From 24c9e317d33f94e39160c6754b41a810dc0f54d5 Mon Sep 17 00:00:00 2001 From: Christian Pointner Date: Sun, 18 Oct 2020 23:50:49 +0200 Subject: standalone/kubelet: local services limit source address --- .../standalone/base/templates/kube-standalone-local-services.sh.j2 | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'roles/kubernetes') diff --git a/roles/kubernetes/standalone/base/templates/kube-standalone-local-services.sh.j2 b/roles/kubernetes/standalone/base/templates/kube-standalone-local-services.sh.j2 index d29e6a34..fdfb1777 100644 --- a/roles/kubernetes/standalone/base/templates/kube-standalone-local-services.sh.j2 +++ b/roles/kubernetes/standalone/base/templates/kube-standalone-local-services.sh.j2 @@ -4,10 +4,10 @@ iptables -t nat -N kube-local-services > /dev/null 2>&1 iptables -t nat -F kube-local-services {% if kubernetes_standalone_local_services_tcp | length > 0 %} -iptables -t nat -A kube-local-services -p tcp --match multiport --dports {{ kubernetes_standalone_local_services_tcp | join(',') }} -i kube-bridge -d {{ kubernetes_standalone_pod_cidr | ipaddr('1') | ipaddr('address') }} -j DNAT --to-destination 127.0.0.1 +iptables -t nat -A kube-local-services -p tcp --match multiport --dports {{ kubernetes_standalone_local_services_tcp | join(',') }} -i kube-bridge -s {{ kubernetes_standalone_pod_cidr }} -d {{ kubernetes_standalone_pod_cidr | ipaddr('1') | ipaddr('address') }} -j DNAT --to-destination 127.0.0.1 {% endif %} {% if kubernetes_standalone_local_services_udp | length > 0 %} -iptables -t nat -A kube-local-services -p udp --match multiport --dports {{ kubernetes_standalone_local_services_udp | join(',') }} -i kube-bridge -d {{ kubernetes_standalone_pod_cidr | ipaddr('1') | ipaddr('address') }} -j DNAT --to-destination 127.0.0.1 +iptables -t nat -A kube-local-services -p udp --match multiport --dports {{ kubernetes_standalone_local_services_udp | join(',') }} -i kube-bridge -s {{ kubernetes_standalone_pod_cidr }} -d {{ kubernetes_standalone_pod_cidr | ipaddr('1') | ipaddr('address') }} -j DNAT --to-destination 127.0.0.1 {% endif %} iptables -t nat -C PREROUTING -j kube-local-services > /dev/null 2>&1 -- cgit v1.2.3