Sitelet https://github.com/kubernetes/kops/pull/18494
Skip to content

Automated cherry pick of #18478: nodeup: load ip_set module and disable firewalld on RHEL10 - #18494

Merged
k8s-ci-robot merged 1 commit into
kubernetes:release-1.35from
rifelpet:automated-cherry-pick-of-#18478-origin-release-1.35
Jun 19, 2026
Merged

k8s-ci-robot merged 1 commit into
kubernetes:release-1.35from
rifelpet:automated-cherry-pick-of-#18478-origin-release-1.35

Conversation

@rifelpet

Copy link
Copy Markdown
Member

Cherry pick of #18478 on release-1.35.

#18478: nodeup: load ip_set module and disable firewalld on RHEL10

For details on the cherry pick process, see the cherry pick requests page.

What type of PR is this?


Two related fixes for Calico on the ForceNftables() distros (RHEL10+,
Rocky10+, etc.).

Load the ip_set kernel module alongside nf_tables and nf_conntrack.
Calico's Felix unconditionally starts an ipsetsManager that shells out
to "ipset list -name" during dataplane resync, even when NFTablesMode
is Enabled. On RHEL10-family kernels ip_set is not auto-loaded, so the
ipset call returns EINVAL and Felix panics in a tight loop, crashing
calico-node and blocking cluster Up on every arm64 grid cell.

Disable and mask firewalld via a new disableFirewalld step on
FirewallBuilder, gated on Distribution.ForceNftables(). firewalld's
default-reject filter_INPUT/filter_FORWARD policies and periodic-reload
behavior conflict with the iptables/nftables rules CNIs install for
pod and service traffic; Calico's own requirements doc and RKE2 both
document that firewalld must be disabled on hosts running these CNIs.
The disable/mask sequence is idempotent and a no-op where firewalld is
not installed, so this is net-neutral on the cloud images that already
strip firewalld (AWS RHEL/Rocky AMIs, Rocky GenericCloud) and net-
positive on the GCE-optimized Rocky 10 image where firewalld ships
active and breaks Calico BGP keepalives in BPF mode.
@k8s-ci-robot k8s-ci-robot added this to the v1.35 milestone Jun 18, 2026
@k8s-ci-robot k8s-ci-robot added the size/M Denotes a PR that changes 30-99 lines, ignoring generated files. label Jun 18, 2026
@k8s-ci-robot
k8s-ci-robot requested review from hakman and olemarkus June 18, 2026 20:36
@k8s-ci-robot k8s-ci-robot added area/nodeup cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. labels Jun 18, 2026
@k8s-ci-robot k8s-ci-robot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Jun 19, 2026
@k8s-ci-robot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: hakman

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jun 19, 2026
@k8s-ci-robot
k8s-ci-robot merged commit a826c8e into kubernetes:release-1.35 Jun 19, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/nodeup cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants