I don't know whether that's correct, but I figure that bridge-nf-call is a typo. I did not have a kernel in reach that had that sysctl. When using net.bridge.bridge-nf-call-iptables, container egress works alright.
Note, that I did not get into the trouble to verify that change by building a new openshift/node image.
I don't know whether that's correct, but I figure that bridge-nf-call is a typo. I did not have a kernel in reach that had that sysctl. When using net.bridge.bridge-nf-call-iptables, container egress works alright.
Note, that I did not get into the trouble to verify that change by building a new openshift/node image.