Skip to content

remove kubelet ipv4 ACCEPT override#833

Open
rpkelly wants to merge 7 commits intobottlerocket-os:developfrom
rpkelly:kubernetes-ipv4
Open

remove kubelet ipv4 ACCEPT override#833
rpkelly wants to merge 7 commits intobottlerocket-os:developfrom
rpkelly:kubernetes-ipv4

Conversation

@rpkelly
Copy link
Contributor

@rpkelly rpkelly commented Feb 13, 2026

Issue number: #540

Description of changes:
Removing FORWARD ACCEPT override of iptables for kubernetes variants.

Testing done:

Built k8s 1.34 and ran k8s e2e tests on ipv4 cluster

Terms of contribution:

By submitting this pull request, I agree that this contribution is dual-licensed under the terms of both the Apache License, version 2.0, and the MIT license.

Signed-off-by: Richard Kelly <rpkelly@amazon.com>
Signed-off-by: Richard Kelly <rpkelly@amazon.com>
Signed-off-by: Richard Kelly <rpkelly@amazon.com>
Signed-off-by: Richard Kelly <rpkelly@amazon.com>
Signed-off-by: Richard Kelly <rpkelly@amazon.com>
Signed-off-by: Richard Kelly <rpkelly@amazon.com>
Signed-off-by: Richard Kelly <rpkelly@amazon.com>
@bcressey
Copy link
Contributor

Please squash this together into one commit that explains (at length) why the change is being made and why it's safe now (with citations) when presumably it wasn't in the past.

It's not obvious to me that it's going to be compatible with deployed (i.e., not necessarily latest) versions of the various CNI solutions: aws-vpc, Cilium, Calico.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants