Sitelet https://github.com/kubernetes/kops/commit/340689d5a29db5067a48484f9234fe25d57170d7
Skip to content

Commit 340689d

Browse files
authored
Merge pull request #18478 from rifelpet/disable-firewalld-rhel10
nodeup: load ip_set module and disable firewalld on RHEL10
2 parents f54e1d7 + 6869831 commit 340689d

2 files changed

Lines changed: 32 additions & 3 deletions

File tree

‎nodeup/pkg/model/firewall.go‎

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,29 @@ func (b *FirewallBuilder) Build(c *fi.NodeupModelBuilderContext) error {
3636
c.AddTask(b.buildFirewallScript())
3737
c.AddTask(b.buildSystemdService())
3838

39+
// On distros where Kubernetes CNIs (notably Calico) document firewalld
40+
// as incompatible, stop and mask it. firewalld's default-reject
41+
// filter_INPUT/filter_FORWARD policies and periodic-reload behavior
42+
// conflict with the iptables/nftables rules CNIs install for pod and
43+
// service traffic. Most cloud images in the RHEL family already ship
44+
// firewalld off (AWS RHEL/Rocky AMIs, upstream Rocky GenericCloud); the
45+
// GCE-optimized Rocky 10 image is the known outlier. The disable/mask
46+
// sequence is idempotent and a no-op where firewalld isn't installed.
47+
// See: https://docs.tigera.io/calico/latest/getting-started/kubernetes/requirements
48+
if b.Distribution.ForceNftables() {
49+
c.AddTask(&nodetasks.File{
50+
Path: "/etc/kops/firewalld-disabled",
51+
Contents: fi.NewStringResource("# Marker: firewalld disabled by kops to avoid conflicts with the Kubernetes CNI dataplane.\n"),
52+
Type: nodetasks.FileType_File,
53+
OnChangeExecute: [][]string{
54+
// Stop and disable so it can't restart at boot.
55+
{"bash", "-c", "systemctl disable --now firewalld.service 2>/dev/null; true"},
56+
// Mask so package updates or preset reloads can't bring it back.
57+
{"bash", "-c", "systemctl mask firewalld.service 2>/dev/null; true"},
58+
},
59+
})
60+
}
61+
3962
return nil
4063
}
4164

‎upup/pkg/fi/nodeup/command.go‎

Lines changed: 9 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -592,9 +592,15 @@ func loadKernelModules(context *model.NodeupModelContext, distribution distribut
592592
}
593593
}
594594
if distribution.ForceNftables() {
595-
// Distributions like RHEL10+ use nftables exclusively
596-
// Load nf_tables and nf_conntrack to fix CNI plugins that use iptables-nft
597-
for _, mod := range []string{"nf_tables", "nf_conntrack"} {
595+
// Distributions like RHEL10+ use nftables exclusively.
596+
// - nf_tables / nf_conntrack: required by CNI plugins that shell out
597+
// to iptables-nft.
598+
// - ip_set: Calico's Felix unconditionally starts an `ipsetsManager`
599+
// that shells out to `ipset list -name` during dataplane resync,
600+
// even when NFTablesMode=Enabled. On RHEL10 family kernels the
601+
// ip_set module isn't auto-loaded, so the ipset call returns
602+
// EINVAL and Felix panics, crashlooping calico-node.
603+
for _, mod := range []string{"nf_tables", "nf_conntrack", "ip_set"} {
598604
if err := modprobe(mod); err != nil {
599605
klog.Warningf("error loading %s module: %v", mod, err)
600606
}

0 commit comments

Comments
 (0)