public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
* [pve-devel] applied: [PATCH firewall] increase default nf_conntrack_max to kernel default
@ 2021-07-08  7:36 wb
  2021-07-08  7:51 ` Thomas Lamprecht
  2021-07-08 20:01 ` alexandre derumier
  0 siblings, 2 replies; 3+ messages in thread
From: wb @ 2021-07-08  7:36 UTC (permalink / raw)
  To: Thomas Lamprecht; +Cc: pve-devel

Hello Thomas,

Currently with Proxmox, I have a Kubernetes node running on LXC. However, I have encountered an issue on the Container Network Interface (CNI) side and in order for it to work, the parameter /proc/sys/net/netfilter/nf_conntrack_max must be raised.

You know that the container settings are managed by the hypervisor. However, something prevents to go above 262144. By searching a bit in your code, I found the limitation in Firewall.pm. I raised this value and the CNI works again.

The last change was in this commit that you made.
https://lists.proxmox.com/pipermail/pve-devel/2019-October/039748.html

Is it possible to take into consideration the increase of this parameter in your code?

Waiting for your feedback.

Sincerely.

Julien BLAIS


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2021-07-08 20:02 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-07-08  7:36 [pve-devel] applied: [PATCH firewall] increase default nf_conntrack_max to kernel default wb
2021-07-08  7:51 ` Thomas Lamprecht
2021-07-08 20:01 ` alexandre derumier

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal