Sitelet https://github.com/kubernetes/kops/pull/18237
Skip to content

cilium: require k8s-connectivity in liveness probe - #18237

Merged
k8s-ci-robot merged 2 commits into
kubernetes:masterfrom
hakman:cilium-k8s-connectivity
Apr 24, 2026
Merged

k8s-ci-robot merged 2 commits into
kubernetes:masterfrom
hakman:cilium-k8s-connectivity

Conversation

@hakman

@hakman hakman commented Apr 24, 2026 •

Copy link
Copy Markdown
Member

This is a regression that blocks refresh of control-plane address for the agents. This was introduced during the last major update and is present in kOps v1.34 and v1.35.

The Q would, do we want to remove this "feature" or we may want to ignore cilium agents during cluster validation?

https://docs.cilium.io/en/stable/api/

GET /healthz returns health and status information of the Cilium daemon and related components such as the local container runtime, connected datastore, Kubernetes integration and Hubble. It accepts the request header "brief" which returns a brief representation of the Cilium status, and "require-k8s-connectivity" which, if set to true, causes failure of the agent to connect to the Kubernetes control plane to also fail the agent's health status.

cilium/cilium#32724

The community discussed the issue in the APAC community meeting and concluded that killing the whole Cilium agent on k8s disconnection is too aggressive — if the kube-apiserver goes down, that would force every cilium-agent instance in the cluster to also go down. Similar to how the dataplane should continue without the local control plane, it makes sense for the local control plane to continue without the central control plane.

/cc @rifelpet @ameukam

@k8s-ci-robot k8s-ci-robot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. area/addons cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. labels Apr 24, 2026
@hakman
hakman force-pushed the cilium-k8s-connectivity branch from a4e64f1 to ddea5ec Compare April 24, 2026 14:38
@k8s-ci-robot k8s-ci-robot added size/M Denotes a PR that changes 30-99 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Apr 24, 2026
@hakman
hakman force-pushed the cilium-k8s-connectivity branch from ddea5ec to dd375d0 Compare April 24, 2026 15:08
@rifelpet

Copy link
Copy Markdown
Member

can you link to any failing jobs or error logs that this would fix?

@hakman

hakman commented Apr 24, 2026

Copy link
Copy Markdown
Member Author

can you link to any failing jobs or error logs that this would fix?

not really, will happen only with real dns or gossip. tested it with gossip and was surprised the agents don't pick up control-plane changes, just get stuck forever waiting to be restarted.

@k8s-ci-robot k8s-ci-robot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Apr 24, 2026
@k8s-ci-robot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: rifelpet

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Apr 24, 2026
@hakman

hakman commented Apr 24, 2026

Copy link
Copy Markdown
Member Author

/test all

@k8s-ci-robot
k8s-ci-robot merged commit 4fe1979 into kubernetes:master Apr 24, 2026
33 of 36 checks passed
k8s-ci-robot added a commit that referenced this pull request Apr 25, 2026
…-upstream-release-1.35

Automated cherry pick of #18237: cilium: require k8s-connectivity in liveness probe
@hakman

hakman commented Apr 25, 2026

Copy link
Copy Markdown
Member Author

can you link to any failing jobs or error logs that this would fix?

Reproduced as part of https://prow.k8s.io/view/gs/kubernetes-ci-logs/pr-logs/pull/kops/18244/pull-kops-aws-upgrade-k135-ko135-to-k136-kolatest-many-addons/2047969291231301632.

k8s-ci-robot added a commit that referenced this pull request Apr 25, 2026
…-upstream-release-1.34

Automated cherry pick of #18237: cilium: require k8s-connectivity in liveness probe
@hakman
hakman deleted the cilium-k8s-connectivity branch May 2, 2026 04:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/addons cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants