0

I have an AKS cluster 1.29.2 with calico network policy. I have an egress network policy that should allow outbound traffic on internet but block all traffic in RFC_1918 range.

apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: egress-allow namespace: production spec: egress: - ports: - port: 53 protocol: UDP to: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: kube-system podSelector: matchLabels: k8s-app: kube-dns - to: - ipBlock: cidr: 0.0.0.0/0 except: - 172.16.0.0/12 - 10.0.0.0/8 - 192.168.0.0/16 podSelector: matchLabels: app.kubernetes.io/name: prodbindms policyTypes: - Egress 

But when I am trying to connect to a svc ip of another microservice in same cluster in the same RFC_1918 range (nc -vz 172.20.217.17 8080) from prodbindms pod, it's able to connect. As soon as I remove the whole ipBlock, the connection fails but then I cant connect to any public ip as well. Basically all egress except connectivity to kube-dns starts failing.

It looks like the except in ipBlock isnt working at all. I have tried all possibilities but couldnt make this work. The same networkpolicy works fine on AWS EKS cluster. What could be the reason for this not working on Azure AKS.

AKS show details: az aks show: "networkMode": null, "networkPlugin": "kubenet", "networkPluginMode": null, "networkPolicy": "calico",

1 Answer 1

0

You could back out the recent cumulative update. Or try the suggested registry value.

"After installing this update, container networking on Kubernetes might not operate as expected, preventing containers from reaching external networks or communicating between pods. It potentially impacts users setting up container networking on dev or production instances using Calico on Server 2022. Affected containers will not connect to the internet, and traffic will be blocked in host devices Firewall."

https://support.microsoft.com/en-us/topic/september-10-2024-kb5042881-os-build-20348-2700-5b548143-9613-4e5a-9454-8ed9be8b2bd2

You must log in to answer this question.

Start asking to get answers

Find the answer to your question by asking.

Ask question

Explore related questions

See similar questions with these tags.