- Sort Score
- Result 10 results
- Languages All
Results 1 - 10 of 14 for Mask (0.18 sec)
-
cni/pkg/iptables/iptables_linux.go
inpodMarkRule := netlink.NewRule() inpodMarkRule.Family = family inpodMarkRule.Table = RouteTableInbound inpodMarkRule.Mark = InpodTProxyMark inpodMarkRule.Mask = InpodTProxyMask inpodMarkRule.Priority = 32764 rules = append(rules, inpodMarkRule) } for _, rule := range rules { log.Debugf("Iterating netlink rule : %+v", rule) if err := f(rule); err != nil {
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Tue Apr 30 22:24:38 GMT 2024 - 3.3K bytes - Viewed (0) -
common-protos/k8s.io/api/networking/v1alpha1/generated.proto
// perNodeHostBits defines the number of host bits to be configured per node. // A subnet mask determines how much of the address is used for network bits // and host bits. For example an IPv4 address of 192.168.0.0/24, splits the // address into 24 bits for the network portion and 8 bits for the host portion. // To allocate 256 IPs, set this field to 8 (a /24 mask for IPv4 or a /120 for IPv6). // Minimum value is 4 (16 IPs). // This field is immutable.
Plain Text - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Mon Mar 11 18:43:24 GMT 2024 - 6K bytes - Viewed (0) -
cni/pkg/repair/netns.go
return link.Attrs().NetNsID, nil } func getLinkWithDestinationOf(ip string) (netlink.Link, error) { routes, err := netlink.RouteListFiltered( netlink.FAMILY_V4, &netlink.Route{Dst: &net.IPNet{IP: net.ParseIP(ip), Mask: net.CIDRMask(32, 32)}}, netlink.RT_FILTER_DST) if err != nil { return nil, err } if len(routes) == 0 { return nil, fmt.Errorf("no routes found for %s", ip) } linkIndex := routes[0].LinkIndex
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Wed Dec 20 22:14:13 GMT 2023 - 4.8K bytes - Viewed (0) -
SUPPORT.md
Plain Text - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Mon Feb 12 19:00:41 GMT 2024 - 411 bytes - Viewed (0) -
cni/pkg/nodeagent/cni-watcher.go
var podIps []netip.Addr for _, configuredPodIPs := range addCmd.IPs { // net.ip is implicitly convertible to netip as slice ip, _ := netip.AddrFromSlice(configuredPodIPs.Address.IP) // We ignore the mask of the IPNet - it's fine if the IPNet defines // a block grant of addresses, we just need one for checking routes. podIps = append(podIps, ip) }
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Thu Feb 08 18:52:24 GMT 2024 - 6.1K bytes - Viewed (0) -
cni/pkg/nodeagent/net.go
// 2. Adding the pod's IPs to the hostnetns ipsets for node probe checks // 3. Creating iptables rules inside the pod's netns // 4. Notifying ztunnel via GRPC to create a proxy for the pod // // You may ask why we pass the pod IPs separately from the pod manifest itself (which contains the pod IPs as a field) // - this is because during add specifically, if CNI plugins have not finished executing,
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Tue Apr 30 22:24:38 GMT 2024 - 12.2K bytes - Viewed (1) -
architecture/ambient/ztunnel.md
## Redirection As ztunnel aims to transparently encrypt and route users traffic, we need a mechanism to capture all traffic entering and leaving "mesh" pods. This is a security critical task: if the ztunnel can be bypassed, authorization policies can be bypassed. Redirection must meet these requirements: * All traffic *egressing* a pod in the mesh should be redirected to the node-local ztunnel on port 15001.
Plain Text - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Thu Apr 25 22:35:16 GMT 2024 - 16.6K bytes - Viewed (0) -
istioctl/pkg/validate/validate.go
if err := checkFields(un); err != nil { return nil, err } // IstioOperator isn't part of pkg/config/schema/collections, // usual conversion not available. Convert unstructured to string // and ask operator code to check. un.SetCreationTimestamp(metav1.Time{}) // UnmarshalIstioOperator chokes on these by := util.ToYAML(un) iop, err := operatoristio.UnmarshalIstioOperator(by, false) if err != nil {
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Mon Jan 22 17:58:52 GMT 2024 - 15K bytes - Viewed (0) -
Makefile.core.mk
.PHONY: test # This target sets JUNIT_REPORT to the location of the go-junit-report binary. # This binary is provided in the build container. If it is not found, the build # container is not being used, so ask the user to install go-junit-report. JUNIT_REPORT := $(shell which go-junit-report 2> /dev/null || echo "${ISTIO_BIN}/go-junit-report") ${ISTIO_BIN}/go-junit-report:
Plain Text - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Wed May 08 20:25:15 GMT 2024 - 22.5K bytes - Viewed (0) -
istioctl/pkg/describe/describe.go
svcHost := extendFQDN(fmt.Sprintf("%s.%s", svc.ObjectMeta.Name, svc.ObjectMeta.Namespace)) filter := istio_envoy_configdump.ClusterFilter{ FQDN: host.Name(svcHost), Port: int(port), // Although we want inbound traffic, ask for outbound traffic, as the DR is // not associated with the inbound traffic. Direction: model.TrafficDirectionOutbound, } dump, err := cd.GetClusterConfigDump() if err != nil { return "", err }
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Sat Apr 13 05:23:38 GMT 2024 - 50.4K bytes - Viewed (0)