summaryrefslogtreecommitdiff
path: root/roles/kubernetes/net
diff options
context:
space:
mode:
authorChristian Pointner <equinox@spreadspace.org>2020-01-17 22:24:09 +0100
committerChristian Pointner <equinox@spreadspace.org>2020-01-31 22:31:22 +0100
commit8010f57a73885f7abb5c98c1f77c49baa59a7d16 (patch)
tree334f5c6c0af02fe3fce098feb398808101a066d9 /roles/kubernetes/net
parentkubernetes: node cleanup works now (diff)
kubernetes: multi master cluster works now
Diffstat (limited to 'roles/kubernetes/net')
-rw-r--r--roles/kubernetes/net/kubeguard/templates/kubeguard-peer.service.j23
1 files changed, 2 insertions, 1 deletions
diff --git a/roles/kubernetes/net/kubeguard/templates/kubeguard-peer.service.j2 b/roles/kubernetes/net/kubeguard/templates/kubeguard-peer.service.j2
index 6f36b571..9ca444e8 100644
--- a/roles/kubernetes/net/kubeguard/templates/kubeguard-peer.service.j2
+++ b/roles/kubernetes/net/kubeguard/templates/kubeguard-peer.service.j2
@@ -4,6 +4,7 @@ After=network.target
Requires=kubeguard-interfaces.service
After=kubeguard-interfaces.service
+{% set pod_ip_self = kubernetes.pod_ip_range | ipsubnet(kubernetes.pod_ip_range_size, kubeguard.node_index[inventory_hostname]) | ipaddr(1) | ipaddr('address') -%}
{% set pod_net_peer = kubernetes.pod_ip_range | ipsubnet(kubernetes.pod_ip_range_size, kubeguard.node_index[peer]) -%}
{% set direct_zone = kubeguard.direct_net_zones | direct_net_zone(inventory_hostname, peer) -%}
{% if direct_zone %}
@@ -22,7 +23,7 @@ Type=oneshot
{% if direct_zone %}
ExecStart=/sbin/ip addr add {{ direct_ip }} dev {{ direct_interface }}
ExecStart=/sbin/ip link set up dev {{ direct_interface }}
-ExecStart=/sbin/ip route add {{ pod_net_peer }} via {{ direct_ip_peer | ipaddr('address') }}
+ExecStart=/sbin/ip route add {{ pod_net_peer }} via {{ direct_ip_peer | ipaddr('address') }} src {{ pod_ip_self }}
ExecStop=/sbin/ip route del {{ pod_net_peer }}
ExecStop=/sbin/ip link set down dev {{ direct_interface }}
ExecStop=/sbin/ip addr del {{ direct_ip }} dev {{ direct_interface }}