Skip to content

add net.ipv4.ip_unprivileged_port_start sysctl#298

Draft
pacoxu wants to merge 2 commits into
coredns:masterfrom
pacoxu:add-sysctl
Draft

add net.ipv4.ip_unprivileged_port_start sysctl#298
pacoxu wants to merge 2 commits into
coredns:masterfrom
pacoxu:add-sysctl

Conversation

@pacoxu

@pacoxu pacoxu commented Aug 6, 2024

Copy link
Copy Markdown
Contributor

kubernetes/kubernetes#103326 marked it as safe sysctl since Kubernetes v1.22.

Kernel 4.11 add this: torvalds/linux@4548b68 which is per namespaced.

xref coredns/coredns#6716 and kubernetes/kubernetes#125226.

pacoxu added 2 commits August 6, 2024 12:36
Signed-off-by: Paco Xu <paco.xu@daocloud.io>
Signed-off-by: Paco Xu <paco.xu@daocloud.io>
@pacoxu

pacoxu commented Aug 6, 2024

Copy link
Copy Markdown
Contributor Author

CI failure is golang install failure.
I sent a PR #299 to fix the CI seperately.

@pacoxu

pacoxu commented Aug 6, 2024

Copy link
Copy Markdown
Contributor Author

/assign @chrisohaver

@pacoxu

pacoxu commented Aug 6, 2024

Copy link
Copy Markdown
Contributor Author

BTW, this needs kernel 4.11+

Or coredns pod will fail with below error:

Warning FailedCreatePodSandBox 2s (x13 over 43s) kubelet Failed to create pod sandbox: rpc error: code = Unknown desc = failed to create containerd task: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: open /proc/sys/net/ipv4/ip_unprivileged_port_start: no such file or directory: unknown

For more context, see kubernetes/kubernetes#105309 (comment).

@pacoxu

pacoxu commented Aug 6, 2024

Copy link
Copy Markdown
Contributor Author

/hold
for kernel version 4.11 requirement

@Tej-Singh-Rana

Copy link
Copy Markdown

Thanks, Pacoxu. 👍

@pacoxu pacoxu marked this pull request as draft August 7, 2024 01:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants