Skip to content

bpf_metadata: Use upstream destination when choosing the source address - #2055

Draft
maanti wants to merge 1 commit into
cilium:mainfrom
maanti:source-address-upstream-destination
Draft

maanti wants to merge 1 commit into
cilium:mainfrom
maanti:source-address-upstream-destination

Conversation

@maanti

@maanti maanti commented Sep 26, 2026 •

Copy link
Copy Markdown

Fixes #2040. The decision on whether to skip the Ingress IP binding is now made from the upstream socket's remote address, instead of the destination filter state of the downstream connection that created the shared upstream connection pool.

I covered the issue with a test and the fix makes this test pass.

Upstream connection pools are shared between downstream connections, so
the source address socket option of one downstream connection is also
used to open upstream connections for requests of other downstream
connections. The option decided whether to skip the source address based
on the destination filter state, which holds the destination of the
latest request of the downstream connection that created the option,
not the destination of the upstream connection being opened.

As a result, north/south L7 LB connections to remote pods could be
opened without the Ingress source address and get dropped by policy at
the destination node, and connections to local pods could be opened with
it.

Use the remote address of the upstream socket instead, which is always
set to the selected upstream host before the socket is bound.

Signed-off-by: Matvei Antipov <matvei.antipov@payrails.com>
@maanti
maanti marked this pull request as ready for review September 26, 2026 12:45
@maanti
maanti requested a review from a team as a code owner September 26, 2026 12:45
@maanti
maanti requested a review from jrajahalme September 26, 2026 12:45
@joestringer

Copy link
Copy Markdown
Member

Hi, please make sure to review the Guide for Submitting a Pull Request and
the Generative AI Policy, and ensure you include the Pull Request Template
in the PR description. Additionally, please complete the checkboxes in the
template so that reviewers understand the steps you took.

@joestringer
joestringer marked this pull request as draft September 26, 2026 17:52

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Connections sometimes skip binding the Ingress IP and get policy-denied

2 participants