Comments (4)
attempt to install Istio Ambient on Talos fails, and this may have to do with the way the Istio-CNI leverages IPtables for redirection of traffic towards the ztunnel and Talos disallows any node-level network reconfiguration.
Hey Marino 👋 ,
Talos doesn't prevent modifications using iptables. I think it could be ztunnel tried to load a module? Talos doesn;t allow loading modules by K8s workloads. Could you also provide the logs of the failed pod/daemonset?
from talos.
Do you know what CNI Talos k8s is using? also does this work with default profile?
from talos.
Do you know what CNI Talos k8s is using?
talos uses flannel by default, but it can be disabled to install a cni of choice
also does this work with default profile?
not sure I get that, you mean K8s pod security profiles/seccomp profiles?
from talos.
attempt to install Istio Ambient on Talos fails, and this may have to do with the way the Istio-CNI leverages IPtables for redirection of traffic towards the ztunnel and Talos disallows any node-level network reconfiguration.
Hey Marino 👋 ,
Talos doesn't prevent modifications using iptables. I think it could be ztunnel tried to load a module? Talos doesn;t allow loading modules by K8s workloads. Could you also provide the logs of the failed pod/daemonset?
Do you know what CNI Talos k8s is using?
talos uses flannel by default, but it can be disabled to install a cni of choice
also does this work with default profile?
not sure I get that, you mean K8s pod security profiles/seccomp profiles?
Hi Noel!! How are you? Great to hear from you 😄 !!!
Lin is referring to the Istio installation profiles such as Default and Ambient, which proceed to install the necessary components of Istio.
Let me see if I can dig into some logs and share what I find.
from talos.
Related Issues (20)
- Include AppArmor LSM in kernel
- Talos 1.8 Release Checklist
- Cilium not get installed with TF HOT 4
- `debug: true` in machineconfig causes apid to hang in esxi HOT 1
- NfTables chain does not get updated with latest KubeSpan peer when `allowDownPeerBypass: true`
- Do not set a default endpoint value in talosctl gen config HOT 1
- Default Flannel installation does not account for KubePrism endpoint
- talosctl cluster create should handle multiple KUBECONFIG files better HOT 2
- talosctl (v1.6.7) is not running on old AMD64 CPU. It requires AMD64 processors with v2 microarchitecture support. HOT 2
- Talos worker not responding to ARP requests HOT 1
- [Feature Request] Hosted control planes for Talos clusters HOT 1
- [Feature Request] Add "permissions" option to machine.disks.partition in Talos configuration
- [bug] Talos configuration will apply the disks section before all devices are ready
- shasum.txt doesn't match binary name
- How to allow port 5678 - Error: Invalid NodePort Value in nginx-ingress-n8n Service YAML HOT 1
- Fix for wireguard UAPI socket to be under `/system` HOT 1
- A problem with multi-terabyte EPHEMERAL HOT 2
- Unable to setup a second network interface in non-routed network HOT 3
- Routing tables configuration (policy routing) and more HOT 1
- Automatically rotate the kubelet certificates HOT 3
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from talos.