bind-internal: allow k8s pod network to query the resolvers #271
Reference in New Issue
Block a user
Delete Branch "benvin/k8s_node_dns"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Kubernetes nodes querying the bind-resolvers LoadBalancer VIP (198.18.200.7) get REFUSED (EDE 18 Prohibited).
The service is
externalTrafficPolicy: Local, which preserves the client source IP for traffic entering the cluster from outside — but a node querying the VIP never leaves via OSPF. Its own kube-proxy DNATs the LB IP in the OUTPUT chain and masquerades the source to a cluster-internal address (the node's flannel.1, e.g. 10.42.x.x). That address is not inacl-main.unkin.net, so the openforwarder view's match-clients rejects the query.External clients preserve their real source IP and match acl-main, which is why only in-cluster hosts were affected.
Add
10.42.0.0/16toacl-main.unkin.netso node-originated (masqueraded) resolver queries are permitted. This mirrors the authoritative cluster, which already allows the pod network (allow-query { ...; 10.42.0.0/16; }).Kubernetes nodes querying the bind-resolvers LoadBalancer VIP (198.18.200.7) get REFUSED (EDE 18 Prohibited). The service is externalTrafficPolicy: Local, which preserves the client source IP for traffic entering the cluster from outside — but a node querying the VIP never leaves via OSPF. Its own kube-proxy DNATs the LB IP in the OUTPUT chain and masquerades the source to a cluster-internal address (the node's flannel.1, e.g. 10.42.x.x). That address is not in acl-main.unkin.net, so the openforwarder view's match-clients rejects the query. External clients preserve their real source IP and match acl-main, which is why only in-cluster hosts were affected. Add 10.42.0.0/16 to acl-main.unkin.net so node-originated (masqueraded) resolver queries are permitted. This mirrors the authoritative cluster, which already allows the pod network (allow-query { ...; 10.42.0.0/16; }).