mirror of https://github.com/k3s-io/k3s
Explicitly set route_localnet on nodes & masters.
Allow for loopback addresses to be used for routing, specifically to enable metadata proxy on master nodes.pull/6/head
parent
40212c17cd
commit
a051a54962
|
@ -34,6 +34,11 @@ function setup-os-params {
|
|||
|
||||
function config-ip-firewall {
|
||||
echo "Configuring IP firewall rules"
|
||||
|
||||
# Do not consider loopback addresses as martian source or destination while
|
||||
# routing. This enables the use of 127/8 for local routing purposes.
|
||||
sysctl -w net.ipv4.conf.all.route_localnet=1
|
||||
|
||||
# The GCI image has host firewall which drop most inbound/forwarded packets.
|
||||
# We need to add rules to accept all TCP/UDP/ICMP packets.
|
||||
if iptables -L INPUT | grep "Chain INPUT (policy DROP)" > /dev/null; then
|
||||
|
|
Loading…
Reference in New Issue