Skip to content
This repository was archived by the owner on May 30, 2023. It is now read-only.

coreos-base/oem-gce: grant CAP_NET_ADMIN to set routes for LB#1146

Merged
pothos merged 1 commit intomainfrom
kai/gce-oem-net-admin
Jul 30, 2021
Merged

coreos-base/oem-gce: grant CAP_NET_ADMIN to set routes for LB#1146
pothos merged 1 commit intomainfrom
kai/gce-oem-net-admin

Conversation

@pothos
Copy link
Copy Markdown
Contributor

@pothos pothos commented Jul 29, 2021

With the switch from rkt to systemd-nspawn the ability for the service
to set the routing entries for the TCP load balancer got lost,
resulting in an unreachable LB as reported in
flatcar/Flatcar#459

The fix also reported there is to retain CAP_NET_ADMIN when starting
the service.

How to use

Testing done

Regular release tests: http://localhost:9091/job/os/job/manifest/3159/cldsv/

With the switch from rkt to systemd-nspawn the ability for the service
to set the routing entries for the TCP load balancer got lost,
resulting in an unreachable LB as reported in
flatcar/Flatcar#459

The fix also reported there is to retain CAP_NET_ADMIN when starting
the service.
@pothos pothos requested a review from a team July 30, 2021 16:01
@pothos pothos marked this pull request as ready for review July 30, 2021 16:01
@pothos pothos merged commit 57f96a5 into main Jul 30, 2021
@pothos pothos deleted the kai/gce-oem-net-admin branch July 30, 2021 16:31
pothos added a commit that referenced this pull request Aug 3, 2021
coreos-base/oem-gce: grant CAP_NET_ADMIN to set routes for LB
pothos added a commit that referenced this pull request Aug 3, 2021
coreos-base/oem-gce: grant CAP_NET_ADMIN to set routes for LB
pothos added a commit that referenced this pull request Aug 3, 2021
coreos-base/oem-gce: grant CAP_NET_ADMIN to set routes for LB
@pothos
Copy link
Copy Markdown
Contributor Author

pothos commented Aug 3, 2021

Picked for 2942, 2920, 2905 (Alpha, Beta, Stable)

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants