bind-internal: allow k8s pod network to query the resolvers
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful

Kubernetes nodes querying the bind-resolvers LoadBalancer VIP
(198.18.200.7) get REFUSED (EDE 18 Prohibited). The service is
externalTrafficPolicy: Local, which preserves the client source IP for
traffic entering the cluster from outside — but a node querying the VIP
never leaves via OSPF. Its own kube-proxy DNATs the LB IP in the OUTPUT
chain and masquerades the source to a cluster-internal address (the
node's flannel.1, e.g. 10.42.x.x). That address is not in
acl-main.unkin.net, so the openforwarder view's match-clients rejects
the query.

External clients preserve their real source IP and match acl-main, which
is why only in-cluster hosts were affected.

Add 10.42.0.0/16 to acl-main.unkin.net so node-originated (masqueraded)
resolver queries are permitted. This mirrors the authoritative cluster,
which already allows the pod network (allow-query { ...; 10.42.0.0/16; }).
This commit is contained in:
2026-07-21 22:08:39 +10:00
parent f835a059f4
commit dbb4cb75db
@@ -8,6 +8,7 @@ metadata:
spec:
clusterRef: bind-resolvers
entries:
- 10.42.0.0/16 # k8s pod network (kube-proxy masquerades node-originated LB queries)
- 198.18.1.10/32
- 198.18.2.160/27
- 198.18.21.160/27