- Sort Score
- Result 10 results
- Languages All
Results 11 - 20 of 37 for from (0.13 sec)
-
cni/pkg/iptables/iptables_linux.go
// // Adds in-pod rules for marking packets with the istio-specific TPROXY mark. // A very similar mechanism is used for sidecar TPROXY. // // TODO largely identical/copied from tools/istio-iptables/pkg/capture/run_linux.go inpodMarkRule := netlink.NewRule() inpodMarkRule.Family = family inpodMarkRule.Table = RouteTableInbound inpodMarkRule.Mark = InpodTProxyMark
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Tue Apr 30 22:24:38 GMT 2024 - 3.3K bytes - Viewed (0) -
cni/pkg/nodeagent/server.go
if err != nil { log.Errorf("failed to remove pod from mesh: %v", err) return err } log.Debug("removing annotation from pod") err = util.AnnotateUnenrollPod(s.kubeClient, &pod.ObjectMeta) if err != nil { log.Errorf("failed to annotate pod unenrollment: %v", err) } return err } // Delete pod from mesh: pod is deleted. iptables rules will die with it, we just need to update ztunnel
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Tue Apr 30 22:24:38 GMT 2024 - 7.2K bytes - Viewed (0) -
architecture/ambient/ztunnel.md
## Background and motivation Motivations to implement ztunnel generally came from two areas. First, and most importantly, it serves as a means to implement the real goal: waypoints. For various reasons outside the scope of this document, there is a desire to move from a sidecar based architecture to a "remote proxy" architecture.
Plain Text - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Thu Apr 25 22:35:16 GMT 2024 - 16.6K bytes - Viewed (0) -
cni/pkg/ipset/nldeps_linux.go
err := netlink.IpsetDel(name, &netlink.IPSetEntry{ IP: net.IP(ip.AsSlice()), Protocol: &ipProto, }) if err != nil { return fmt.Errorf("failed to delete IP %s with and proto %d from ipset %s: %w", ip, ipProto, name, err) } return nil } func (m *realDeps) flush(name string) error { err := netlink.IpsetFlush(name) if err != nil {
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Tue Apr 30 22:24:38 GMT 2024 - 3.9K bytes - Viewed (0) -
cni/pkg/config/config.go
K8sServiceProtocol string // KUBERNETES_SERVICE_HOST K8sServiceHost string // KUBERNETES_SERVICE_PORT K8sServicePort string // KUBERNETES_NODE_NAME K8sNodeName string // Directory from where the CNI binaries should be copied CNIBinSourceDir string // Directories into which to copy the CNI binaries CNIBinTargetDirs []string // The HTTP port for monitoring MonitoringPort int
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Tue Apr 30 22:24:38 GMT 2024 - 5.5K bytes - Viewed (0) -
cni/pkg/nodeagent/informers.go
if matchAmbient { log.Infof("Namespace %s is enabled in ambient mesh", namespace) } else { log.Infof("Namespace %s is disabled from ambient mesh", namespace) } for _, pod := range s.pods.List(namespace, klabels.Everything()) { // ztunnel pods are never "added to/removed from the mesh", so do not fire // spurious events for them to avoid triggering extra // ztunnel node reconciliation checks.
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Fri May 03 19:29:42 GMT 2024 - 9.6K bytes - Viewed (0) -
operator/cmd/mesh/install.go
if revision != util.DefaultRevisionName { revisionWarning = "" } if icpTag < tag { p.Printf("%s Istio is being upgraded from %s to %s.\n"+revisionWarning+check, warnMarker, icpTag, tag) } else { p.Printf("%s Istio is being downgraded from %s to %s.\n"+revisionWarning+check, warnMarker, icpTag, tag) } } } return nil } // GetTagVersion returns istio tag version
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Thu May 02 14:30:43 GMT 2024 - 15.5K bytes - Viewed (1) -
docker/Dockerfile.base
FROM ubuntu:noble ENV DEBIAN_FRONTEND=noninteractive # Do not add more stuff to this list that isn't small or critically useful. # If you occasionally need something on the container do # sudo apt-get update && apt-get whichever # hadolint ignore=DL3005,DL3008 RUN apt-get update && \ apt-get install --no-install-recommends -y \ ca-certificates \ curl \ iptables \ iproute2 \ iputils-ping \ knot-dnsutils \
Plain Text - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Wed May 08 18:50:51 GMT 2024 - 1000 bytes - Viewed (0) -
cni/pkg/iptables/iptables.go
"-j", "CONNMARK", "--set-xmark", inpodTproxyMark) // Handle healthcheck probes from the host node. In the host netns, before the packet enters the pod, we SNAT // the healthcheck packet to a fixed IP if the packet is coming from a node-local process with a socket. // // We do this so we can exempt this traffic from ztunnel capture/proxy - otherwise both kube-proxy (legit)
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Tue May 07 19:54:50 GMT 2024 - 19.7K bytes - Viewed (0) -
istioctl/pkg/writer/ztunnel/configdump/certificates.go
if out, err = yaml.JSONToYAML(out); err != nil { return err } } fmt.Fprintln(c.Stdout, string(out)) return nil } // PrintSecretSummary prints a summary of dynamic active secrets from the config dump func (c *ConfigWriter) PrintSecretSummary() error { if c.ztunnelDump == nil { return fmt.Errorf("config writer has not been primed") } secretDump := c.ztunnelDump.Certificates
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Thu Apr 25 16:38:16 GMT 2024 - 3.2K bytes - Viewed (0)