 Cilium v1.9 Documentationsource host. For east-west type load balancing, Cilium performs efficient service-to-backend translation right in the Linux kernel’s socket layer (e.g. at TCP connect time) such that per-packet NAT operations For kernels older than v5.8 such reverse translation is not taking place for this system call. For the vast majority of applications not having this translation at getpeername(2) does not cause any issues from the backend need to make the extra hop back that node in order to perform the reverse SNAT translation there before returning the packet directly to the external client. This setting can be changed0 码力 | 1263 页 | 18.62 MB | 1 年前3 Cilium v1.9 Documentationsource host. For east-west type load balancing, Cilium performs efficient service-to-backend translation right in the Linux kernel’s socket layer (e.g. at TCP connect time) such that per-packet NAT operations For kernels older than v5.8 such reverse translation is not taking place for this system call. For the vast majority of applications not having this translation at getpeername(2) does not cause any issues from the backend need to make the extra hop back that node in order to perform the reverse SNAT translation there before returning the packet directly to the external client. This setting can be changed0 码力 | 1263 页 | 18.62 MB | 1 年前3
 Cilium v1.10 Documentationsource host. For east-west type load balancing, Cilium performs efficient service-to-backend translation right in the Linux kernel’s socket layer (e.g. at TCP connect time) such that per-packet NAT operations For kernels older than v5.8 such reverse translation is not taking place for this system call. For the vast majority of applications not having this translation at getpeername(2) does not cause any issues from the backend need to make the extra hop back that node in order to perform the reverse SNAT translation there before returning the packet directly to the external client. This setting can be changed0 码力 | 1307 页 | 19.26 MB | 1 年前3 Cilium v1.10 Documentationsource host. For east-west type load balancing, Cilium performs efficient service-to-backend translation right in the Linux kernel’s socket layer (e.g. at TCP connect time) such that per-packet NAT operations For kernels older than v5.8 such reverse translation is not taking place for this system call. For the vast majority of applications not having this translation at getpeername(2) does not cause any issues from the backend need to make the extra hop back that node in order to perform the reverse SNAT translation there before returning the packet directly to the external client. This setting can be changed0 码力 | 1307 页 | 19.26 MB | 1 年前3
 Cilium v1.11 Documentationsource host. For east-west type load balancing, Cilium performs efficient service-to-backend translation right in the Linux kernel’s socket layer (e.g. at TCP connect time) such that per-packet NAT operations For kernels older than v5.8 such reverse translation is not taking place for this system call. For the vast majority of applications not having this translation at getpeername(2) does not cause any issues from the backend need to make the extra hop back that node in order to perform the reverse SNAT translation there before returning the packet directly to the external client. This setting can be changed0 码力 | 1373 页 | 19.37 MB | 1 年前3 Cilium v1.11 Documentationsource host. For east-west type load balancing, Cilium performs efficient service-to-backend translation right in the Linux kernel’s socket layer (e.g. at TCP connect time) such that per-packet NAT operations For kernels older than v5.8 such reverse translation is not taking place for this system call. For the vast majority of applications not having this translation at getpeername(2) does not cause any issues from the backend need to make the extra hop back that node in order to perform the reverse SNAT translation there before returning the packet directly to the external client. This setting can be changed0 码力 | 1373 页 | 19.37 MB | 1 年前3
 Cilium v1.8 DocumentationFor kernels older than v5.8 such reverse translation is not taking place for this system call. For the vast majority of applications not having this translation at getpeername(2) does not cause any issues from the backend need to make the extra hop back that node in order to perform the reverse SNAT translation there before returning the packet directly to the external client. This setting can be changed case. For example, if the kernel does not support Host-Reachable Services, then the ClusterIP translation for the node’s host- namespace is done through kube-proxy’s iptables rules. Also, the Cilium agent0 码力 | 1124 页 | 21.33 MB | 1 年前3 Cilium v1.8 DocumentationFor kernels older than v5.8 such reverse translation is not taking place for this system call. For the vast majority of applications not having this translation at getpeername(2) does not cause any issues from the backend need to make the extra hop back that node in order to perform the reverse SNAT translation there before returning the packet directly to the external client. This setting can be changed case. For example, if the kernel does not support Host-Reachable Services, then the ClusterIP translation for the node’s host- namespace is done through kube-proxy’s iptables rules. Also, the Cilium agent0 码力 | 1124 页 | 21.33 MB | 1 年前3
 Cilium v1.7 Documentationfrom the backend need to make the extra hop back that node in order to perform the reverse SNAT translation there before returning the packet directly to the external client. This setting can be changed case. For example, if the kernel does not support Host-Reachable Services, then the ClusterIP translation for the node’s host-namespace is done through kube-proxy’s iptables rules. global.kubeProxyReplacement=partial: upon the Host-Reachable Services feature which uses BPF cgroup hooks to implement the service translation. The getpeername(2) hook is currently missing which will be addressed for newer kernels. It is0 码力 | 885 页 | 12.41 MB | 1 年前3 Cilium v1.7 Documentationfrom the backend need to make the extra hop back that node in order to perform the reverse SNAT translation there before returning the packet directly to the external client. This setting can be changed case. For example, if the kernel does not support Host-Reachable Services, then the ClusterIP translation for the node’s host-namespace is done through kube-proxy’s iptables rules. global.kubeProxyReplacement=partial: upon the Host-Reachable Services feature which uses BPF cgroup hooks to implement the service translation. The getpeername(2) hook is currently missing which will be addressed for newer kernels. It is0 码力 | 885 页 | 12.41 MB | 1 年前3
 Cilium v1.6 Documentationsecurity identities from the key-value store, and status of deleted nodes from CiliumNetworkPolicy Translation of toGroups policy Interaction with the AWS API for managing AWS ENI Terminology Labels Labels (group of containers). This ensures simplicity in architecture, avoids unnecessary network address translation (NAT) and provides each individual container with a full range of port numbers to use. The logical shortest possible opcodes for a given instruction to shrink the total necessary size for the program translation. Hardening BPF locks the entire BPF interpreter image (struct bpf_prog) as well as the JIT compiled0 码力 | 734 页 | 11.45 MB | 1 年前3 Cilium v1.6 Documentationsecurity identities from the key-value store, and status of deleted nodes from CiliumNetworkPolicy Translation of toGroups policy Interaction with the AWS API for managing AWS ENI Terminology Labels Labels (group of containers). This ensures simplicity in architecture, avoids unnecessary network address translation (NAT) and provides each individual container with a full range of port numbers to use. The logical shortest possible opcodes for a given instruction to shrink the total necessary size for the program translation. Hardening BPF locks the entire BPF interpreter image (struct bpf_prog) as well as the JIT compiled0 码力 | 734 页 | 11.45 MB | 1 年前3
 Cilium v1.5 Documentationhelp for update --id uint Identifier --rev Add reverse translation (default true) Options inherited from parent commands --config string config file (default0 码力 | 740 页 | 12.52 MB | 1 年前3 Cilium v1.5 Documentationhelp for update --id uint Identifier --rev Add reverse translation (default true) Options inherited from parent commands --config string config file (default0 码力 | 740 页 | 12.52 MB | 1 年前3
共 7 条
- 1














