Closed ragunathan23 closed 3 years ago
the configuration provided in the master repo is obsolete and does not work for ipv6 usecase - pls use the latest container from gcr and try and let me know below example -
image: gcr.io/google-containers/ip-masq-agent-amd64:v2.5.0
args:
- --masq-chain=IP-MASQ
- --enable-ipv6=true
Issues go stale after 90d of inactivity.
Mark the issue as fresh with /remove-lifecycle stale
.
Stale issues rot after an additional 30d of inactivity and eventually close.
If this issue is safe to close now please do so with /close
.
Send feedback to sig-testing, kubernetes/test-infra and/or fejta. /lifecycle stale
/remove-lifecycle stale
/kind bug
cc @anfernee @sdmodi
ip-masq-agent runs on hostNetwork: true
which means it runs in the host network namespace. That's why you can ping ipv6 device from there.
It could be a calico issue. but to be able to correctly triage it, can you run ip6tables-save
on your machine and share the result to see if any iptables rules are missing?
Issues go stale after 90d of inactivity.
Mark the issue as fresh with /remove-lifecycle stale
.
Stale issues rot after an additional 30d of inactivity and eventually close.
If this issue is safe to close now please do so with /close
.
Send feedback to sig-contributor-experience at kubernetes/community. /lifecycle stale
Stale issues rot after 30d of inactivity.
Mark the issue as fresh with /remove-lifecycle rotten
.
Rotten issues close after an additional 30d of inactivity.
If this issue is safe to close now please do so with /close
.
Send feedback to sig-contributor-experience at kubernetes/community. /lifecycle rotten
Rotten issues close after 30d of inactivity.
Reopen the issue with /reopen
.
Mark the issue as fresh with /remove-lifecycle rotten
.
Send feedback to sig-contributor-experience at kubernetes/community. /close
@fejta-bot: Closing this issue.
Hi, Running k8s cluster with calico as CNI. We have a usecase to connect to ipv6 device from the pod which is configured with ipv4.
Added ip-masq-agent to masquerade daemonset
It created the iptables for masquerading in the host machine
Able to ping the ipv6 device from the container of the ip-masq-agent
Unable to reach the ipv6 device from the container of other workloads in the same cluster. Getting connect: Network is unreachable when running ping6