Skip to content

Conversation

giorio94
Copy link
Member

Please review commit by commit, and refer to the individual messages for additional details.

The manifest appears to have been introduced in 46f3918 ("connectivity:
Add Port Range Tests"), but has never been actually used. Hence, let's get
rid of it.

Signed-off-by: Marco Iorio <marco.iorio@isovalent.com>
Multiple policies leveraged by the connectivity tests depend on DNS
introspection to support toFQDN rules. However, they are currently
not particularly consistent, each configuring the allowed DNS servers
in slightly different ways. Let's consolidate the configuration in
a single policy, which is then applied alongside all the others, to
ensure consistency and guarantee that modifications apply to all.

Signed-off-by: Marco Iorio <marco.iorio@isovalent.com>
Modify the DNS policies to specify a cluster selector to allow targeting
DNS servers in the local cluster only, matching best practices.

Signed-off-by: Marco Iorio <marco.iorio@isovalent.com>
@giorio94 giorio94 added kind/cleanup This includes no functional changes. release-note/misc This PR makes changes that have no direct user impact. cilium-cli This PR contains changes related with cilium-cli labels Nov 26, 2024
@github-actions github-actions bot added the cilium-cli-exclusive This PR only impacts cilium-cli binary label Nov 26, 2024
It appears to be currently owned by the clustermesh team, even if it is
not clustermesh related. Let's assign it to the fqdn team, given that
it configures DNS interception.

Signed-off-by: Marco Iorio <marco.iorio@isovalent.com>
@giorio94
Copy link
Member Author

/test

@giorio94 giorio94 marked this pull request as ready for review November 27, 2024 09:06
@giorio94 giorio94 requested review from a team as code owners November 27, 2024 09:06
Copy link
Member

@pippolo84 pippolo84 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks! 💯

@maintainer-s-little-helper maintainer-s-little-helper bot added the ready-to-merge This PR has passed all tests and received consensus from code owners to merge. label Nov 27, 2024
Copy link
Member

@gandro gandro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ACK for FQDN

@tklauser tklauser added this pull request to the merge queue Nov 27, 2024
Merged via the queue into cilium:main with commit 176c55d Nov 27, 2024
78 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cilium-cli This PR contains changes related with cilium-cli cilium-cli-exclusive This PR only impacts cilium-cli binary kind/cleanup This includes no functional changes. ready-to-merge This PR has passed all tests and received consensus from code owners to merge. release-note/misc This PR makes changes that have no direct user impact.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants