Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions charts/linkerd-control-plane/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -341,6 +341,10 @@ proxyInit:
kubeAPIServerPorts: "443,6443"
# -- Comma-separated list of subnets in valid CIDR format that should be skipped by the proxy
skipSubnets: ""
# -- Comma-separated list of inbound source subnets in valid CIDR format that should be skipped by the proxy
skipInboundSubnets: ""
# -- Comma-separated list of outbound destination subnets in valid CIDR format that should be skipped by the proxy
skipOutboundSubnets: ""
# -- Log level for the proxy-init
# @default -- info
logLevel: ""
Expand Down
8 changes: 8 additions & 0 deletions charts/partials/templates/_proxy-init.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,14 @@ args:
- --subnets-to-ignore
- {{ .Values.proxyInit.skipSubnets | quote }}
{{- end }}
{{- if .Values.proxyInit.skipInboundSubnets }}
- --inbound-subnets-to-ignore
- {{ .Values.proxyInit.skipInboundSubnets | quote }}
{{- end }}
{{- if .Values.proxyInit.skipOutboundSubnets }}
- --outbound-subnets-to-ignore
- {{ .Values.proxyInit.skipOutboundSubnets | quote }}
{{- end }}
image: {{.Values.proxy.image.name}}:{{.Values.proxy.image.version | default .Values.linkerdVersion}}
command: ["/usr/lib/linkerd/linkerd2-proxy-init"]
imagePullPolicy: {{.Values.proxy.image.pullPolicy | default .Values.imagePullPolicy}}
Expand Down
2 changes: 2 additions & 0 deletions pkg/charts/linkerd2/values.go
Original file line number Diff line number Diff line change
Expand Up @@ -223,6 +223,8 @@ type (
IgnoreOutboundPorts string `json:"ignoreOutboundPorts"`
KubeAPIServerPorts string `json:"kubeAPIServerPorts"`
SkipSubnets string `json:"skipSubnets"`
SkipInboundSubnets string `json:"skipInboundSubnets"`
SkipOutboundSubnets string `json:"skipOutboundSubnets"`
LogLevel string `json:"logLevel"`
LogFormat string `json:"logFormat"`
SAMountPath *VolumeMountPath `json:"saMountPath"`
Expand Down
10 changes: 10 additions & 0 deletions pkg/inject/inject.go
Original file line number Diff line number Diff line change
Expand Up @@ -73,6 +73,8 @@ var (
k8s.ProxyAwait,
k8s.ProxyDefaultInboundPolicyAnnotation,
k8s.ProxySkipSubnetsAnnotation,
k8s.ProxySkipInboundSubnetsAnnotation,
k8s.ProxySkipOutboundSubnetsAnnotation,
k8s.ProxyAccessLogAnnotation,
k8s.ProxyShutdownGracePeriodAnnotation,
k8s.ProxyOutboundDiscoveryCacheUnusedTimeout,
Expand Down Expand Up @@ -601,6 +603,14 @@ func ApplyAnnotationOverrides(values *l5dcharts.Values, annotations map[string]s
values.ProxyInit.SkipSubnets = override
}

if override, ok := annotations[k8s.ProxySkipInboundSubnetsAnnotation]; ok {
values.ProxyInit.SkipInboundSubnets = override
}

if override, ok := annotations[k8s.ProxySkipOutboundSubnetsAnnotation]; ok {
values.ProxyInit.SkipOutboundSubnets = override
}

if override, ok := annotations[k8s.ProxyAccessLogAnnotation]; ok {
values.Proxy.AccessLog = override
}
Expand Down
4 changes: 4 additions & 0 deletions pkg/inject/inject_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,8 @@ func TestGetOverriddenValues(t *testing.T) {
k8s.ProxyOpaquePortsAnnotation: "4320-4325,3306",
k8s.ProxyAwait: "enabled",
k8s.ProxySkipSubnetsAnnotation: "172.17.0.0/16",
k8s.ProxySkipInboundSubnetsAnnotation: "10.0.0.0/8",
k8s.ProxySkipOutboundSubnetsAnnotation: "192.168.0.0/16",
k8s.ProxyAccessLogAnnotation: "apache",
k8s.ProxyShutdownGracePeriodAnnotation: "30s",
k8s.ProxyOutboundDiscoveryCacheUnusedTimeout: "50000ms",
Expand Down Expand Up @@ -113,6 +115,8 @@ func TestGetOverriddenValues(t *testing.T) {
values.ProxyInit.IgnoreInboundPorts = "4222,6222"
values.ProxyInit.IgnoreOutboundPorts = "8079,8080"
values.ProxyInit.SkipSubnets = "172.17.0.0/16"
values.ProxyInit.SkipInboundSubnets = "10.0.0.0/8"
values.ProxyInit.SkipOutboundSubnets = "192.168.0.0/16"
values.Proxy.RequireIdentityOnInboundPorts = "8888,9999"
values.Proxy.OutboundConnectTimeout = "6000ms"
values.Proxy.InboundConnectTimeout = "600ms"
Expand Down
8 changes: 8 additions & 0 deletions pkg/k8s/labels.go
Original file line number Diff line number Diff line change
Expand Up @@ -164,6 +164,14 @@ const (
// ProxySkipSubnetsAnnotation can be used to override the skipSubnets config
ProxySkipSubnetsAnnotation = ProxyConfigAnnotationsPrefix + "/skip-subnets"

// ProxySkipInboundSubnetsAnnotation can be used to override the inbound
// subnet exclusions configured for proxy-init.
ProxySkipInboundSubnetsAnnotation = ProxyConfigAnnotationsPrefix + "/skip-inbound-subnets"

// ProxySkipOutboundSubnetsAnnotation can be used to override the outbound
// subnet exclusions configured for proxy-init.
ProxySkipOutboundSubnetsAnnotation = ProxyConfigAnnotationsPrefix + "/skip-outbound-subnets"

// ProxyInboundPortAnnotation can be used to override the inboundPort config.
ProxyInboundPortAnnotation = ProxyConfigAnnotationsPrefix + "/inbound-port"

Expand Down
Loading