https://github.com/cilium/cilium
- HEAD
- refs/heads/1.2.7-hotfix1-fqdn-regen
- refs/heads/EndpointPolicyEnformcement
- refs/heads/all-scalability-improvements
- refs/heads/beta/service-mesh
- refs/heads/bpf-metrics
- refs/heads/brb/brb-patch-2
- refs/heads/cilium-envoy-crd-pre-beta
- refs/heads/cilium-no-gopath
- refs/heads/cli-upgrade-v1.12-ci-test
- refs/heads/clustermesh511-upgrade-test
- refs/heads/committers-codeowners
- refs/heads/debug
- refs/heads/dev/joe/v1.8-with-hostfw-fixes
- refs/heads/enable_cnp_latency
- refs/heads/encrypt-node-fixes
- refs/heads/ensure-macos-build-succeeds
- refs/heads/envoy-policy-precedence
- refs/heads/envoy-warnings-cleanup
- refs/heads/extension-mysql
- refs/heads/feature/cep-scalability
- refs/heads/feature/devices-and-addresses
- refs/heads/feature/devices-reconciliation-v1.16
- refs/heads/feature/main/svc-icmp-response
- refs/heads/feature/service-refactor
- refs/heads/feature/service-refactor-fresh
- refs/heads/feature/v1.11/beta-test
- refs/heads/feature/v1.11/k8s-ingress
- refs/heads/fix-iphealth
- refs/heads/fqdn-fixl3-wildcard
- refs/heads/fristonio/iptables-manager-fix
- refs/heads/ft/main/chancez/push-dev-charts
- refs/heads/ft/main/push_chart_stable_branches_fix
- refs/heads/ft/main/test_push_chart_updates
- refs/heads/gce-example
- refs/heads/gh-readonly-queue/main/pr-27509-78a5f177693fb443cd946441f45826bf7fa2437a
- refs/heads/ginkgo-better-timeout
- refs/heads/graduation
- refs/heads/hf/main/ipam-pools-build-230605
- refs/heads/hf/master/v1.12-rc2-health-dbg-v1
- refs/heads/hf/master/wg-fix-ipam-k8s-v2
- refs/heads/hf/v1.10/cls-prio2
- refs/heads/hf/v1.10/debug-taint-removal
- refs/heads/hf/v1.10/v1.10.10-with-19452
- refs/heads/hf/v1.10/v1.10.2-fix-ipsec-ep-routes
- refs/heads/hf/v1.10/v1.10.5-with-identity-leak-fix
- refs/heads/hf/v1.10/v1.10.7-additional-logs
- refs/heads/hf/v1.10/v1.10.7-exclude-local
- refs/heads/hf/v1.10/v1.10.7-exclude-loopback
- refs/heads/hf/v1.10/v1.10.7-extra-logs
- refs/heads/hf/v1.10/v1.10.7-more-logs
- refs/heads/hf/v1.10/v1.10.8-deadlock-and-complexity-fix
- refs/heads/hf/v1.10/v1.10.8-deadlock-fix
- refs/heads/hf/v1.10/xdp-multidev-with-bpf-multihoming-and-egress-gw-fixes-v3
- refs/heads/hf/v1.10/xdp-multidev-with-bpf-multihoming-and-egress-gw-fixes-v4
- refs/heads/hf/v1.10/xdp-multidev-with-bpf-multihoming-and-egress-gw-fixes-v5
- refs/heads/hf/v1.10/xdp-multidev-with-bpf-multihoming-and-egress-gw-fixes-v6
- refs/heads/hf/v1.10/xdp-multidev-with-bpf-multihoming-and-egress-gw-fixes-v7
- refs/heads/hf/v1.11/1.11.4-custom-taint
- refs/heads/hf/v1.11/19247-custom-taint-key
- refs/heads/hf/v1.11/dbg-svc-restore
- refs/heads/hf/v1.11/v1.11.16-fix-xfrm-leak
- refs/heads/hf/v1.11/v1.11.16-fix-xfrm-leak-eni-attach-and-logging
- refs/heads/hf/v1.11/v1.11.16-fix-xfrm-leak-eni-attachment
- refs/heads/hf/v1.11/v1.11.3-with-19259
- refs/heads/hf/v1.11/v1.11.4-custom-taint
- refs/heads/hf/v1.11/v1.11.5-and-19247-eed5544
- refs/heads/hf/v1.11/xdp-multidev-v1
- refs/heads/hf/v1.11/xdp-multidev-v2-ipcache-fix
- refs/heads/hf/v1.12/next-net-v1
- refs/heads/hf/v1.12/v1.12.18-994
- refs/heads/hf/v1.12/v1.12.3-debug-k8s-heartbeat
- refs/heads/hf/v1.12/v1.12.3-debug-k8s-heartbeat-v2
- refs/heads/hf/v1.13/bpf-sock-l7-fix
- refs/heads/hf/v1.13/v1.13.12-without-deny-precedence
- refs/heads/hf/v1.13/v1.13.14-without-deny-precedence
- refs/heads/hf/v1.13/v1.13.14-without-deny-precedence-debug
- refs/heads/hf/v1.13/v1.13.14-without-deny-precedence-with-xfrm-fix
- refs/heads/hf/v1.13/v1.13.2-with-24875
- refs/heads/hf/v1.13/v1.13.3-with-26242
- refs/heads/hf/v1.14/cidr-identity-refcnt-fix
- refs/heads/hf/v1.14/v1.14-with-27327
- refs/heads/hf/v1.7/v1.7.15-with-neighbor-fix
- refs/heads/hf/v1.7/v1.7.15-with-neighbor-fix-2
- refs/heads/hf/v1.8/v1.8.13-with-19452
- refs/heads/hf/v1.8/v1.8.6-eni-cidr-fix-1
- refs/heads/hf/v1.8/v1.8.6-eni-cidr-fix-15303
- refs/heads/hf/v1.8/v1.8.7-with-fqdn-underscore-fix
- refs/heads/hf/v1.8/v1.8.8-eni-cidr-fix-1
- refs/heads/hf/v1.8/v1.8.8-with-encrypt-fixes
- refs/heads/hf/v1.9/v1.9.8-azure-ipam-fix
- refs/heads/hf/v1.9/v1.9.9-azure-pod-egress-fix
- refs/heads/images/runtime/20210830
- refs/heads/ipc-demo
- refs/heads/ktls-tx-only
- refs/heads/ktls-tx-only-v2
- refs/heads/ktls-tx-rx
- refs/heads/ktls-tx-rx-v2
- refs/heads/ktls-tx-rx-v3
- refs/heads/ktls-tx-rx-v4
- refs/heads/ktls-tx-rx-v5
- refs/heads/ldelossa/feat/bgp-control-plane
- refs/heads/ldelossa/segment-makefiles
- refs/heads/ldelossa/segment-makefiles-v2
- refs/heads/ldelossa/srv6-encap-fib
- refs/heads/lizrice/pr/cli-confusion
- refs/heads/main
- refs/heads/multi-stack-dev-vm
- refs/heads/pr/1-9-ci-test
- refs/heads/pr/aanm-update-k8s-conformance
- refs/heads/pr/aanm/bisect
- refs/heads/pr/aanm/test-31027
- refs/heads/pr/add-controller-identity
- refs/heads/pr/aditighag/lrp-skip-lb
- refs/heads/pr/asauber/link-local-as-host
- refs/heads/pr/asauber/max-ifindex-metric
- refs/heads/pr/avoid-ct-for-dsr
- refs/heads/pr/backend-state
- refs/heads/pr/bbb-cpy
- refs/heads/pr/bimmlerd/modularize-bandwidth-manager
- refs/heads/pr/bimmlerd/v1.12-backport-quay-org-from-env
- refs/heads/pr/bounded-loops
- refs/heads/pr/bpf-based-masquerading
- refs/heads/pr/bpf-edt-proxy
- refs/heads/pr/brb/arping-nexthop
- refs/heads/pr/brb/arping-via-gw
- refs/heads/pr/brb/auto-multi-dev-v2
- refs/heads/pr/brb/backport-1.8.5-nat-gc
- refs/heads/pr/brb/bpf-host-routing-wg
- refs/heads/pr/brb/bpf-lxc-no-redirect
- refs/heads/pr/brb/bpf-masq-no-socket-lb
- refs/heads/pr/brb/bpf-masq-veth
- refs/heads/pr/brb/bpf-multihoming
- refs/heads/pr/brb/cgroup-v2-test
- refs/heads/pr/brb/check-errors-in-logs
- refs/heads/pr/brb/check-wg
- refs/heads/pr/brb/ci
- refs/heads/pr/brb/ci-1111
- refs/heads/pr/brb/ci-2
- refs/heads/pr/brb/ci-4.19
- refs/heads/pr/brb/ci-arping-flake
- refs/heads/pr/brb/ci-bigtcp
- refs/heads/pr/brb/ci-bpf-netdev-without-egress
- refs/heads/pr/brb/ci-cleanup-svc
- refs/heads/pr/brb/ci-dbg-conformance-kind
- refs/heads/pr/brb/ci-dbg-external
- refs/heads/pr/brb/ci-dbg-flake-from-outside
- refs/heads/pr/brb/ci-demo
- refs/heads/pr/brb/ci-disable-ces-for-egress-gw
- refs/heads/pr/brb/ci-dp-disable-bpf-host-routing
- refs/heads/pr/brb/ci-dp-hubble-flows
- refs/heads/pr/brb/ci-dp-more-diversity
- refs/heads/pr/brb/ci-dp-v1.13
- refs/heads/pr/brb/ci-dp-v6
- refs/heads/pr/brb/ci-dp-verifier
- refs/heads/pr/brb/ci-e2e-enable-debug-ipsec
- refs/heads/pr/brb/ci-e2e-geneve-dsr
- refs/heads/pr/brb/ci-e2e-helm-mode-v1.13
- refs/heads/pr/brb/ci-e2e-lvh-retry
- refs/heads/pr/brb/ci-e2e-more-nodes
- refs/heads/pr/brb/ci-e2e-new-cli
- refs/heads/pr/brb/ci-e2e-nft
- refs/heads/pr/brb/ci-e2e-unsafe
- refs/heads/pr/brb/ci-e2e-unsafe-v2
- refs/heads/pr/brb/ci-e2e-upgrade-tests
- refs/heads/pr/brb/ci-e2e-upgrade-tests-ipsec
- refs/heads/pr/brb/ci-early-terminate-conn-disrupt
- refs/heads/pr/brb/ci-eks-ipsec-upgrade
- refs/heads/pr/brb/ci-encrypt-l7
- refs/heads/pr/brb/ci-fix-ip-masq-dry-run
- refs/heads/pr/brb/ci-ipsec-upgrade-fix
- refs/heads/pr/brb/ci-ipsec-upgrade-missed-tail-calls
- refs/heads/pr/brb/ci-ipsec-upgrade-v1.13
- refs/heads/pr/brb/ci-ipsec-upgrade-vol2
- refs/heads/pr/brb/ci-keep-missed-tail-calls
- refs/heads/pr/brb/ci-l7-nodeport
- refs/heads/pr/brb/ci-lvh-4.19
- refs/heads/pr/brb/ci-lvh-5.4
- refs/heads/pr/brb/ci-lvh-5.4-v2
- refs/heads/pr/brb/ci-lvh-bpf-next
- refs/heads/pr/brb/ci-no-self-hosted
- refs/heads/pr/brb/ci-pass-kernel-env
- refs/heads/pr/brb/ci-prepull-l4lb
- refs/heads/pr/brb/ci-refactor-svc-suite
- refs/heads/pr/brb/ci-rm-smoke-tests
- refs/heads/pr/brb/ci-sanity
- refs/heads/pr/brb/ci-test
- refs/heads/pr/brb/ci-test-2
- refs/heads/pr/brb/ci-test-k8s-vsn-swap
- refs/heads/pr/brb/ci-test-large-runners
- refs/heads/pr/brb/ci-uffff
- refs/heads/pr/brb/ci-upgrade-vol-2
- refs/heads/pr/brb/ci-upgrade-vol-3
- refs/heads/pr/brb/ci-wg-mtu
- refs/heads/pr/brb/ci-wg-mtu-vol2
- refs/heads/pr/brb/cilium-host-v6-from-ipam
- refs/heads/pr/brb/cli-bump-test
- refs/heads/pr/brb/datapath-loop-dbg
- refs/heads/pr/brb/dbg-ci
- refs/heads/pr/brb/dbg-conformance-gke
- refs/heads/pr/brb/dbg-master-np-vxlan-ipcache-ci
- refs/heads/pr/brb/debug-nodeport-bpf-flake
- refs/heads/pr/brb/do-not-derive-pod-cidrs-from-dev
- refs/heads/pr/brb/do-not-query-dev-for-arping
- refs/heads/pr/brb/docs-clarify-egress-gw-ip-addr-dp
- refs/heads/pr/brb/drop-notify
- refs/heads/pr/brb/dsr
- refs/heads/pr/brb/dsr-v2
- refs/heads/pr/brb/dualstack-ci
- refs/heads/pr/brb/enable-ipv6-per-endpoint-routes
- refs/heads/pr/brb/enable-route-mtu-cni
- refs/heads/pr/brb/fib-lookup-src
- refs/heads/pr/brb/fix-backend-id-u32
- refs/heads/pr/brb/fix-ci-dp-deprecation-warn
- refs/heads/pr/brb/fix-clang-vsn-regexp
- refs/heads/pr/brb/fix-egress-ip-16147
- refs/heads/pr/brb/fix-external-ip-dp
- refs/heads/pr/brb/fix-maglev-del
- refs/heads/pr/brb/fix-nodeport-hostnetns
- refs/heads/pr/brb/fix-stale-dsr
- refs/heads/pr/brb/fix-svc-backend-selection
- refs/heads/pr/brb/fix-third-host
- refs/heads/pr/brb/gh-action-cgr
- refs/heads/pr/brb/gh-action-lvh
- refs/heads/pr/brb/gh-install-cli-backup
- refs/heads/pr/brb/ginkgo-kpr-strict
- refs/heads/pr/brb/ginkgo-rm-update-tests
- refs/heads/pr/brb/go-crazy
- refs/heads/pr/brb/hubble-tcp-ack-seq-no
- refs/heads/pr/brb/improve-svc-restore
- refs/heads/pr/brb/istio-getsockopt
- refs/heads/pr/brb/it-cannot-be-truth
- refs/heads/pr/brb/kpr-svc-mesh
- refs/heads/pr/brb/kubeproxy-free-ci
- refs/heads/pr/brb/l7-np-bpf
- refs/heads/pr/brb/l7-rerevert
- refs/heads/pr/brb/lets-be-friends-with-ipsec
- refs/heads/pr/brb/lvh-kind-127
- refs/heads/pr/brb/lvh-kind-ipsec-upgrade
- refs/heads/pr/brb/meyskens/auth-ep-gc-locks
- refs/heads/pr/brb/multi-network
- refs/heads/pr/brb/no-cache-snat
- refs/heads/pr/brb/no-rev-nat-bpf-lxc-ingress
- refs/heads/pr/brb/node-id-per-fam
- refs/heads/pr/brb/nodeport-xlr-flag
- refs/heads/pr/brb/perf-wg
- refs/heads/pr/brb/pin-lvh
- refs/heads/pr/brb/push-ci-charts
- refs/heads/pr/brb/pwru
- refs/heads/pr/brb/rm-arping-l2-addr-check
- refs/heads/pr/brb/rm-no-redirect
- refs/heads/pr/brb/rm-np-deadcode
- refs/heads/pr/brb/rm-partial-host-svc
- refs/heads/pr/brb/rm-test-gke
- refs/heads/pr/brb/test-bpf-masq
- refs/heads/pr/brb/test-ci-e2e
- refs/heads/pr/brb/test-ci-e2e-v1.13
- refs/heads/pr/brb/test-kind
- refs/heads/pr/brb/third-host-more-pain
- refs/heads/pr/brb/timing-l4lb-gh-action
- refs/heads/pr/brb/triage-flake-v2
- refs/heads/pr/brb/triage-lb-flake
- refs/heads/pr/brb/unquarantine-svc
- refs/heads/pr/brb/v1.10-istio-snat
- refs/heads/pr/brb/v1.12-ci-e2e
- refs/heads/pr/brb/v1.12-ci-ipsec-upgrade
- refs/heads/pr/brb/v1.12-test-ipsec-upgrade
- refs/heads/pr/brb/v1.13-ci-e2e
- refs/heads/pr/brb/v1.13-remote-np
- refs/heads/pr/brb/v1.13-upgrade-fixes
- refs/heads/pr/brb/v1.14-ci-e2e-upgrade
- refs/heads/pr/brb/v1.14-drop-notify
- refs/heads/pr/brb/v1.15-enable-route-mtu-cni
- refs/heads/pr/brb/v1.6.9-iptables-W
- refs/heads/pr/brb/v1.8-fix-icmp-port-check
- refs/heads/pr/brb/wg-duplicate-node-ip
- refs/heads/pr/brb/wg-encrypt-node-test
- refs/heads/pr/brb/wg-hack
- refs/heads/pr/brb/wg-ipam-fix
- refs/heads/pr/brb/wg-kpr
- refs/heads/pr/brb/wg-test
- refs/heads/pr/brb/wip
- refs/heads/pr/brb/wip-ci
- refs/heads/pr/brb/wip-sync-policy-map
- refs/heads/pr/brb/xdp-egress-gw
- refs/heads/pr/brb/xdp-multidev-with-bpf-multihoming
- refs/heads/pr/brb/xdp-multidev-with-bpf-multihoming-v2
- refs/heads/pr/bruno/sleepy-pawn
- refs/heads/pr/bugtool-systemd
- refs/heads/pr/bwm-base2
- refs/heads/pr/bwm-fq
- refs/heads/pr/bwm-priority
- refs/heads/pr/chancez/add_hubble_l7_dashboard_prometheus_example
- refs/heads/pr/chancez/fix_websocket_l7_policies
- refs/heads/pr/chancez/flow_filter_namespace
- refs/heads/pr/chancez/hubble_metrics_tls_docs
- refs/heads/pr/chancez/hubble_plus_plus
- refs/heads/pr/chancez/static_peers_hubble_relay
- refs/heads/pr/christarazi/controlplane-fqdn
- refs/heads/pr/christarazi/ipcache-async-cep-pods-namedports
- refs/heads/pr/christarazi/prep-from-cidr-tests
- refs/heads/pr/ci-k8s-1.30
- refs/heads/pr/datapath-opt
- refs/heads/pr/dbkm/nodeport-lb
- refs/heads/pr/debug-dns-timeout
- refs/heads/pr/eproutes-redir
- refs/heads/pr/example/neigh-state-manager
- refs/heads/pr/fastdp
- refs/heads/pr/fastdp2
- refs/heads/pr/feroz/allow-sbom-read
- refs/heads/pr/feroz/set-container-scan-failure-flag
- refs/heads/pr/fib-consolidation
- refs/heads/pr/fix-aks-workflow
- refs/heads/pr/fix-k8s-all-sha1
- refs/heads/pr/fix-net-next-1.16
- refs/heads/pr/fix-pod-pacing
- refs/heads/pr/fix-tail-call-replace
- refs/heads/pr/fristonio/feat-19038
- refs/heads/pr/fristonio/fix-istio-k8sT
- refs/heads/pr/fristonio/ipv6-masquerading
- refs/heads/pr/fristonio/test-dual-stack
- refs/heads/pr/fristonio/test-ipv6-dualstack
- refs/heads/pr/gandro+brb/fix-monitor-aggregation-np-v2
- refs/heads/pr/gandro+brb/mv-trace-point-to-rev-nodeport
- refs/heads/pr/gandro+brb/wg-host-encryption-v3
- refs/heads/pr/gandro+brb/wg-host2host
- refs/heads/pr/gandro+brb/wg-host2host-kind
- refs/heads/pr/gandro/bump-hubble-2020-03-25
- refs/heads/pr/gandro/ci-conformance-multicluster-fix-log-gathering
- refs/heads/pr/gandro/ci-delete-crds-in-cleanupcomponents
- refs/heads/pr/gandro/ci-fix-status-if-workflows-are-skipped
- refs/heads/pr/gandro/ci-wait-for-all-relevant-images-do-not-merge-test
- refs/heads/pr/gandro/enable-hubble-by-default
- refs/heads/pr/gandro/portmap-refcount
- refs/heads/pr/gandro/re-enable-wireguard-in-multicluster-ci
- refs/heads/pr/gandro/svc-healthchecknodeport
- refs/heads/pr/gc-on-svc-update
- refs/heads/pr/getname-hooks
- refs/heads/pr/giorio94/1.14/test-cilium-cli-2184
- refs/heads/pr/giorio94/main/cluster-name-validation-strict
- refs/heads/pr/giorio94/main/clustermesh-deprecated-cleanup
- refs/heads/pr/giorio94/main/gha-cl2-agents-pprof
- refs/heads/pr/giorio94/main/gha-cl2-compress-agent-pprofs
- refs/heads/pr/giorio94/main/gha-cluster-name
- refs/heads/pr/giorio94/main/gha-conformance-clustermesh-lb
- refs/heads/pr/giorio94/main/test-cilium-cli-2184
- refs/heads/pr/giorio94/main/tests-clustermesh-upgrade-interrupted
- refs/heads/pr/gray/30837-with-pwru
- refs/heads/pr/gray/main/connectivity-wg-proxy-nodeport
- refs/heads/pr/gray/main/decouple-ipsec-gh-actions
- refs/heads/pr/gray/main/egress-proxy-ipsec-fix2
- refs/heads/pr/gray/main/fix-leak-detection-race
- refs/heads/pr/gray/main/xfrm-delete-flake
- refs/heads/pr/gray/main/xfrm-delete-flake2
- refs/heads/pr/gray/pwru-action
- refs/heads/pr/gray/v1.15/decouple-ipsec-gh-actions
- refs/heads/pr/health
- refs/heads/pr/health-data-path
- refs/heads/pr/hubble-tls-cert-gen-via-k8s-job
- refs/heads/pr/ianvernon/kvstore-client-type
- refs/heads/pr/ianvernon/kvstore-context
- refs/heads/pr/ianvernon/more-endpoint-cleanup
- refs/heads/pr/ianvernon/resolve-cidr-policy-perf-improvement
- refs/heads/pr/increase-verifier-test-build-timeout
- refs/heads/pr/ipip
- refs/heads/pr/ipip-encap
- refs/heads/pr/ipip-encap2
- refs/heads/pr/ipip2
- refs/heads/pr/ipip4
- refs/heads/pr/ipip6
- refs/heads/pr/jibi/differentiate-udp-tcp-svcs-take-4
- refs/heads/pr/jibi/fix-differentiate-udp-tcp-svc-upgrade
- refs/heads/pr/jibi/ip-list-contains-addr
- refs/heads/pr/joamaki/gather-network-info
- refs/heads/pr/joamaki/idless-service-restapi
- refs/heads/pr/joe/ariane-scheduled-cilium-only
- refs/heads/pr/joe/backport-28007-1.11
- refs/heads/pr/joe/bump-ginkgo-seed
- refs/heads/pr/joe/docker-build-log-tracing
- refs/heads/pr/joe/ipcache-cidr-policy
- refs/heads/pr/joe/lost-identity
- refs/heads/pr/joe/policymap-format-test
- refs/heads/pr/joe/ready-to-merge
- refs/heads/pr/joe/release-codeowners
- refs/heads/pr/joe/sw-quay
- refs/heads/pr/joe/test-labeler
- refs/heads/pr/joe/test-lvh-fix
- refs/heads/pr/joe/v1.13-stability-check
- refs/heads/pr/joe/v1.7-dev-env
- refs/heads/pr/jrajahalme/gh-filter-test-files
- refs/heads/pr/jrfastab/backport-ooo-ipsec-fixes
- refs/heads/pr/jrfastab/backport-v111-loopback
- refs/heads/pr/jrfastab/backport-v115
- refs/heads/pr/jrfastab/dbgNodeId
- refs/heads/pr/jrfastab/dbgNodeId111
- refs/heads/pr/jrfastab/dbgNodeId111v2
- refs/heads/pr/jrfastab/dbgv114
- refs/heads/pr/jrfastab/eks-encrypt-ipamupdate
- refs/heads/pr/jrfastab/fix-encrypt-subnets
- refs/heads/pr/jrfastab/fix-ixsec-vxlan-remoteIP
- refs/heads/pr/jrfastab/fixes-ipsec-init
- refs/heads/pr/jrfastab/v1.8-fix-ipsec-vxlan-remoteIP
- refs/heads/pr/jrfastab/v1.9-fix-ipsec-vxlan-remoteIP
- refs/heads/pr/jrfastab/v111-debug-ooo
- refs/heads/pr/jrfastab/v111-debug-ooo-v2
- refs/heads/pr/jwi/main/ipsec-rhel8
- refs/heads/pr/jwi/v1.14/ci-ipsec
- refs/heads/pr/jwi/v1.15/bpf-complexity
- refs/heads/pr/jwi/v1.15/ci-ipsec
- refs/heads/pr/k8s-nat46x64
- refs/heads/pr/k8s-nat46x64-2
- refs/heads/pr/kaworu/helm-hubble-cli.yaml
- refs/heads/pr/kkourt/azure-ipam-test-race
- refs/heads/pr/kkourt/bpftool-update
- refs/heads/pr/kkourt/ct-rst-timeout-wip
- refs/heads/pr/kkourt/v1.11-backport-2022-01-26
- refs/heads/pr/kkourt/v1.9-lxc-complexity
- refs/heads/pr/l4lb-improvements-tmp
- refs/heads/pr/learnitall/ginkgo-race-workflow
- refs/heads/pr/learnitall/test-startup-script-changes
- refs/heads/pr/lmb/1.14-cni
- refs/heads/pr/lmb/1.15-cni
- refs/heads/pr/lmb/update-cni-plugin
- refs/heads/pr/marga/v1.11-without-deny-precedence
- refs/heads/pr/marseel/scale_test_1_15
- refs/heads/pr/max/upgrade-llvm-18-1-6
- refs/heads/pr/mhofstetter/guestbook-registry
- refs/heads/pr/mhofstetter/junit-fetch-nullglob
- refs/heads/pr/mhofstetter/ssh-store-consolelog
- refs/heads/pr/mhofstetter/test-ingress
- refs/heads/pr/michi/circular-struggle
- refs/heads/pr/michi/clustermesh
- refs/heads/pr/michi/crdregister
- refs/heads/pr/michi/debug
- refs/heads/pr/michi/description
- refs/heads/pr/michi/dns-refactor12
- refs/heads/pr/michi/ipsec-workflows
- refs/heads/pr/michi/l7drop
- refs/heads/pr/michi/majestic-ketchup
- refs/heads/pr/michi/mega-ketchup
- refs/heads/pr/michi/peerapi
- refs/heads/pr/michi/rest
- refs/heads/pr/michi/scaletest
- refs/heads/pr/michi/sleep-on-it
- refs/heads/pr/michi/test
- refs/heads/pr/michi/weekly-bot
- refs/heads/pr/monitor-wait-ci
- refs/heads/pr/move-image-to-one-repo
- refs/heads/pr/nat-gw-tests
- refs/heads/pr/nathanjsweet/add-complex-allow-test-to-policy-map-tests
- refs/heads/pr/nathanjsweet/add-lockdown-mode-for-policy-map-overflows
- refs/heads/pr/nathanjsweet/differentiate-protocol-in-services
- refs/heads/pr/nathanjsweet/node-port-addresses
- refs/heads/pr/nathanjsweet/refactor-mapstate
- refs/heads/pr/nathanjsweet/update-k8s-control-plane-tests-to-1-27
- refs/heads/pr/nebril/add-dns-concurrency-limit
- refs/heads/pr/nebril/fix-precheck
- refs/heads/pr/nebril/fqdn-proxy-ha
- refs/heads/pr/nebril/fqdn-proxy-interface
- refs/heads/pr/nebril/gke-workflow-migrate-from-cli
- refs/heads/pr/nebril/quarantine-1.14-nodeport
- refs/heads/pr/nebril/test-bottlerocket
- refs/heads/pr/nebril/test-helm-gke-fix
- refs/heads/pr/nebril/test-our-ghaction-shenanigans
- refs/heads/pr/nebril/test-rebase-helm
- refs/heads/pr/nebril/trololo
- refs/heads/pr/nebril/update-cli-9.1-test
- refs/heads/pr/netkit
- refs/heads/pr/netkit3
- refs/heads/pr/netns-switch
- refs/heads/pr/netns-switch-no-peer
- refs/heads/pr/nodeport-fix
- refs/heads/pr/nodeport-improvements2
- refs/heads/pr/nodeport-nat-improvements
- refs/heads/pr/nodeport-nat-improvements2
- refs/heads/pr/nodeport-retry-sport
- refs/heads/pr/pchaigno/deprecate-bpf_network-f
- refs/heads/pr/pchaigno/fix-4.19-bpf-program-size
- refs/heads/pr/pchaigno/hotfix1-ipsec-fix
- refs/heads/pr/pchaigno/hotfix1-ipsec-fix-brb-v0
- refs/heads/pr/pchaigno/optim-complexity-ipcache-lookup
- refs/heads/pr/pchaigno/rework-config-probes
- refs/heads/pr/pchaigno/tmp-base-branch
- refs/heads/pr/pin-1.10-workflows-k8s-version
- refs/heads/pr/pin-1.11-workflows-k8s-version
- refs/heads/pr/pin-1.12-workflows-k8s-version
- refs/heads/pr/pin-1.13-workflows-k8s-version
- refs/heads/pr/pin-cloud-provider-master-workflows
- refs/heads/pr/pr/fix-ipam-node-manager-semaphore-error-handling
- refs/heads/pr/publish-test-images
- refs/heads/pr/qmonnet/docs-20230224
- refs/heads/pr/qmonnet/docs-bump
- refs/heads/pr/qmonnet/ipsec/no-missed-tail-call-1.13
- refs/heads/pr/qmonnet/standalone-lb-docs
- refs/heads/pr/qmonnet/sync-joblists
- refs/heads/pr/rastislavs/bgp-e2e-test
- refs/heads/pr/ray/late-dns-proxy
- refs/heads/pr/rgo3/1.12-run-no-unexpected-drops-for-patch
- refs/heads/pr/rgo3/fix-k8s-vm-provisioning-1.13
- refs/heads/pr/rgo3/fix-missing-health-endpoint
- refs/heads/pr/rolinh/better-policy-verdict
- refs/heads/pr/rolinh/hubble-dump-all
- refs/heads/pr/rolinh/hubble-fix-maxflows-rounding
- refs/heads/pr/route-test
- refs/heads/pr/run-tests-in-parallel
- refs/heads/pr/scalability-crd-only
- refs/heads/pr/squeed/make-ccache
- refs/heads/pr/squeed/per-node-config
- refs/heads/pr/squeed/remote-cluster-leak
- refs/heads/pr/stacy/docs-update
- refs/heads/pr/tammach/accesslog-envoy
- refs/heads/pr/tammach/ci-cm
- refs/heads/pr/tammach/cleanup-helm-1.16
- refs/heads/pr/tammach/envoy-1.30
- refs/heads/pr/tammach/headless-service-flake
- refs/heads/pr/tammach/ingress-controller-e2e-config6
- refs/heads/pr/tammach/more-ingress-tests
- refs/heads/pr/tammach/rennovate-statedb
- refs/heads/pr/tammach/revert/fib-lookup
- refs/heads/pr/tammach/ubuntu-24.04
- refs/heads/pr/tammach/ubuntu-24.04-no-llvm
- refs/heads/pr/tc-np-test
- refs/heads/pr/tcx
- refs/heads/pr/tcx-helm
- refs/heads/pr/tcx-misc
- refs/heads/pr/test-419-ci
- refs/heads/pr/test-increase-update-delete-timeout
- refs/heads/pr/test-k8s-all-tests
- refs/heads/pr/test-lb-super-netperf
- refs/heads/pr/test-nightly
- refs/heads/pr/test-upstream-timeout
- refs/heads/pr/tgraf/chaos-testing
- refs/heads/pr/tgraf/clustermesh-stale-state
- refs/heads/pr/tgraf/eni-ipam
- refs/heads/pr/tgraf/new-endpoint-state
- refs/heads/pr/tgraf/new-policy
- refs/heads/pr/tgraf/remove-tunnel-map
- refs/heads/pr/tgraf/scoped-ipam
- refs/heads/pr/tgraf/sctp
- refs/heads/pr/tgraf/split-lxc-prog
- refs/heads/pr/thorn3r/cesBlanketTest
- refs/heads/pr/thorn3r/clustermesh511
- refs/heads/pr/tklauser/build-push-images-env-var
- refs/heads/pr/tommyp1ckles/debugging-aks-conformance
- refs/heads/pr/tp/add-logging-for-wait-for-pods-term-condition
- refs/heads/pr/tp/backport-31380
- refs/heads/pr/tp/bump-cilium-cli
- refs/heads/pr/tp/cleanup-ipam-ips-metric-docs
- refs/heads/pr/tp/complexity-issue-verifier-case-main
- refs/heads/pr/tp/dont-terminate-on-node-config-changee
- refs/heads/pr/tp/eps-modular-health
- refs/heads/pr/tp/fix-stuck-ginko-pod-v2
- refs/heads/pr/tp/forward-hubble-for-e2e
- refs/heads/pr/tp/forward-hubble-for-e2e-v2
- refs/heads/pr/tp/switch-1.24-eks-region
- refs/heads/pr/tp/switch-1.24-eks-region-v1.13
- refs/heads/pr/tp/use-helm-default-vars-for-clustermesh-downgrade-c1
- refs/heads/pr/tweak-github-action-ref
- refs/heads/pr/twpayne/hubble-recent-events-buffer
- refs/heads/pr/twpayne/hubble-ring-buffer-benchmarks
- refs/heads/pr/update-azure
- refs/heads/pr/update-readme-for-releases
- refs/heads/pr/update-tm-network
- refs/heads/pr/v1.10-backport-2022-06-13
- refs/heads/pr/v1.10-backport-2022-10-03
- refs/heads/pr/v1.10-eni-stability-improvements-v1
- refs/heads/pr/v1.10-neigh-clean
- refs/heads/pr/v1.11-backport-2022-10-03
- refs/heads/pr/v1.11-test/issue-692
- refs/heads/pr/v1.12-backport-2023-10-10
- refs/heads/pr/v1.12-test/issue-692
- refs/heads/pr/v1.13-backport-2023-10-31
- refs/heads/pr/v1.13-backport-2024-04-22-03-42
- refs/heads/pr/v1.13-test/issue-692
- refs/heads/pr/v1.14-backport-2024-06-18-02-46
- refs/heads/pr/v1.14.1
- refs/heads/pr/v1.7-stability-test
- refs/heads/pr/v1.7.9-hf-13205
- refs/heads/pr/v3-cpu
- refs/heads/pr/v6-host-addr2
- refs/heads/pr/vk/bpf/tests/csum
- refs/heads/pr/vk/ci/test/concurrent/run
- refs/heads/pr/vk/doc/ipsec
- refs/heads/pr/vk/ipsec/key/rotate
- refs/heads/pr/vk/test/ipsec/tests/concurrent/run
- refs/heads/pr/wip/bijective-nodemap
- refs/heads/regex_improved
- refs/heads/renovate/v1.13-all-dependencies
- refs/heads/renovate/v1.14-all-dependencies
- refs/heads/renovate/v1.15-aanm-test
- refs/heads/renovate/v1.15-all-dependencies
- refs/heads/renovate/v1.16-cilium-cli
- refs/heads/renovate/v1.16-go
- refs/heads/revert-29086-2023-11-09-backport-1.14
- refs/heads/revert-33302-policy-catch-invalid-port-wildcard
- refs/heads/rib
- refs/heads/run-ci-wihout-building-cilium
- refs/heads/sh-dep-test-l4lb
- refs/heads/sidecar-http-proxy
- refs/heads/sockmap-v5
- refs/heads/sockops-build-fix
- refs/heads/tam/integration-tests
- refs/heads/tam/more-ingress-tests
- refs/heads/tb/bpf-remove-bear
- refs/heads/test-branch
- refs/heads/test-ipsec
- refs/heads/test-sig-bgp-notifs
- refs/heads/test/brlbil/upload
- refs/heads/test/skip-workflows
- refs/heads/tgraf/process-policy
- refs/heads/thorn3r/cesScaleTest
- refs/heads/thorn3rCES
- refs/heads/tinker/learnitall/scale-test-1
- refs/heads/tinker/learnitall/scale-test-2
- refs/heads/tklauser+brb/wip/multi-homing
- refs/heads/unit-test-ipsec
- refs/heads/v0.10
- refs/heads/v0.11
- refs/heads/v0.12
- refs/heads/v0.13
- refs/heads/v0.8
- refs/heads/v0.9
- refs/heads/v1.0
- refs/heads/v1.0.0-rc2
- refs/heads/v1.0.0-rc3
- refs/heads/v1.1
- refs/heads/v1.10
- refs/heads/v1.11
- refs/heads/v1.12
- refs/heads/v1.12.11-base
- refs/heads/v1.13
- refs/heads/v1.14
- refs/heads/v1.15
- refs/heads/v1.16
- refs/heads/v1.2
- refs/heads/v1.3
- refs/heads/v1.3.1
- refs/heads/v1.3.1-release
- refs/heads/v1.3.7-release
- refs/heads/v1.4
- refs/heads/v1.4.5-release
- refs/heads/v1.5
- refs/heads/v1.5.2-rc1-with-clusterip-fix
- refs/heads/v1.5.4-release
- refs/heads/v1.6
- refs/heads/v1.7
- refs/heads/v1.7.9-1
- refs/heads/v1.7.9.1
- refs/heads/v1.8
- refs/heads/v1.9
- refs/heads/verify-external-workload-dns-setup-redux
- refs/heads/vladu/identity-type-metrics
- refs/heads/weavescope
- refs/heads/wip-ktls-tx-rx
- refs/heads/wip-sockmap
- refs/heads/wip-sockmap-v2
- refs/heads/wip-sockmap-v3
- refs/heads/wip-sockmap-v4
- refs/heads/xfrm-subnet-test
- refs/heads/yutaro/bgp-cplane-etp-local/doc
- refs/heads/yutaro/oss/eni-overlapping-mark
- refs/remotes/bruno/hf/v1.10/v1.10.3-bpf-snat-and-masq-fixes
- refs/remotes/joe/submit/quarantine-etcd
- refs/remotes/origin/1.2-backports-18-09-12
- refs/remotes/origin/ipvlan3
- refs/remotes/origin/pr/add-reserved-health
- refs/remotes/origin/pr/brb/nodeport-lb
- refs/remotes/origin/pr/ianvernon/5859
- refs/remotes/origin/pr/ianvernon/dynamic-ep-cfg
- refs/remotes/origin/pr/tgraf/kube-dns-fixed-identity
- refs/semaphoreci/6384f501b324813e55cfbe818c04a40f2a923765
- refs/semaphoreci/7f69b285bac8a1be414e8769799962ae1408d9e1
- refs/semaphoreci/b5eb6622da121ad36b8f375a084392f7feeec64a
- refs/semaphoreci/d9e7e28f39d34a7050a9c1cad2a26d84f5f4eff1
- refs/semaphoreci/f55ec535d85f387ef981265967fabb3c1b5f1ec6
- refs/tags/0.10.1
- refs/tags/1.1.1
- refs/tags/1.9.0-rc0
- refs/tags/v0.11
- refs/tags/v0.12.0
- refs/tags/v0.13.1
- refs/tags/v0.8.0
- refs/tags/v0.8.1
- refs/tags/v0.8.2
- refs/tags/v0.9.0
- refs/tags/v0.9.0-rc1
- refs/tags/v1.0.0-rc2
- Branches list truncated to 687 entries, 4 were omitted.
- v1.0.0-rc14
- v1.0.0-rc13
- v1.0.0-rc11
- v1.0.0-rc10
- v1.0.0-rc1
- v1.0.0
- v0.13.9
- v0.13.8
- v0.13.7
- v0.13.6
- v0.13.5
- v0.13.4
- v0.13.3
- v0.13.28
- v0.13.25
- v0.13.24
- v0.13.23
- v0.13.22
- v0.13.21
- v0.13.20
- v0.13.2
- v0.13.19
- v0.13.18
- v0.13.17
- v0.13.16
- v0.13.15
- v0.13.14
- v0.13.13
- v0.13.12
- v0.13.11
- v0.13.10
- v0.10.0
- 1.9.9
- 1.9.8
- 1.9.7
- 1.9.6
- 1.9.5
- 1.9.4
- 1.9.3
- 1.9.2
- 1.9.18
- 1.9.17
- 1.9.16
- 1.9.15
- 1.9.14
- 1.9.13
- 1.9.12
- 1.9.11
- 1.9.10
- 1.9.1
- 1.9.0-rc3
- 1.9.0-rc2
- 1.9.0-rc1
- 1.9.0
- 1.8.9
- 1.8.8
- 1.8.7
- 1.8.6
- 1.8.5
- 1.8.4
- 1.8.3
- 1.8.2
- 1.8.13
- 1.8.12
- 1.8.11
- 1.8.10
- 1.8.1
- 1.8.0-rc4
- 1.8.0-rc3
- 1.8.0-rc2
- 1.8.0-rc1
- 1.8.0
- 1.7.9
- 1.7.8
- 1.7.7
- 1.7.6
- 1.7.5
- 1.7.4
- 1.7.3
- 1.7.2
- 1.7.16
- 1.7.15
- 1.7.14
- 1.7.13
- 1.7.12
- 1.7.11
- 1.7.10
- 1.7.1
- 1.7.0-rc4
- 1.7.0-rc3
- 1.7.0
- 1.6.9
- 1.6.8
- 1.6.7
- 1.6.6
- 1.6.5
- 1.6.4
- 1.6.3
- 1.6.2
- 1.6.12
- 1.6.11
- 1.6.10
- 1.6.1
- 1.6.0
- 1.5.9
- 1.5.8
- 1.5.7
- 1.5.6
- 1.5.5
- 1.5.4
- 1.5.3
- 1.5.2
- 1.5.13
- 1.5.12
- 1.5.11
- 1.5.10
- 1.5.1
- 1.5.0-rc6
- 1.5.0-rc5
- 1.5.0-rc4
- 1.5.0-rc3
- 1.5.0-rc2
- 1.5.0
- 1.4.9
- 1.4.8
- 1.4.7
- 1.4.6
- 1.4.5
- 1.4.4
- 1.4.3
- 1.4.2
- 1.4.10
- 1.4.1
- 1.4.0-rc9
- 1.4.0-rc8
- 1.4.0-rc7
- 1.4.0-rc6
- 1.4.0-rc5
- 1.4.0-rc2
- 1.4.0
- 1.3.8
- 1.3.7
- 1.3.6
- 1.3.5
- 1.3.4
- 1.3.3
- 1.3.2
- 1.3.1
- 1.3.0-rc5
- 1.3.0-rc4
- 1.3.0
- 1.2.8
- 1.2.7
- 1.2.6
- 1.2.5
- 1.2.4
- 1.2.3
- 1.2.2
- 1.2.1
- 1.2.0-rc3
- 1.2.0-rc2
- 1.2.0-rc1
- 1.2.0
- 1.16.0-rc.1
- 1.16.0-rc.0
- 1.16.0-pre.3
- 1.16.0-pre.2
- 1.16.0-pre.1
- 1.16.0-pre.0
- 1.15.7
- 1.15.6
- 1.15.5
- 1.15.4
- 1.15.3
- 1.15.2
- 1.15.1
- 1.15.0-rc.1
- 1.15.0-rc.0
- 1.15.0-pre.3
- 1.15.0-pre.2
- 1.15.0-pre.1
- 1.15.0-pre.0
- 1.15.0
- 1.14.9
- 1.14.8
- 1.14.7
- 1.14.6
- 1.14.5
- 1.14.4
- 1.14.3
- 1.14.2
- 1.14.13
- 1.14.12
- 1.14.11
- 1.14.10
- 1.14.1
- 1.14.0-snapshot.4
- 1.14.0-snapshot.3
- 1.14.0-snapshot.2
- 1.14.0-snapshot.1
- 1.14.0-snapshot.0
- 1.14.0-rc.1
- 1.14.0-rc.0
- 1.14.0-pre.2
- 1.14.0
- 1.13.9
- 1.13.8
- 1.13.7
- 1.13.6
- 1.13.5
- 1.13.4
- 1.13.3
- 1.13.2
- 1.13.18
- 1.13.17
- 1.13.16
- 1.13.15
- 1.13.14
- 1.13.13
- 1.13.12
- 1.13.11
- 1.13.10
- 1.13.1
- 1.13.0-rc5
- 1.13.0-rc4
- 1.13.0-rc3
- 1.13.0-rc2
- 1.13.0-rc1
- 1.13.0-rc0
- 1.13.0
- 1.12.9
- 1.12.8
- 1.12.7
- 1.12.6
- 1.12.5
- 1.12.4
- 1.12.3
- 1.12.2
- 1.12.19
- 1.12.18
- 1.12.17
- 1.12.16
- 1.12.15
- 1.12.14
- 1.12.13
- 1.12.12
- 1.12.11
- 1.12.10
- 1.12.1
- 1.12.0-rc3
- 1.12.0-rc2
- 1.12.0-rc1
- 1.12.0-rc0
- 1.12.0
- 1.11.9
- 1.11.8
- 1.11.7
- 1.11.6
- 1.11.5
- 1.11.4
- 1.11.3
- 1.11.20
- 1.11.2
- 1.11.19
- 1.11.18
- 1.11.17
- 1.11.16
- 1.11.15
- 1.11.14
- 1.11.13
- 1.11.12
- 1.11.11
- 1.11.10
- 1.11.1
- 1.11.0-rc3
- 1.11.0-rc2
- 1.11.0-rc1
- 1.11.0-rc0
- 1.11.0
- 1.10.9
- 1.10.8
- 1.10.7
- 1.10.6
- 1.10.5
- 1.10.4
- 1.10.3
- 1.10.20
- 1.10.2
- 1.10.19
- 1.10.18
- 1.10.17
- 1.10.16
- 1.10.15
- 1.10.14
- 1.10.13
- 1.10.12
- 1.10.11
- 1.10.10
- 1.10.1
- 1.10.0-rc2
- 1.10.0-rc1
- 1.10.0-rc0
- 1.10.0
- 1.1.6
- 1.1.5
- 1.1.4
- 1.1.3
- 1.1.2
- 1.1.0
- 1.0.7
- 1.0.6
- 1.0.5
- 1.0.4
- Releases list truncated to 313 entries, 325 were omitted.
Take a new snapshot of a software origin
If the archived software origin currently browsed is not synchronized with its upstream version (for instance when new commits have been issued), you can explicitly request Software Heritage to take a new snapshot of it.
Use the form below to proceed. Once a request has been submitted and accepted, it will be processed as soon as possible. You can then check its processing state by visiting this dedicated page.Processing "take a new snapshot" request ...
Permalinks
To reference or cite the objects present in the Software Heritage archive, permalinks based on SoftWare Hash IDentifiers (SWHIDs) must be used.
Select below a type of object currently browsed in order to display its associated SWHID and permalink.
Revision | Author | Date | Message | Commit Date |
---|---|---|---|---|
5e0516a | Ian Vernon | 10 April 2018, 21:21:58 UTC | test/k8sT: do not defer deletion of resources within It In K8sValidatedPolicyTestAcrossNamespaces, the deletion of pods and policies was wrapped with `defer` calls, which meant that regardless of whether the test failed or succeeded, the aforementioned resources were deleted within the `It` for the test. Destruction of such resources should only be performed in the `AfterEach` block of the test, as we want all resources to still be present for running log-gathering scripts like `cilium bugtool`. Signed-off by: Ian Vernon <ian@cilium.io> | 14 April 2018, 00:09:13 UTC |
d0b8fe7 | André Martins | 11 April 2018, 12:45:23 UTC | test: update kubedns to 1.14.9 Since kubedns 1.14.9 contains bug fixes it might help in kube-dns issues the CI is having Signed-off-by: André Martins <andre@cilium.io> | 14 April 2018, 00:07:39 UTC |
1e1fbbd | Jarno Rajahalme | 13 April 2018, 20:13:56 UTC | envoy: Remove assert, reduce logging. Signed-off-by: Jarno Rajahalme <jarno@covalent.io> | 14 April 2018, 00:07:03 UTC |
279d1a8 | Daniel Borkmann | 13 April 2018, 10:14:47 UTC | docs, bpf: finalize initial round on xdp section Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> | 13 April 2018, 21:31:37 UTC |
118ad82 | Thomas Graf | 13 April 2018, 06:44:46 UTC | policy: Do not wildcard CIDR 0/0 for world and all entity With the introduction of label based egress including the world and all identity, it is no longer required to whitelist CIDR 0/0 for the world and all entity as it is covered by the identity based policy map which also supports L4. This allows to define rules such as: [{ "endpointSelector": {"matchLabels": {}}, "egress": [{ "toEntities": ["world"], "toPorts": [ {"ports":[ {"port": "80", "protocol": "TCP"}, {"port": "53", "protocol": "UDP"} ]} ] }] }] Signed-off-by: Thomas Graf <thomas@cilium.io> | 13 April 2018, 20:36:46 UTC |
935d0ab | Eloy Coto | 12 April 2018, 10:43:40 UTC | Docs: Add a new `test-docs-please` phrase to test only docs Signed-off-by: Eloy Coto <eloy.coto@gmail.com> | 13 April 2018, 18:40:17 UTC |
e93a9fd | Eloy Coto | 10 April 2018, 15:01:37 UTC | DOC: Update cilium contributing docs: - Added documentation for JustAfterEach, AfterFailed and example flow of execution. - Extend documentation related to sshConfig - Added documenation how to run ginkgo using delve. Signed-off-by: Eloy Coto <eloy.coto@gmail.com> | 13 April 2018, 16:52:00 UTC |
5ac8834 | Eloy Coto | 13 April 2018, 10:44:44 UTC | Test: CNP use full FQDN Signed-off-by: Eloy Coto <eloy.coto@gmail.com> | 13 April 2018, 16:23:00 UTC |
ee0a66d | Eloy Coto | 13 April 2018, 09:31:10 UTC | Test: Validate DNS before trying to connect on curl This commit intruduced a new Kubectl method that make sure that the DNS exits before pods try to connect to other pod using DNS. On the other hand, changed all services names to use the full FQDN, some containers didn't use the search directive commands [0] and the name resolution didn't work as expected: Example trace: ``` U +0.477121 10.10.0.77:47324 -> 10.10.0.18:53 ~''''''''''''deathstar'default''''' U +0.000141 10.10.0.18:19419 -> 8.8.8.8:53 '''''''''''''deathstar'default''''' U +0.000320 10.10.0.18:19419 -> 8.8.4.4:53 '''''''''''''deathstar'default''''' U +0.000318 10.10.0.77:47324 -> 10.10.0.18:53 '''''''''''''deathstar'default''''' U +0.000070 10.10.0.18:40244 -> 8.8.8.8:53 '''''''''''''deathstar'default''''' U +0.064932 8.8.4.4:53 -> 10.10.0.18:19419 '''''''''''''deathstar'default''''''''''''Q{'@'a'root-servers'net''nstld'verisign-grs'com'xH'''''''''''':'''Q' ``` [0] https://github.com/gliderlabs/docker-alpine/blob/master/docs/caveats.commands#dns Fix #3712 Fix #3675 Fix #3462 Fix #3676 Fix #3694 Fix #3695 Signed-off-by: Eloy Coto <eloy.coto@gmail.com> | 13 April 2018, 16:23:00 UTC |
efb3222 | André Martins | 13 April 2018, 11:36:08 UTC | docs: fix misspelled words Signed-off-by: André Martins <andre@cilium.io> | 13 April 2018, 12:50:16 UTC |
92f7ae1 | Ray Bejjani | 13 April 2018, 10:10:59 UTC | doc: system requirements mention meltdown | 13 April 2018, 11:23:30 UTC |
3110085 | Joe Stringer | 10 April 2018, 23:51:58 UTC | Revert "bpf: Allow CT creation on FIN" This reverts commit 3389456b3b4dbdac94541c5169fb7de371db78b4. Signed-off-by: Joe Stringer <joe@covalent.io> | 13 April 2018, 09:53:35 UTC |
64bc5df | Joe Stringer | 10 April 2018, 22:00:47 UTC | bpf: Only create conntrack entries for SYN packets Previously in e4c58da6d6a5 ("bpf: Simplify connection tracking logic"), we loosened the policy for creating conntrack entries to allow entries for long-lived connections to be temporarily removed and to be subsequently added. This worked around issues with overzealous conntrack cleanup and proxy implementations with no keepalives. After recent commits to simplify & streamline conntrack garbage collection, and updates to the keepalive policy, we expect that it is now safe again to require a SYN packet to create a connection. This also allows deletion of conntrack entries due to commit 9095ef8918e3 ("bpf: Remove connection tracking entries on policy deny") to halt ongoing connections when a liberal egress policy is in place, rather than allowing such connections to continue due to egress traffic re-creating the conntrack entry. Signed-off-by: Joe Stringer <joe@covalent.io> | 13 April 2018, 09:53:35 UTC |
f486df7 | André Martins | 12 April 2018, 15:29:28 UTC | docs: add istio GSG to the list of GSGs Signed-off-by: André Martins <andre@cilium.io> | 13 April 2018, 09:52:14 UTC |
7e8fdff | André Martins | 12 April 2018, 15:09:51 UTC | docs: GSG add instructions to install standalone etcd Signed-off-by: André Martins <andre@cilium.io> | 13 April 2018, 09:52:14 UTC |
b037c83 | André Martins | 12 April 2018, 15:09:13 UTC | examples/kubernetes: move standalone-etcd.yaml to addons/ Signed-off-by: André Martins <andre@cilium.io> | 13 April 2018, 09:52:14 UTC |
45e7b89 | André Martins | 12 April 2018, 15:03:51 UTC | docs: use common minikube setup for all GSG Signed-off-by: André Martins <andre@cilium.io> | 13 April 2018, 09:52:14 UTC |
016db04 | André Martins | 12 April 2018, 15:00:39 UTC | examples/kubernetes: change etcd default port Signed-off-by: André Martins <andre@cilium.io> | 13 April 2018, 09:52:14 UTC |
3c767f2 | André Martins | 12 April 2018, 14:58:32 UTC | examples/kubernetes: avoid port conflict for running etcd By setting the listen-peer-urls to a particular port etcd can avoid clashing with an existing etcd instance listenning on the same default port. Signed-off-by: André Martins <andre@cilium.io> | 13 April 2018, 09:52:14 UTC |
2d4ad0c | André Martins | 12 April 2018, 14:45:39 UTC | examples/kubernetes: keep file order when catenating all files into one Signed-off-by: André Martins <andre@cilium.io> | 13 April 2018, 09:52:14 UTC |
403b265 | Daniel Borkmann | 12 April 2018, 08:40:30 UTC | docs, bpf: initial xdp section and improved projects section Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> | 13 April 2018, 09:50:44 UTC |
49d2785 | ashwinp | 13 April 2018, 01:09:47 UTC | Update docs related to cluster-diagnosis - add doc section for system dump collection Signed-off-by: Ashwin Paranjpe <ashwin@covalent.io> | 13 April 2018, 04:53:18 UTC |
3ba379a | Jarno Rajahalme | 12 April 2018, 22:32:21 UTC | daemon: Regenerate endpoint in PATCH handler also when endpoint is in waiting-for-identity state. commit 41c08396ce ("daemon: Only regenerate in PATCH from valid state") intended to limit endpoint regeneration calls from the API PATCH endpoint handler to valid endpoint states, but inadvertently limited the allowed states only to waiting-to-regenerate, while the endpoint should also be built while in the waiting-for-identity state. The symptom was that endpoints created via docker never built the initial drop-all bpf program while waiting for identity. This commit allows endpoint regeneration via the PATCH endpoint API also when the endpoint is in wairing-for-identity state. Fixes: 41c08396ce ("daemon: Only regenerate in PATCH from valid state") Signed-off-by: Jarno Rajahalme <jarno@covalent.io> | 13 April 2018, 04:09:33 UTC |
1314122 | Ray Bejjani | 11 April 2018, 17:42:24 UTC | doc: Update metrics documentation & list exported metrics We export a small list of metrics and now list them in the docs. This change also includes some text fixups and a bad link to the prometheus configuration. | 12 April 2018, 21:55:24 UTC |
6ba1209 | Ray Bejjani | 12 April 2018, 18:35:17 UTC | docs: Update system requirements Signed-off-by: Ray Bejjani <ray@covalent.io> | 12 April 2018, 21:53:57 UTC |
8515b21 | Jarno Rajahalme | 12 April 2018, 17:44:03 UTC | endpoint: Fix label replacement. Fix bugs in label updates: - Information labels were never deleted - Information label assignments were logged even when nothing changed - Identity label updates never updated the Source or Value of an existing label Add unit test for label updates. Signed-off-by: Jarno Rajahalme <jarno@covalent.io> | 12 April 2018, 20:59:55 UTC |
b195507 | Joe Stringer | 12 April 2018, 18:05:30 UTC | tunnel: Remove old tunnel map upon upgrade. This fixes up #3681 to ensure we don't end up with extraneous map entries on the filesystem after upgrade. Signed-off-by: Joe Stringer <joe@covalent.io> | 12 April 2018, 20:29:52 UTC |
ddcc645 | Manali Bhutiyani | 12 April 2018, 17:52:57 UTC | CI: Remove call to WaitUntilEndpointUpdates, if CiliumPolicyAction is present. CiliumPolicyAction takes care of waiting till endpoints get updated correctly. Remove the unnecessary calling of WaitUntilEndpointUpdates, in addition to CiliumPolicyAction. Fixes :#3343 Signed-Off-By: Manali Bhutiyani <manali@covalent.io> | 12 April 2018, 19:27:45 UTC |
9ba22a0 | Manali Bhutiyani | 10 April 2018, 22:26:06 UTC | CI: Add ingress/egress default deny tests for CNP Fixes :#3343 Signed-Off-By: Manali Bhutiyani <manali@covalent.io> | 12 April 2018, 19:27:45 UTC |
768fbdf | Jarno Rajahalme | 11 April 2018, 22:59:46 UTC | envoy: Pass 'non-redirect' http traffic through. Cilium only creates a host proxy redirect when the relevant policy has http rules. A sidecar proxy gets also traffic that would not have been redirected with a host proxy. To emulate the host proxy behavior we pass (allow) traffic through a sidecar if it is passed through by the bpf datapath and would not have been redirected to a host proxy. There are two cases in cilium network policy enforcement where we can detect that the given packet would not have been forwarded to a host proxy: 1. There is no port policy that covers this connection. Cilium always configures a port policy for a redirect, and hence if we find that there is no applicable port policy, the connection must have been passed by the bpf datapath to a sidecar and the sidecar proxy should pass it through, i.e., consider the decision made by the bpf datapath final. 2. There is a port policy, but it does not have any http rules. Again, in this case this request would not have been redirected to a host proxy, and we must consider bpf datapath policy decision as final by passing the request through the sidecar proxy. There changes are marked with TODOs as they will need to be reconsidered when a non-bpf datapaths are supported. Suggested-by: Romain Lenglet <romain@covalent.io> Signed-off-by: Jarno Rajahalme <jarno@covalent.io> | 12 April 2018, 15:22:37 UTC |
b200061 | Maciej Kwiek | 11 April 2018, 14:23:54 UTC | [DOCS] Edit API compatibility guarantees section Signed-off-by: Maciej Kwiek <maciej@covalent.io> | 12 April 2018, 14:21:42 UTC |
5e64046 | Eloy Coto | 11 April 2018, 07:45:19 UTC | DOC: Cheatsheet change structure - Add a intro in the page - Change structure of the page to multiple headline levels. - Add Kubernetes section - Add a quick tip how to install tab completion and json support. - Add some cilium commands. Signed-off-by: Eloy Coto <eloy.coto@gmail.com> | 12 April 2018, 13:19:27 UTC |
323973b | Romain Lenglet | 11 April 2018, 19:13:38 UTC | doc: Use K8s-version-specific YAML files in Istio GSG Signed-off-by: Romain Lenglet <romain@covalent.io> | 12 April 2018, 12:59:39 UTC |
b542e40 | Romain Lenglet | 10 April 2018, 09:46:26 UTC | examples/kubernetes: Generate daemon sets defs for sidecar mode Clean up examples/kubernetes/Makefile. Add support for V=0 quiet option. Add support for multiple daemon set definitions for each Kubernetes version. Generate */cilium-sidecar*.yaml daemon set files for running Cilium along with Istio. Signed-off-by: Romain Lenglet <romain@covalent.io> | 12 April 2018, 12:59:39 UTC |
a04087a | Romain Lenglet | 04 April 2018, 15:48:16 UTC | doc: Update Istio GSG for Istio 0.7.0 Signed-off-by: Romain Lenglet <romain@covalent.io> | 12 April 2018, 12:59:39 UTC |
f117836 | Joe Stringer | 12 April 2018, 04:26:20 UTC | bpf: Rename tunnel_endpoint_map -> cilium_tunnel_map Rename the tunnel endpoint map so it has the same prefix as all of the other cilium maps. Signed-off-by: Joe Stringer <joe@covalent.io> | 12 April 2018, 12:48:33 UTC |
3344b52 | Ian Vernon | 11 April 2018, 19:26:32 UTC | test/helpers: add previous Cilium pod logs to kubectl.GatherLogs() Signed-off by: Ian Vernon <ian@cilium.io> | 12 April 2018, 12:46:38 UTC |
352fa2a | Eloy Coto | 12 April 2018, 08:35:41 UTC | Test: Enabled K8sUpdates correctly. On abc97b91ac7bf088e46e556cca357f1b91f8531d the test was mark to run, but in the It there was a return that I didn't figure it out, so the whole test was not running. :-( Related to: #3624 Signed-off-by: Eloy Coto <eloy.coto@gmail.com> | 12 April 2018, 12:46:07 UTC |
39d3b06 | Eloy Coto | 12 April 2018, 10:54:40 UTC | Test: Fix issue with Kubectl describe Kubectl describe does not have `-o json` option available. And the output in a failed test was not correct. Signed-off-by: Eloy Coto <eloy.coto@gmail.com> | 12 April 2018, 12:45:37 UTC |
d7a17db | Daniel Borkmann | 11 April 2018, 15:02:02 UTC | docs, bpf: complete iproute2 section and add llvm inline asm example Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> | 12 April 2018, 00:45:09 UTC |
7a2ecac | Manali Bhutiyani | 11 April 2018, 19:40:12 UTC | docs: Minikube audit. Add reference links wherever required. Improve docs wherever required. Part of the 1.0 Documentation Review. Fixes: #3669 Related to: #3597 Signed-Off-By: Manali Bhutiyani <manali@covalent.io> | 12 April 2018, 00:11:41 UTC |
99297d4 | Ian Vernon | 11 April 2018, 18:28:51 UTC | test/k8sT: do not access redis-master via hostname, only service IP In K8s 1.7 tests, there are issues accessing redis-master via hostname. Disable accessing redis-master via its hostname until K8s 1.7 is updated in CI to a newer version. See GH-3462 for more information. Signed-off by: Ian Vernon <ian@cilium.io> | 11 April 2018, 23:07:38 UTC |
45bca6a | André Martins | 11 April 2018, 17:14:59 UTC | docs: review troubleshooting guide Signed-off-by: André Martins <andre@cilium.io> | 11 April 2018, 19:52:58 UTC |
bb8d3f1 | André Martins | 11 April 2018, 13:33:10 UTC | docs: fix some misspelled words Signed-off-by: André Martins <andre@cilium.io> | 11 April 2018, 19:45:39 UTC |
2508f2d | André Martins | 11 April 2018, 13:31:30 UTC | docs: add misspell words checker Signed-off-by: André Martins <andre@cilium.io> | 11 April 2018, 19:45:39 UTC |
025e558 | André Martins | 10 April 2018, 13:10:22 UTC | docs: add quay.io tutorial - Add tutorial to update cilium-runtime and cilium-builder images Signed-off-by: André Martins <andre@cilium.io> | 11 April 2018, 18:23:01 UTC |
08b4b2c | André Martins | 10 April 2018, 12:42:12 UTC | docs: fix titles formatting Signed-off-by: André Martins <andre@cilium.io> | 11 April 2018, 18:23:01 UTC |
8e0a92d | André Martins | 10 April 2018, 11:09:30 UTC | Makefile: remove docker-image push instructions Signed-off-by: André Martins <andre@cilium.io> | 11 April 2018, 18:23:01 UTC |
952ae20 | André Martins | 10 April 2018, 11:07:25 UTC | envoy: move Dockerfile.builder to envoy directory Signed-off-by: André Martins <andre@cilium.io> | 11 April 2018, 18:23:01 UTC |
c867679 | André Martins | 09 April 2018, 19:28:40 UTC | Dockerfile: point dockerfile to quay.io base images Since quay.io does not detect symlinks we have to move the Dockefile directly to the envoy directory. Signed-off-by: André Martins <andre@cilium.io> | 11 April 2018, 18:23:01 UTC |
bdcb94e | André Martins | 29 March 2018, 17:20:09 UTC | packaging/docker: update docker runtime to 17.10 Signed-off-by: André Martins <andre@cilium.io> | 11 April 2018, 18:23:01 UTC |
b97c14d | Eloy Coto | 11 April 2018, 10:27:31 UTC | Test: Add separate logs per each cilium pod Fix 3636 Signed-off-by: Eloy Coto <eloy.coto@gmail.com> | 11 April 2018, 17:47:37 UTC |
ee23ad0 | Ian Vernon | 25 October 2017, 19:08:07 UTC | pkg/ip: add functionality to coalesce CIDR list Add CoalesceCIDRs and associated helper functions, which combines a list of CIDRs into the smallest equivalent set of CIDRs. Signed-off by: Ian Vernon <ian@cilium.io> | 11 April 2018, 17:44:30 UTC |
b8babe4 | Romain Lenglet | 11 April 2018, 06:33:08 UTC | test: Fix K8s demos to not use TTYs with kubectl exec Signed-off-by: Romain Lenglet <romain@covalent.io> | 11 April 2018, 15:37:26 UTC |
7a73360 | André Martins | 11 April 2018, 11:40:18 UTC | pkg/node: fix nil pointer dereference If a node doesn't have any IPv6 address cilium can panic while trying to delete the IPv6 routes of that node. Signed-off-by: André Martins <andre@cilium.io> Reported-by: Markus Padourek <markus.padourek@gmail.com> | 11 April 2018, 12:54:50 UTC |
cb9020a | Eloy Coto | 03 April 2018, 10:29:14 UTC | Test: trigger AfterFailed before AfterEach when is in Context When a context is defined with a AfterEach the AfterEach function will be called before `JustAfterEach` and `AfterFailed` and some info cannot be retrieved correctly because no longer exits. With this commit all the `JustAfterEach` and `AfterFailed` will be called just before the AfterEach. Fix #3481 Signed-off-by: Eloy Coto <eloy.coto@gmail.com> | 11 April 2018, 12:32:25 UTC |
66f4279 | André Martins | 06 April 2018, 23:27:14 UTC | docs: fix spelling in documentation Signed-off-by: André Martins <andre@cilium.io> | 11 April 2018, 12:30:19 UTC |
980d1e0 | André Martins | 06 April 2018, 23:26:09 UTC | docs: add custom worldlist for spellcheck Signed-off-by: André Martins <andre@cilium.io> | 11 April 2018, 12:30:19 UTC |
e670050 | André Martins | 06 April 2018, 23:25:21 UTC | docs: add sphinx-spelling to documentation Signed-off-by: André Martins <andre@cilium.io> | 11 April 2018, 12:30:19 UTC |
f854ce8 | André Martins | 10 April 2018, 23:58:42 UTC | examples/k8s: fix 1.8 spec files Signed-off-by: André Martins <andre@cilium.io> | 11 April 2018, 12:28:28 UTC |
985c95c | André Martins | 10 April 2018, 23:57:53 UTC | docs: update minikube GSG Signed-off-by: André Martins <andre@cilium.io> | 11 April 2018, 12:26:03 UTC |
aca339e | Daniel Borkmann | 10 April 2018, 11:37:35 UTC | bpf: further work on bpf reference guide Add various improvements all over the place plus a section on bpftool and BPF to BPF calls. XDP and tc coming next. Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> | 11 April 2018, 12:19:39 UTC |
c26a37b | Daniel Borkmann | 09 April 2018, 19:24:55 UTC | docs: update mailmap and authors Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> | 11 April 2018, 12:19:39 UTC |
5b03fb8 | Romain Lenglet | 10 April 2018, 17:30:23 UTC | daemon: Clean up access log setup Pass access logging settings as parameters instead of coupling via viper flags. Minor log message cleanups. Signed-off-by: Romain Lenglet <romain@covalent.io> | 11 April 2018, 07:13:55 UTC |
c9b0328 | Thomas Graf | 10 April 2018, 22:30:15 UTC | health: Do sanity checking on health response Check all fields for potential nil pointers. Some of the fields can be omitted if the health API is triggered while the agent is still bootstrapping. Fixes: #3628 Signed-off-by: Thomas Graf <thomas@cilium.io> | 11 April 2018, 06:12:34 UTC |
80a1f22 | André Martins | 10 April 2018, 23:57:17 UTC | docs: review kafka GSG Signed-off-by: André Martins <andre@cilium.io> | 11 April 2018, 05:18:55 UTC |
60a4b52 | Eloy Coto | 09 April 2018, 11:29:29 UTC | Test: Enable Cilium Update test - Update cilium_ds.yaml to use cilium/cilium:stable image - Delete scale command. It'll fail with 5 or 8 containers. Signed-off-by: Eloy Coto <eloy.coto@gmail.com> | 10 April 2018, 20:31:59 UTC |
1df6acc | Ian Vernon | 10 April 2018, 18:24:00 UTC | pkg/endpoint: log what caused policy changes Before this commit, we only logged whether policy was changed or not for a given endpoint or consumable, not what caused the policy change itself. To get more visibility into what might trigger regenerations, log at debug level what causes policy changes. Signed-off by: Ian Vernon <ian@cilium.io> | 10 April 2018, 20:30:13 UTC |
473a2d8 | Ian Vernon | 10 April 2018, 15:59:43 UTC | test/k8sT: add more descriptive error messages to Guestbook test Signed-off by: Ian Vernon <ian@cilium.io> | 10 April 2018, 20:29:58 UTC |
72a3f86 | Ian Vernon | 09 April 2018, 22:19:22 UTC | test/k8sT: add wait for service endpoints to be ready in guestbook test Signed-off by: Ian Vernon <ian@cilium.io> | 10 April 2018, 20:29:58 UTC |
0fb21a4 | Ian Vernon | 09 April 2018, 19:57:46 UTC | test/k8sT: query both service IP and hostname of redis master This will add more visibility to cases where there is an issue with resolving service names via DNS. Signed-off by: Ian Vernon <ian@cilium.io> | 10 April 2018, 20:29:58 UTC |
ebf2a35 | Ian Vernon | 09 April 2018, 17:55:11 UTC | test/helpers: gather more K8s metadata * Get output in JSON for K8s-related objects in K8s log gathering functions. * Get replicationcontroller and deployment data. Signed-off by: Ian Vernon <ian@cilium.io> | 10 April 2018, 20:29:58 UTC |
adb32c6 | Romain Lenglet | 10 April 2018, 18:31:04 UTC | docs: Use go-swagger Docker container to generate APIs Signed-off-by: Romain Lenglet <romain@covalent.io> | 10 April 2018, 20:28:21 UTC |
f4233ea | Shantanu Deshpande | 10 April 2018, 07:16:44 UTC | Change logging of new connections from warn to info level Signed-off-by: Shantanu Deshpande <shantanud106@gmail.com> | 10 April 2018, 18:36:52 UTC |
1024913 | Romain Lenglet | 09 April 2018, 20:53:32 UTC | proxy: Create access log file and setup notifier at startup Move the access log file and notifier and metadata configuration at daemon startup instead of when creating the first redirect, so access logging is usable with sidecar proxies, for which Cilium doesn't create redirects. Signed-off-by: Romain Lenglet <romain@covalent.io> | 10 April 2018, 16:30:30 UTC |
4fa2bca | Eloy Coto | 10 April 2018, 11:09:54 UTC | Bugtool: Add gops output - Add gops output for cilium agent to know what happens to the agent in case of something wrong. Signed-off-by: Eloy Coto <eloy.coto@gmail.com> | 10 April 2018, 16:08:10 UTC |
56d43d5 | Thomas Graf | 10 April 2018, 07:41:48 UTC | agent: Provide non-blocking agent status Signed-off-by: Thomas Graf <thomas@cilium.io> | 10 April 2018, 15:59:17 UTC |
4d8b510 | Thomas Graf | 10 April 2018, 01:48:13 UTC | policy: Remove connection tracking cleanup on policy change Signed-off-by: Thomas Graf <thomas@cilium.io> | 10 April 2018, 15:52:22 UTC |
9095ef8 | Thomas Graf | 10 April 2018, 01:26:38 UTC | bpf: Remove connection tracking entries on policy deny Signed-off-by: Thomas Graf <thomas@cilium.io> | 10 April 2018, 15:52:22 UTC |
b35644e | Thomas Graf | 09 April 2018, 22:39:00 UTC | policy: Do not make initial endpoint DROP_ALL mode dependent on policy option The current code only puts a DROP_ALL in place if the endpoint has ingress or egress policy enforcement enabled. This option is derived based on policies which select the endpoint so the option is likely still disabled at the time we determine this for the first time. This leaves the endpoint unprotected until the labels have been derived and thus policy could have been inspected to affect the ingress/egress policy enforcement bits. Signed-off-by: Thomas Graf <thomas@cilium.io> | 10 April 2018, 06:21:41 UTC |
51fdcf0 | Joe Stringer | 09 April 2018, 21:46:03 UTC | policy: Log errors inserting CIDR entries Signed-off-by: Joe Stringer <joe@covalent.io> | 10 April 2018, 06:21:02 UTC |
3ce8067 | Joe Stringer | 09 April 2018, 22:19:37 UTC | cidrmap: Allow insert of any length of CIDR Previously, when attempting to insert CIDRs that differ in length from the maximum prefix length of the protocol type (32 for IPv4, 128 for IPv6), we could end up rejecting the CIDR. Tweak it so that it will accept different CIDR lengths unless the CIDRMap is created without dynamic prefix length (The special XDP prefilter case). Signed-off-by: Joe Stringer <joe@covalent.io> | 10 April 2018, 06:21:02 UTC |
ca1f1fe | Thomas Graf | 09 April 2018, 21:36:05 UTC | policy: Remove logic to reset proxy port Since commit 52a948c40 ("bpf: Derive proxy_port from policy rather than CT"), the proxy port is always derived from the policy table. This makes it unnecessary to clean up the proxy_port in the connection tracking table and all of the logic can be removed. Signed-off-by: Thomas Graf <thomas@cilium.io> | 10 April 2018, 00:45:34 UTC |
8152d64 | Thomas Graf | 09 April 2018, 21:26:05 UTC | bpf: Remove proxy_port from conntrack table It is no longer required as the policy map is used to derived the proxy port and the reverse translation occurs via proxymap. Signed-off-by: Thomas Graf <thomas@cilium.io> | 10 April 2018, 00:45:34 UTC |
f3b4621 | Manali Bhutiyani | 09 April 2018, 19:53:30 UTC | CI: Temporarily add retry 3 times logic in connectivity.go Fixes: #3596 Related to: #3393 Related to: #3595 Related to: #3558 Signed-off-By: Manali Bhutiyani <manali@covalent.io> | 09 April 2018, 23:03:47 UTC |
5316859 | Michal Rostecki | 09 April 2018, 11:21:49 UTC | pkg/kvstore: Handler error from Get method properly Signed-off-by: Michal Rostecki <mrostecki@suse.com> | 09 April 2018, 22:08:34 UTC |
c98584b | Michal Rostecki | 09 April 2018, 10:49:07 UTC | pkg/k8s: Assign value to `rules` variable only if it's used Signed-off-by: Michal Rostecki <mrostecki@suse.com> | 09 April 2018, 22:08:34 UTC |
9b1a403 | Michal Rostecki | 09 April 2018, 10:38:38 UTC | pkg/k8s: Remove unused `node` variable assignment Signed-off-by: Michal Rostecki <mrostecki@suse.com> | 09 April 2018, 22:08:34 UTC |
816f2cf | Michal Rostecki | 09 April 2018, 10:35:11 UTC | pkg/policy: Don't assingn unused variables Before this change, this package assigned `err` or any other vabiables regardless of whether they are actually used. In some cases, `err` variables were assigned properly, but they weren't checked. Signed-off-by: Michal Rostecki <mrostecki@suse.com> | 09 April 2018, 22:08:34 UTC |
e0e7884 | Michal Rostecki | 09 April 2018, 10:18:11 UTC | pkg/ip: Assign value to allowedCIDRs variable only if it's used The first value returned by RemoveCIDRs is not always used and it can be skipped once. Signed-off-by: Michal Rostecki <mrostecki@suse.com> | 09 April 2018, 22:08:34 UTC |
c9e509b | Michal Rostecki | 09 April 2018, 10:01:21 UTC | pkg/envoy/xds: Assign value to ip variable only if it's used `ip` variable is used only once, so there is no need of assigning the value of IstioNodeToIP everytime. Signed-off-by: Michal Rostecki <mrostecki@suse.com> | 09 April 2018, 22:08:34 UTC |
5937a32 | Michal Rostecki | 09 April 2018, 09:42:57 UTC | pkg/endpoint: Don't declare errs variable in function scope errs variables are used only to get the result of applyNewFilter method and it should be declred in the smallest scope possible. Signed-off-by: Michal Rostecki <mrostecki@suse.com> | 09 April 2018, 22:08:34 UTC |
0b19157 | Michal Rostecki | 09 April 2018, 09:36:44 UTC | daemon/endpoint: Handle DeleteElement error properly Error from lxcmap.DeleteElement should be added to the slice of errors, not override it. Signed-off-by: Michal Rostecki <mrostecki@suse.com> | 09 April 2018, 22:08:34 UTC |
daca889 | Ian Vernon | 06 April 2018, 22:27:46 UTC | .gitignore: ignore test/test_results directory Signed-off by: Ian Vernon <ian@cilium.io> | 08 April 2018, 10:16:04 UTC |
2e7aef4 | André Martins | 06 April 2018, 22:42:07 UTC | docs: fix l4 policy examples Signed-off-by: André Martins <andre@cilium.io> | 08 April 2018, 10:13:12 UTC |
f351195 | André Martins | 06 April 2018, 22:15:58 UTC | fix misspelled comments in the code Signed-off-by: André Martins <andre@cilium.io> | 07 April 2018, 00:06:15 UTC |
b2e9402 | Ian Vernon | 05 April 2018, 21:12:51 UTC | bpf/lib: unconditionally create ipcache bpf map in datapath In case the opening and creating of the map in userspace fails, it now will be unconditionally created in the datapath. This will not affect the datapath because the lookup into the map is only performed when egress policy is enabled in the datapath for a specific endpoint. Signed-off by: Ian Vernon <ian@cilium.io> | 06 April 2018, 23:19:32 UTC |
5df8397 | Ian Vernon | 04 April 2018, 20:37:05 UTC | pkg/bpf: add additional logging and error handling * Add logs for when we append to list of maps to open after bpffs is mounted. * Log errors that occur when opening / creating maps which are stored in list of maps to open after bpffs is mounted. Signed-off by: Ian Vernon <ian@cilium.io> | 06 April 2018, 23:19:32 UTC |
09f1936 | Ian Vernon | 06 April 2018, 07:58:01 UTC | pkg/logging/logfields: add log field for BPF map name Signed-off by: Ian Vernon <ian@cilium.io> | 06 April 2018, 23:19:32 UTC |
11091ed | Ian Vernon | 04 April 2018, 19:20:33 UTC | pkg/maps/ipcache: log if map unable to be opened Signed-off by: Ian Vernon <ian@cilium.io> | 06 April 2018, 23:19:32 UTC |