pod内容器
➜ ~kubectl logs productpage-v1-65576bb7bf-rcnfr
error: a container name must be specified for pod productpage-v1-65576bb7bf-rcnfr, choose one of: [productpage istio-proxy] or one of the init containers: [istio-init]
istio-proxy
➜ ~ kubectl logs productpage-v1-65576bb7bf-rcnfr -c istio-proxy
2021-09-23T02:52:11.293116Z info FLAG: --concurrency="2"
2021-09-23T02:52:11.293140Z info FLAG: --domain="default.svc.cluster.local"
2021-09-23T02:52:11.293145Z info FLAG: --help="false"
2021-09-23T02:52:11.293148Z info FLAG: --log_as_json="false"
2021-09-23T02:52:11.293150Z info FLAG: --log_caller=""
2021-09-23T02:52:11.293152Z info FLAG: --log_output_level="default:info"
2021-09-23T02:52:11.293155Z info FLAG: --log_rotate=""
2021-09-23T02:52:11.293157Z info FLAG: --log_rotate_max_age="30"
2021-09-23T02:52:11.293159Z info FLAG: --log_rotate_max_backups="1000"
2021-09-23T02:52:11.293162Z info FLAG: --log_rotate_max_size="104857600"
2021-09-23T02:52:11.293164Z info FLAG: --log_stacktrace_level="default:none"
2021-09-23T02:52:11.293169Z info FLAG: --log_target="[stdout]"
2021-09-23T02:52:11.293172Z info FLAG: --meshConfig="./etc/istio/config/mesh"
2021-09-23T02:52:11.293174Z info FLAG: --outlierLogPath=""
2021-09-23T02:52:11.293176Z info FLAG: --proxyComponentLogLevel="misc:error"
2021-09-23T02:52:11.293178Z info FLAG: --proxyLogLevel="warning"
2021-09-23T02:52:11.293181Z info FLAG: --serviceCluster="productpage.default"
2021-09-23T02:52:11.293183Z info FLAG: --stsPort="0"
2021-09-23T02:52:11.293185Z info FLAG: --templateFile=""
2021-09-23T02:52:11.293188Z info FLAG: --tokenManagerPlugin="GoogleTokenExchange"
2021-09-23T02:52:11.293205Z info Version 1.8.2-bfa8bcbc116a8736c301a5dfedc4ed2673e2bfa3-Clean
2021-09-23T02:52:11.293531Z info Obtained private IP [10.244.1.11 fe80::b4d3:afff:fea9:1988]
2021-09-23T02:52:11.293618Z info Apply proxy config from env {"proxyMetadata":{"DNS_AGENT":""}}
2021-09-23T02:52:11.295330Z info Effective config: binaryPath: /usr/local/bin/envoy
concurrency: 2
configPath: ./etc/istio/proxy
controlPlaneAuthPolicy: MUTUAL_TLS
discoveryAddress: istiod.istio-system.svc:15012
drainDuration: 45s
envoyAccessLogService: {}
envoyMetricsService: {}
parentShutdownDuration: 60s
proxyAdminPort: 15000
proxyMetadata:
DNS_AGENT: ""
serviceCluster: productpage.default
statNameLength: 189
statusPort: 15020
terminationDrainDuration: 5s
tracing:
zipkin:
address: zipkin.istio-system:9411
2021-09-23T02:52:11.295396Z info Proxy role: &model.Proxy{RWMutex:sync.RWMutex{w:sync.Mutex{state:0, sema:0x0}, writerSem:0x0, readerSem:0x0, readerCount:0, readerWait:0}, Type:"sidecar", IPAddresses:[]string{"10.244.1.11", "fe80::b4d3:afff:fea9:1988"}, ID:"productpage-v1-65576bb7bf-rcnfr.default", Locality:(*envoy_config_core_v3.Locality)(nil), DNSDomain:"default.svc.cluster.local", ConfigNamespace:"", Metadata:(*model.NodeMetadata)(nil), SidecarScope:(*model.SidecarScope)(nil), PrevSidecarScope:(*model.SidecarScope)(nil), MergedGateway:(*model.MergedGateway)(nil), ServiceInstances:[]*model.ServiceInstance(nil), IstioVersion:(*model.IstioVersion)(nil), VerifiedIdentity:(*spiffe.Identity)(nil), ipv6Support:false, ipv4Support:false, GlobalUnicastIP:"", XdsResourceGenerator:model.XdsResourceGenerator(nil), WatchedResources:map[string]*model.WatchedResource(nil)}
2021-09-23T02:52:11.295414Z info JWT policy is third-party-jwt
2021-09-23T02:52:11.295442Z info PilotSAN []string{"istiod.istio-system.svc"}
2021-09-23T02:52:11.295495Z info sa.serverOptions.CAEndpoint == istiod.istio-system.svc:15012 Citadel
2021-09-23T02:52:11.295581Z info Using CA istiod.istio-system.svc:15012 cert with certs: var/run/secrets/istio/root-cert.pem
2021-09-23T02:52:11.295693Z info citadelclient Citadel client using custom root: istiod.istio-system.svc:15012 -----BEGIN CERTIFICATE-----
MIIC/TCCAeWgAwIBAgIRAOYOpkjwEDCsYkyLt1JY6rkwDQYJKoZIhvcNAQELBQAw
GDEWMBQGA1UEChMNY2x1c3Rlci5sb2NhbDAeFw0yMTA5MTAxMzUzMThaFw0zMTA5
MDgxMzUzMThaMBgxFjAUBgNVBAoTDWNsdXN0ZXIubG9jYWwwggEiMA0GCSqGSIb3
DQEBAQUAA4IBDwAwggEKAoIBAQC2B2ql/f3tZqnyLJ86NYtcpkMWux379jCl3sUb
0Lf3hqd2wD6VtnQpAuHO42PXacS56hiNJGwdkhU/Z8zlhFc58vGWeOShT5C8jLrC
z//9TjTsfvGUS4REjQ13O4QGQyHtYnjJZx47HJr7m4estVOLbaqmjMNkD1cpGpHR
3tv3LRMuqPQERx2RxVBIp5P1UD7kgyzWb2dOFzqmE5gYeCfoxc6E003rXyd5u4UU
C9D5lwGmSPICLKXFBgegrEd1A1JdmQKHC5urrykVpn70mwMZzAY2PHNc353CJdSD
Zk3dvMvc0/3KJdeXZijx4B8VgyTJyBrSdunJZGDh/N7gVDqTAgMBAAGjQjBAMA4G
A1UdDwEB/wQEAwICBDAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBRkc4FW0Drr
w/ux1836u3Wv1agGYTANBgkqhkiG9w0BAQsFAAOCAQEAVJkrYH8hvditinreypWI
+hNJBMGk5BeeYZGAAyRVCgmA2tuMIvy6Pd0O/VtM6CZDJq1ChHm/oHk9i3ScdMS7
2qCN9Jvgr9OQ/hehESqCDPwP81FqhpWK4d0P+8WGwpVuQF0WRZFa8RvAr8rWypz5
ouTB6yZJ5wdlH8FG51YRSCgeHQ3+VpeCF8/CLu5RghGYGgArATjf+zicegCvIemI
1p7NdrcfptXmhUkqiax7ePJuj4D1svrcKAJtIZJ+ocgNhwl/Uhb9Cz5l7TXUKqhN
56iNXtTfotqodlbAtgu033aMAdFny461CxuKyBi80mZq5OAE6AHRbndM0PcYWWHy
7A==
-----END CERTIFICATE-----
2021-09-23T02:52:11.334052Z info sds SDS gRPC server for workload UDS starts, listening on "./etc/istio/proxy/SDS"
2021-09-23T02:52:11.334321Z info xdsproxy Initializing with upstream address istiod.istio-system.svc:15012 and cluster Kubernetes
2021-09-23T02:52:11.334265Z info sds Start SDS grpc server
2021-09-23T02:52:11.334695Z info xdsproxy adding watcher for certificate var/run/secrets/istio/root-cert.pem
2021-09-23T02:52:11.334927Z info Starting proxy agent
2021-09-23T02:52:11.335076Z info Opening status port 15020
2021-09-23T02:52:11.335241Z info Received new config, creating new Envoy epoch 0
2021-09-23T02:52:11.335322Z info Epoch 0 starting
2021-09-23T02:52:11.343146Z info Envoy command: [-c etc/istio/proxy/envoy-rev0.json --restart-epoch 0 --drain-time-s 45 --parent-shutdown-time-s 60 --service-cluster productpage.default --service-node sidecar~10.244.1.11~productpage-v1-65576bb7bf-rcnfr.default~default.svc.cluster.local --local-address-ip-version v4 --bootstrap-version 3 --log-format-prefix-with-location 0 --log-format %Y-%m-%dT%T.%fZ %l envoy %n %v -l warning --component-log-level misc:error --concurrency 2]
2021-09-23T02:52:11.412475Z warning envoy runtime Unable to use runtime singleton for feature envoy.http.headermap.lazy_map_min_size
2021-09-23T02:52:11.412672Z warning envoy runtime Unable to use runtime singleton for feature envoy.http.headermap.lazy_map_min_size
2021-09-23T02:52:11.413442Z warning envoy runtime Unable to use runtime singleton for feature envoy.http.headermap.lazy_map_min_size
2021-09-23T02:52:11.413569Z warning envoy runtime Unable to use runtime singleton for feature envoy.http.headermap.lazy_map_min_size
2021-09-23T02:52:11.454710Z warning envoy main there is no configured limit to the number of allowed active connections. Set a limit via the runtime key overload.global_downstream_max_connections
2021-09-23T02:52:11.455704Z info xdsproxy Envoy ADS stream established
2021-09-23T02:52:11.455949Z info xdsproxy connecting to upstream XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:11.473271Z error xdsproxy failed to create upstream grpc client: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:11.473379Z info xdsproxy disconnected from XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:11.474501Z warning envoy config StreamAggregatedResources gRPC config stream closed: 14, connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:11.795970Z info xdsproxy Envoy ADS stream established
2021-09-23T02:52:11.796062Z info xdsproxy connecting to upstream XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:11.805039Z error xdsproxy failed to create upstream grpc client: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:11.805183Z info xdsproxy disconnected from XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:11.805472Z warning envoy config StreamAggregatedResources gRPC config stream closed: 14, connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:12.611766Z info xdsproxy Envoy ADS stream established
2021-09-23T02:52:12.611860Z info xdsproxy connecting to upstream XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:12.616565Z warning envoy config StreamAggregatedResources gRPC config stream closed: 14, connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:12.616339Z error xdsproxy failed to create upstream grpc client: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:12.616351Z info xdsproxy disconnected from XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:14.603617Z info xdsproxy Envoy ADS stream established
2021-09-23T02:52:14.604067Z info xdsproxy connecting to upstream XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:14.636949Z error xdsproxy failed to create upstream grpc client: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:14.636970Z info xdsproxy disconnected from XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:14.637360Z warning envoy config StreamAggregatedResources gRPC config stream closed: 14, connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:15.699301Z info xdsproxy Envoy ADS stream established
2021-09-23T02:52:15.699514Z info xdsproxy connecting to upstream XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:15.706515Z error xdsproxy failed to create upstream grpc client: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:15.706534Z info xdsproxy disconnected from XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:15.706709Z warning envoy config StreamAggregatedResources gRPC config stream closed: 14, connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:20.503604Z info xdsproxy Envoy ADS stream established
2021-09-23T02:52:20.503706Z info xdsproxy connecting to upstream XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:20.586429Z error xdsproxy failed to create upstream grpc client: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:20.586451Z info xdsproxy disconnected from XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:20.598527Z warning envoy config StreamAggregatedResources gRPC config stream closed: 14, connection error: desc = "transport: Error while dialing dial tcp: lookup istiod.istio-system.svc on 10.96.0.10:53: no such host"
2021-09-23T02:52:24.727314Z info xdsproxy Envoy ADS stream established
2021-09-23T02:52:24.727920Z info xdsproxy connecting to upstream XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:30.771217Z error xdsproxy failed to create upstream grpc client: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial tcp 10.96.68.72:15012: connect: connection refused"
2021-09-23T02:52:30.771238Z info xdsproxy disconnected from XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:30.774174Z warning envoy config StreamAggregatedResources gRPC config stream closed: 14, connection error: desc = "transport: Error while dialing dial tcp 10.96.68.72:15012: connect: connection refused"
2021-09-23T02:52:42.907758Z warn Envoy proxy is NOT ready: config not received from Pilot (is Pilot running?): cds updates: 0 successful, 0 rejected; lds updates: 0 successful, 0 rejected
2021-09-23T02:52:44.913337Z warn Envoy proxy is NOT ready: config not received from Pilot (is Pilot running?): cds updates: 0 successful, 0 rejected; lds updates: 0 successful, 0 rejected
2021-09-23T02:52:46.905358Z warn Envoy proxy is NOT ready: config not received from Pilot (is Pilot running?): cds updates: 0 successful, 0 rejected; lds updates: 0 successful, 0 rejected
2021-09-23T02:52:48.907121Z warn Envoy proxy is NOT ready: config not received from Pilot (is Pilot running?): cds updates: 0 successful, 0 rejected; lds updates: 0 successful, 0 rejected
2021-09-23T02:52:50.920121Z warn Envoy proxy is NOT ready: config not received from Pilot (is Pilot running?): cds updates: 0 successful, 0 rejected; lds updates: 0 successful, 0 rejected
2021-09-23T02:52:52.059419Z info xdsproxy Envoy ADS stream established
2021-09-23T02:52:52.059644Z info xdsproxy connecting to upstream XDS server: istiod.istio-system.svc:15012
2021-09-23T02:52:52.117894Z warning envoy filter mTLS PERMISSIVE mode is used, connection can be either plaintext or TLS, and client cert can be omitted. Please consider to upgrade to mTLS STRICT mode for more secure configuration that only allows TLS connection with client cert. See https://istio.io/docs/tasks/security/mtls-migration/
2021-09-23T02:52:52.119033Z warning envoy filter mTLS PERMISSIVE mode is used, connection can be either plaintext or TLS, and client cert can be omitted. Please consider to upgrade to mTLS STRICT mode for more secure configuration that only allows TLS connection with client cert. See https://istio.io/docs/tasks/security/mtls-migration/
2021-09-23T02:52:52.124293Z info sds resource:ROOTCA new connection
2021-09-23T02:52:52.124418Z info sds Skipping waiting for gateway secret
2021-09-23T02:52:52.125335Z info sds resource:default new connection
2021-09-23T02:52:52.125449Z info sds Skipping waiting for gateway secret
2021-09-23T02:52:52.192179Z info cache Root cert has changed, start rotating root cert for SDS clients
2021-09-23T02:52:52.192204Z info cache GenerateSecret default
2021-09-23T02:52:52.197381Z info sds resource:default pushed key/cert pair to proxy
2021-09-23T02:52:52.324549Z info cache Loaded root cert from certificate ROOTCA
2021-09-23T02:52:52.324858Z info sds resource:ROOTCA pushed root cert to proxy
2021-09-23T02:52:52.905575Z info Envoy proxy is ready
2021-09-23T03:24:59.695819Z info xdsproxy disconnected from XDS server: istiod.istio-system.svc:15012
2021-09-23T03:24:59.696566Z warning envoy config StreamAggregatedResources gRPC config stream closed: 0,
2021-09-23T03:25:00.014333Z info xdsproxy Envoy ADS stream established
2021-09-23T03:25:00.014561Z info xdsproxy connecting to upstream XDS server: istiod.istio-system.svc:15012
[2021-09-23T03:37:25.147Z] "GET /details/0 HTTP/1.1" 503 UF "-" 0 91 90 - "-" "curl/7.52.1" "507f4f72-c53d-999a-864b-71c67c722717" "details:9080" "10.244.2.5:9080" outbound|9080||global-sidecar.default.svc.cluster.local - 10.96.206.167:9080 10.244.1.11:46772 - -
[2021-09-23T03:37:25.265Z] "GET /reviews/0 HTTP/1.1" 503 UF "-" 0 91 0 - "-" "curl/7.52.1" "507f4f72-c53d-999a-864b-71c67c722717" "reviews:9080" "10.244.2.5:9080" outbound|9080||global-sidecar.default.svc.cluster.local - 10.96.27.89:9080 10.244.1.11:42392 - -
[2021-09-23T03:37:25.274Z] "GET /reviews/0 HTTP/1.1" 503 UF "-" 0 91 0 - "-" "curl/7.52.1" "507f4f72-c53d-999a-864b-71c67c722717" "reviews:9080" "10.244.2.5:9080" outbound|9080||global-sidecar.default.svc.cluster.local - 10.96.27.89:9080 10.244.1.11:42396 - -
[2021-09-23T03:37:25.062Z] "GET /productpage HTTP/1.1" 200 - "-" 0 3769 247 227 "-" "curl/7.52.1" "507f4f72-c53d-999a-864b-71c67c722717" "productpage:9080" "127.0.0.1:9080" inbound|9080|| 127.0.0.1:54786 10.244.1.11:9080 10.244.2.12:57852 outbound_.9080_._.productpage.default.svc.cluster.local default
应用容器
➜ ~ kubectl logs productpage-v1-65576bb7bf-rcnfr -c productpage
INFO:root:start at port 9080
* Serving Flask app "productpage" (lazy loading)
* Environment: production
WARNING: Do not use the development server in a production environment.
Use a production WSGI server instead.
* Debug mode: on
INFO:werkzeug: * Running on http://0.0.0.0:9080/ (Press CTRL+C to quit)
INFO:werkzeug: * Restarting with stat
INFO:root:start at port 9080
WARNING:werkzeug: * Debugger is active!
INFO:werkzeug: * Debugger PIN: 305-281-729
DEBUG:urllib3.connectionpool:Starting new HTTP connection (1): details:9080
send: b'GET /details/0 HTTP/1.1\r\nHost: details:9080\r\nuser-agent: curl/7.52.1\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\nX-B3-TraceId: 3864470a4495b8d10216068955349927\r\nX-B3-SpanId: b88111f1d827040a\r\nX-B3-ParentSpanId: 0216068955349927\r\nX-B3-Sampled: 1\r\nx-request-id: 507f4f72-c53d-999a-864b-71c67c722717\r\n\r\n'
reply: 'HTTP/1.1 503 Service Unavailable\r\n'
header: content-length: 91
header: content-type: text/plain
header: date: Thu, 23 Sep 2021 03:37:24 GMT
header: server: envoy
DEBUG:urllib3.connectionpool:http://details:9080 "GET /details/0 HTTP/1.1" 503 91
DEBUG:urllib3.connectionpool:Starting new HTTP connection (1): reviews:9080
send: b'GET /reviews/0 HTTP/1.1\r\nHost: reviews:9080\r\nuser-agent: curl/7.52.1\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\nX-B3-TraceId: 3864470a4495b8d10216068955349927\r\nX-B3-SpanId: b88111f1d827040a\r\nX-B3-ParentSpanId: 0216068955349927\r\nX-B3-Sampled: 1\r\nx-request-id: 507f4f72-c53d-999a-864b-71c67c722717\r\n\r\n'
reply: 'HTTP/1.1 503 Service Unavailable\r\n'
header: content-length: 91
header: content-type: text/plain
header: date: Thu, 23 Sep 2021 03:37:24 GMT
header: server: envoy
DEBUG:urllib3.connectionpool:http://reviews:9080 "GET /reviews/0 HTTP/1.1" 503 91
DEBUG:urllib3.connectionpool:Starting new HTTP connection (1): reviews:9080
send: b'GET /reviews/0 HTTP/1.1\r\nHost: reviews:9080\r\nuser-agent: curl/7.52.1\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\nX-B3-TraceId: 3864470a4495b8d10216068955349927\r\nX-B3-SpanId: b88111f1d827040a\r\nX-B3-ParentSpanId: 0216068955349927\r\nX-B3-Sampled: 1\r\nx-request-id: 507f4f72-c53d-999a-864b-71c67c722717\r\n\r\n'
reply: 'HTTP/1.1 503 Service Unavailable\r\n'
header: content-length: 91
header: content-type: text/plain
header: date: Thu, 23 Sep 2021 03:37:24 GMT
header: server: envoy
DEBUG:urllib3.connectionpool:http://reviews:9080 "GET /reviews/0 HTTP/1.1" 503 91
INFO:werkzeug:127.0.0.1 - - [23/Sep/2021 03:37:25] "GET /productpage HTTP/1.1" 200 -
istio-init
➜ ~ kubectl logs productpage-v1-65576bb7bf-rcnfr -c istio-init
Environment:
------------
ENVOY_PORT=
INBOUND_CAPTURE_PORT=
ISTIO_INBOUND_INTERCEPTION_MODE=
ISTIO_INBOUND_TPROXY_MARK=
ISTIO_INBOUND_TPROXY_ROUTE_TABLE=
ISTIO_INBOUND_PORTS=
ISTIO_OUTBOUND_PORTS=
ISTIO_LOCAL_EXCLUDE_PORTS=
ISTIO_SERVICE_CIDR=
ISTIO_SERVICE_EXCLUDE_CIDR=
Variables:
PROXY_PORT=15001
PROXY_INBOUND_CAPTURE_PORT=15006
PROXY_TUNNEL_PORT=15008
PROXY_UID=1337
PROXY_GID=1337
INBOUND_INTERCEPTION_MODE=REDIRECT
INBOUND_TPROXY_MARK=1337
INBOUND_TPROXY_ROUTE_TABLE=133
INBOUND_PORTS_INCLUDE=*
INBOUND_PORTS_EXCLUDE=15090,15021,15020
OUTBOUND_IP_RANGES_INCLUDE=*
OUTBOUND_IP_RANGES_EXCLUDE=
OUTBOUND_PORTS_INCLUDE=
OUTBOUND_PORTS_EXCLUDE=
KUBEVIRT_INTERFACES=
ENABLE_INBOUND_IPV6=false
Writing following contents to rules file: /tmp/iptables-rules-1632365525899234396.txt110258964
* nat
-N ISTIO_INBOUND
-N ISTIO_REDIRECT
-N ISTIO_IN_REDIRECT
-N ISTIO_OUTPUT
-A ISTIO_INBOUND -p tcp --dport 15008 -j RETURN
-A ISTIO_REDIRECT -p tcp -j REDIRECT --to-ports 15001
-A ISTIO_IN_REDIRECT -p tcp -j REDIRECT --to-ports 15006
-A PREROUTING -p tcp -j ISTIO_INBOUND
-A ISTIO_INBOUND -p tcp --dport 22 -j RETURN
-A ISTIO_INBOUND -p tcp --dport 15090 -j RETURN
-A ISTIO_INBOUND -p tcp --dport 15021 -j RETURN
-A ISTIO_INBOUND -p tcp --dport 15020 -j RETURN
-A ISTIO_INBOUND -p tcp -j ISTIO_IN_REDIRECT
-A OUTPUT -p tcp -j ISTIO_OUTPUT
-A ISTIO_OUTPUT -o lo -s 127.0.0.6/32 -j RETURN
-A ISTIO_OUTPUT -o lo ! -d 127.0.0.1/32 -m owner --uid-owner 1337 -j ISTIO_IN_REDIRECT
-A ISTIO_OUTPUT -o lo -m owner ! --uid-owner 1337 -j RETURN
-A ISTIO_OUTPUT -m owner --uid-owner 1337 -j RETURN
-A ISTIO_OUTPUT -o lo ! -d 127.0.0.1/32 -m owner --gid-owner 1337 -j ISTIO_IN_REDIRECT
-A ISTIO_OUTPUT -o lo -m owner ! --gid-owner 1337 -j RETURN
-A ISTIO_OUTPUT -m owner --gid-owner 1337 -j RETURN
-A ISTIO_OUTPUT -d 127.0.0.1/32 -j RETURN
-A ISTIO_OUTPUT -j ISTIO_REDIRECT
COMMIT
iptables-restore --noflush /tmp/iptables-rules-1632365525899234396.txt110258964
Writing following contents to rules file: /tmp/ip6tables-rules-1632365526282819021.txt568430947
ip6tables-restore --noflush /tmp/ip6tables-rules-1632365526282819021.txt568430947
iptables-save
Generated by iptables-save v1.6.1 on Thu Sep 23 02:52:06 2021
*nat
:PREROUTING ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
:ISTIO_INBOUND - [0:0]
:ISTIO_IN_REDIRECT - [0:0]
:ISTIO_OUTPUT - [0:0]
:ISTIO_REDIRECT - [0:0]
-A PREROUTING -p tcp -j ISTIO_INBOUND
-A OUTPUT -p tcp -j ISTIO_OUTPUT
-A ISTIO_INBOUND -p tcp -m tcp --dport 15008 -j RETURN
-A ISTIO_INBOUND -p tcp -m tcp --dport 22 -j RETURN
-A ISTIO_INBOUND -p tcp -m tcp --dport 15090 -j RETURN
-A ISTIO_INBOUND -p tcp -m tcp --dport 15021 -j RETURN
-A ISTIO_INBOUND -p tcp -m tcp --dport 15020 -j RETURN
-A ISTIO_INBOUND -p tcp -j ISTIO_IN_REDIRECT
-A ISTIO_IN_REDIRECT -p tcp -j REDIRECT --to-ports 15006
-A ISTIO_OUTPUT -s 127.0.0.6/32 -o lo -j RETURN
-A ISTIO_OUTPUT ! -d 127.0.0.1/32 -o lo -m owner --uid-owner 1337 -j ISTIO_IN_REDIRECT
-A ISTIO_OUTPUT -o lo -m owner ! --uid-owner 1337 -j RETURN
-A ISTIO_OUTPUT -m owner --uid-owner 1337 -j RETURN
-A ISTIO_OUTPUT ! -d 127.0.0.1/32 -o lo -m owner --gid-owner 1337 -j ISTIO_IN_REDIRECT
-A ISTIO_OUTPUT -o lo -m owner ! --gid-owner 1337 -j RETURN
-A ISTIO_OUTPUT -m owner --gid-owner 1337 -j RETURN
-A ISTIO_OUTPUT -d 127.0.0.1/32 -j RETURN
-A ISTIO_OUTPUT -j ISTIO_REDIRECT
-A ISTIO_REDIRECT -p tcp -j REDIRECT --to-ports 15001
COMMIT
#Completed on Thu Sep 23 02:52:06 2021
➜ ~