Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Stop fighting calico #745

Merged
merged 1 commit into from
Nov 8, 2024
Merged

Stop fighting calico #745

merged 1 commit into from
Nov 8, 2024

Conversation

daaang
Copy link
Collaborator

@daaang daaang commented Nov 8, 2024

No description provided.

The newer firewall can get into a weird state when port ranges are
defined with hyphens, because in iptables they are defined with colons,
so puppet agent will view this as a corrective change.

This is not necessarily a problem, but when the host's networking is
sufficiently chaotic, this attempt at a corrective change can cause the
puppet server to lose the resource in favor of `nil` and crash.

Calico is sufficiently chaotic, and this commit also aims to stop
purging half of calico's firewall on every puppet agent run.
Copy link
Member

@rrotter rrotter left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@daaang daaang merged commit c19fb50 into production Nov 8, 2024
1 check passed
@daaang daaang deleted the stop-fighting-calico branch November 8, 2024 21:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants