Sitelet https://github.com/kubernetes/kops/pull/18452
Skip to content

Calico: add NFTablesMode setting - #18452

Merged
k8s-ci-robot merged 1 commit into
kubernetes:masterfrom
rifelpet:calico-nftables-mode
Jun 7, 2026
Merged

k8s-ci-robot merged 1 commit into
kubernetes:masterfrom
rifelpet:calico-nftables-mode

Conversation

@rifelpet

@rifelpet rifelpet commented Jun 7, 2026

Copy link
Copy Markdown
Member

Surface Calico's Felix NFTablesMode (Disabled, Enabled, Auto) as a field on CalicoNetworkingSpec and propagate it to the calico-node DaemonSet via FELIX_NFTABLESMODE. When left unset, the upstream Calico chart default applies, preserving existing behavior.

On distributions where iptables is only present as a shim over nftables (e.g. RHEL10+, Rocky10+), routing Felix's data plane through iptables-nft / nft_compat has produced BGP session flapping and broken pod networking on GCE. This field lets clusters opt their Calico install into native nftables on those nodes.

Surface Calico's Felix NFTablesMode (Disabled, Enabled, Auto) as a
field on CalicoNetworkingSpec and propagate it to the calico-node
DaemonSet via FELIX_NFTABLESMODE. When left unset, the upstream
Calico chart default applies, preserving existing behavior.

On distributions where iptables is only present as a shim over
nftables (e.g. RHEL10+, Rocky10+), routing Felix's data plane
through iptables-nft / nft_compat has produced BGP session flapping
and broken pod networking on GCE. This field lets clusters opt
their Calico install into native nftables on those nodes.
@k8s-ci-robot

Copy link
Copy Markdown
Contributor

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@k8s-ci-robot k8s-ci-robot added do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Jun 7, 2026
@k8s-ci-robot
k8s-ci-robot requested review from olemarkus and zetaab June 7, 2026 12:16
@k8s-ci-robot k8s-ci-robot added area/addons area/api cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. labels Jun 7, 2026
@rifelpet

rifelpet commented Jun 7, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-e2e-k8s-gce-calico-rocky10

2 similar comments
@rifelpet

rifelpet commented Jun 7, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-e2e-k8s-gce-calico-rocky10

@rifelpet

rifelpet commented Jun 7, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-e2e-k8s-gce-calico-rocky10

@k8s-ci-robot k8s-ci-robot removed the size/S Denotes a PR that changes 10-29 lines, ignoring generated files. label Jun 7, 2026
@rifelpet

rifelpet commented Jun 7, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-e2e-k8s-gce-calico-rocky10

@k8s-ci-robot k8s-ci-robot added the size/M Denotes a PR that changes 30-99 lines, ignoring generated files. label Jun 7, 2026
@rifelpet
rifelpet force-pushed the calico-nftables-mode branch from 6bca570 to 1c09677 Compare June 7, 2026 18:04
@k8s-ci-robot k8s-ci-robot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Jun 7, 2026
@rifelpet

rifelpet commented Jun 7, 2026

Copy link
Copy Markdown
Member Author

@rifelpet
rifelpet marked this pull request as ready for review June 7, 2026 18:05
@k8s-ci-robot k8s-ci-robot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jun 7, 2026
@k8s-ci-robot
k8s-ci-robot requested a review from hakman June 7, 2026 18:05
@k8s-ci-robot k8s-ci-robot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Jun 7, 2026
@k8s-ci-robot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: hakman

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jun 7, 2026
@hakman

hakman commented Jun 7, 2026

Copy link
Copy Markdown
Member

/override pull-kops-e2e-cni-kubenet

@k8s-ci-robot

Copy link
Copy Markdown
Contributor

@hakman: Overrode contexts on behalf of hakman: pull-kops-e2e-cni-kubenet

Details

In response to this:

/override pull-kops-e2e-cni-kubenet

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@hakman

hakman commented Jun 7, 2026

Copy link
Copy Markdown
Member

/override pull-kops-e2e-k8s-gce-calico-rocky10

@k8s-ci-robot

Copy link
Copy Markdown
Contributor

@hakman: Overrode contexts on behalf of hakman: pull-kops-e2e-k8s-gce-calico-rocky10

Details

In response to this:

/override pull-kops-e2e-k8s-gce-calico-rocky10

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@k8s-ci-robot
k8s-ci-robot merged commit aece537 into kubernetes:master Jun 7, 2026
41 of 43 checks passed
k8s-ci-robot added a commit that referenced this pull request Jun 8, 2026
…52-origin-release-1.35

Automated cherry pick of #18452: Calico: add NFTablesMode setting
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/addons area/api cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/S Denotes a PR that changes 10-29 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants