-
Notifications
You must be signed in to change notification settings - Fork 441
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[BUG] Performance about NetworkPolicy #4349
Comments
|
1、The first log shows that there's sth wrong with the netpol vm/np-net-xxxxx. Is it possible to provide the content about netpol vm/np-net-xxxxx? |
- apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: np-net-SUBNET-A
namespace: vm
spec:
egress:
- to:
- podSelector:
matchLabels:
net-SUBNET-A: "1"
podSelector:
matchLabels:
net-SUBNET-A: "1"
policyTypes:
- Egress |
head 400 lines here
|
Thanks for the information. I will have a test in my environment. |
I tried to use SecurityGroup to replace NetworkPolicy That's another problem, just a side note. |
The logs still looks confusing. Are you in the WeChat group? We can communicate the issue directly. To join the WeChat group, you can visit https://kubeovn.github.io/docs/stable |
Kube-OVN Version
v1.12.19
Kubernetes Version
v1.27.4
Operation-system/Kernel Version
TencentOS Server 4.0
6.6.6-2401.0.1.tl4.4.x86_64
Description
I have a cluster with 4 nodes, ~100 subnets, ~200 pods. I've found that my pods often take more than 10 minutes to obtain a DHCP lease. Therefore, I've been debugging this issue.
My
kube-ovn-controller.log
looks like:My dashboard "Work Queue Depth" is look like this
So I think my problem is about networkpolicy.
I have ~100 network policies, one is special:
Others(>=100) look like this, to make pods in the same subnet can connect to each other:
This seems to indicate that there are some performance issues with the NetworkPolicy under this configuration. I haven't confirmed this yet, nor have I constructed a minimal reproduction environment.
I'm attempting to use
SecurityGroup
as a replacement, hoping this could help.Steps To Reproduce
/
Current Behavior
/
Expected Behavior
/
The text was updated successfully, but these errors were encountered: