tried to flush iptables/switch to ipvs - no changes. NodePorts works only if desired pod is located on that particular node i.e my-pod works on node-2, has nodeport 30087 so node-2:30087 - works, and node-1:30087 - not
Additional context / logs:
nothing really meaningful/pointing into any issue in k3s logs
Please advise me what could I also check and try? Thanks in advance.