Set traefik-external externalTrafficPolicy to Local (#519)
With the default Cluster external policy, kube-proxy SNATs inbound traffic to the traefik-external LoadBalancer, hiding real client IPs from traefik and adding a cross-node hop. Local preserves source IPs. Internal policy stays Cluster so in-cluster callers on nodes without a traefik-external pod still reach it. - Set `externalTrafficPolicy: Local` on the traefik-external Service - Set `internalTrafficPolicy: Cluster` explicitly Reviewed-on: #519 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #519.
This commit is contained in:
@@ -59,6 +59,8 @@ service:
|
||||
spec:
|
||||
type: LoadBalancer
|
||||
loadBalancerIP: "198.18.199.0"
|
||||
externalTrafficPolicy: Local
|
||||
internalTrafficPolicy: Cluster
|
||||
additionalServices: {}
|
||||
|
||||
autoscaling:
|
||||
|
||||
Reference in New Issue
Block a user