Set traefik-external externalTrafficPolicy to Local #519
Reference in New Issue
Block a user
Delete Branch "benvin/traefik-external-local-traffic"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
With the default Cluster external policy, kube-proxy SNATs inbound traffic to the traefik-external LoadBalancer, hiding real client IPs from traefik and adding a cross-node hop. Local preserves source IPs. Internal policy stays Cluster so in-cluster callers on nodes without a traefik-external pod still reach it.
externalTrafficPolicy: Localon the traefik-external ServiceinternalTrafficPolicy: ClusterexplicitlyinternalTrafficPolicy: Localis not justified by the stated why (source IP / external hop) and breaks in-cluster clients of the ClusterIP: pods on nodes without a traefik-external pod (2-5 replicas) get dropped traffic → remove this line, or split to its own PR with its own why.Set traefik-external traffic policies to Localto Set traefik-external externalTrafficPolicy to LocalinternalTrafficPolicy: Clusteris the Service default and only governs ClusterIP traffic, not the LB IP, so it does not do what the body claims → drop the line and the matching body bullet.