Closed negz closed 6 years ago
We deployed a build of ip-masq-agent #22 to a production cluster earlier today and configured both ip-masq-agent and kube-proxy to mount /run/xtables.lock
. I've observed zero ip-masq-agent restarts since; typically we'd see a dozen or so on busy nodes in that time frame.
I've recently observed my ip-masq-agent containers restarting fairly frequently due to errors syncing masquerade rules. It's hard to determine exactly what is wrong with the rules given the limited log output. I've observed this in both v2.0.1 and v2.1.1 of ip-masq-agent.
I wonder if perhaps I'm being hit by iptables locking issues as described in https://github.com/kubernetes/kubernetes/pull/44895? I notice ip-masq-agent is pinned to a version of
util/iptables
from before that PR was merged, and thus (I believe) won't use any iptables locking.