• Icon: Sub-task Sub-task
    • Resolution: Done
    • Icon: Major Major
    • maistra-2.1.0
    • None
    • None
    • None
    • Sprint 9, Sprint 10, Sprint 11

      DNS capture is not correct when using CNI. It's capturing packets which the destination is the server found in /etc/resolv.conf. Since with CNI the iptables binary runs on the node, it's getting the contents of resolv.conf from the node, not from the container. Upstream fixed this in https://github.com/istio/istio/issues/29511 which we need to backport in some way.

            jsantana@redhat.com Jonh Wendell
            jsantana@redhat.com Jonh Wendell
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: