Set LoadBalancer ingress IPMode to prevent kube-proxy from short-circuiting LoadBalancer traffic
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 55/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- go, kubernetes
- Domain
- cloud, infrastructure
Research direction
Start at makeLoadBalancerStatus() and inspect the referenced implementation's getIPMode() helper, proxy protocol configuration, and annotation handling. Review the linked commit and its tests and documentation; done means all LoadBalancerIngress return paths set Proxy or VIP correctly, including the manual override behavior.
Written by the indexing model from the issue text.
Description
Problem
The CCM does not set the ipMode field on LoadBalancerIngress entries. Without this, kube-proxy binds the LoadBalancer IP to every node and intercepts traffic destined for it, bypassing the NodeBalancer entirely for
cluster-internal requests.
This causes a well-known class of failures when proxy protocol is enabled on the NodeBalancer: internal traffic (e.g. cert-manager HTTP01 validation, in-cluster requests to LoadBalancer IPs) reaches the ingress controller
without the expected PROXY protocol header, resulting in broken header errors and failed requests.
See: cert-manager/cert-manager#466
The current workaround is deploying hairpin-proxy, which intercepts DNS and injects PROXY protocol headers for internal traffic. This shouldn't be necessary.
Solution
KEP-1860 added an ipMode field to LoadBalancerIngress with two values:
VIP: kube-proxy binds the LB IP to nodes (current default behavior)Proxy: kube-proxy does not intercept LB traffic, forcing it through the actual LoadBalancer
The CCM should set this field based on proxy protocol configuration. When all ports on a service use proxy protocol, ipMode should be Proxy so that kube-proxy doesn't short-circuit traffic around the NodeBalancer.
Otherwise it should be VIP.
A manual override annotation (service.beta.kubernetes.io/linode-loadbalancer-ip-mode) would also be useful for edge cases.
Reference implementation
I've put together an implementation in this commit that:
- Adds a
getIPMode()helper that auto-detects from proxy protocol config or reads an annotation override - Sets
IPModeon allLoadBalancerIngressentries inmakeLoadBalancerStatus()(all three return paths: hostname-only, IPv6, default) - Includes tests and documentation
The Kubernetes API types (LoadBalancerIPModeVIP, LoadBalancerIPModeProxy) are already available in the k8s.io/api version used by this project.
- Dominant language
- Go
- Stars
- 94
- Forks
- 75
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 7
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from linode/linode-cloud-controller-manager
-
Difficulty 4/5 3-5 days Newbie friendliness 28/100
linode/linode-cloud-controller-manager#543 ·
Maintainers usually reply within 1 day
-
Dependency DashboardOpen
Difficulty 5/5 Over a week Newbie friendliness 20/100
linode/linode-cloud-controller-manager#474 ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
linode/linode-cloud-controller-manager#399 · 2 comments ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 55/100
linode/linode-cloud-controller-manager#392 · 2 comments ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 42/100
linode/linode-cloud-controller-manager#252 · 3 comments ·
Maintainers usually reply within 1 day
All issues in linode/linode-cloud-controller-manager
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
router-for-me/CLIProxyAPI#6399 ·
Maintainers usually reply within 1 day
-
settings.py flaps between reconciles: needsMigrationSetting depends on map iteration orderPossibly taken @fontaineajulien claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
pulp/pulp-operator#1691 ·
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
AOSSIE-Org/DebateAI#611 ·
Maintainers usually reply within 3 days