Add service.kubernetes.io/service-proxy-name label to LoadBalancer services when external: true. This prevents Cilium from adding the service to its BPF service map, fixing two issues: 1. Inter-tenant connectivity via public LB IPs: Cilium's kube-proxy replacement DNATs traffic to LB IPs before policy evaluation, causing the CiliumClusterwideNetworkPolicy to block legitimate cross-tenant traffic through public IPs. 2. WholeIP broken on Cilium 1.19+ (#2327): wildcard service drop entries block all ports not declared in the Service spec before traffic reaches cozy-proxy's nftables rules. With this label, Cilium completely ignores the Service. Routing is handled by kube-ovn (via the wholeIP annotation) and MetalLB continues to advertise the IP via L2 unaffected. Tested on Cilium 1.18.6 and 1.19.1: inter-tenant via LB IP works, pod IP isolation preserved, external access unaffected. Signed-off-by: mattia-eleuteri <mattia@hidora.io> |
||
|---|---|---|
| .. | ||
| _helpers.tpl | ||
| dashboard-resourcemap.yaml | ||
| secret.yaml | ||
| service.yaml | ||
| vm-update-hook.yaml | ||
| vm.yaml | ||