Skip to content

cilium policy trace should prompt user to specify --dport #1940

@joestringer

Description

@joestringer

When a user performs cilium policy trace -s ... -d ... and there are L3-dependent l4 policies in place, it only traces l3, and prints a message like Rule restricts traffic to specific L4 destinations; deferring policy decision to L4 policy stage and Label verdict: undecided. There's no prompt to perform a more thorough trace.

It would be more user-friendly if we reported that l4 policies are skipped and prompt the user to specify --dport in the case when it's not specified.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/daemonImpacts operation of the Cilium daemon.good-first-issueGood starting point for new developers, which requires minimal understanding of Cilium.staleThe stale bot thinks this issue is old. Add "pinned" label to prevent this from becoming stale.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions