You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CIS Version : 2.16.1
Build: f5networks/k8s-bigip-ctlr:latest
BIGIP Version: Big IP 17.1.1.3
AS3 Version: 3.46.2
Agent Mode: AS3
Orchestration: OCP
Orchestration Version: 4.14.16
Pool Mode: Cluster
Additional Setup details: Static Routes, CRD, IngressLink
Description
After deleting all IngressLink CRs from the cluster, CIS would push bare AS3 declaration with no defaultRouteDomain parameter, resetting the Partition default RD to 0 and breaking subsequent Static Route push.
Steps To Reproduce
Create BIG-IP Partition with non-0 RD (e.g. RD1) to be managed by CIS
Observe CIS-managed Partition in BIG-IP (tmsh list auth partition) --> Partition will have RD0 as default RD
Expected Result
Default RD for CIS-managed Partition is consistent with both CIS deployment args (i.e. --default-route-domain) and original Partition RD in BIG-IP
Actual Result
CIS-Managed Partition has RD reset to 0 with no IngressLink CR present, due to CIS pushed bare AS3 declaration without <tenant>/defaultRouteDomain parameter. This makes every Static Route push fails until another CR is created.
In the worst timing scenario, 30 seconds (or more, depends on the verify-interval parameter) would elapse after next CR is created with no connectivity, until the next Static Route push is accepted by BIG-IP.
Setup Details
CIS Version : 2.16.1
Build: f5networks/k8s-bigip-ctlr:latest
BIGIP Version: Big IP 17.1.1.3
AS3 Version: 3.46.2
Agent Mode: AS3
Orchestration: OCP
Orchestration Version: 4.14.16
Pool Mode: Cluster
Additional Setup details: Static Routes, CRD, IngressLink
Description
After deleting all IngressLink CRs from the cluster, CIS would push bare AS3 declaration with no
defaultRouteDomain
parameter, resetting the Partition default RD to 0 and breaking subsequent Static Route push.Steps To Reproduce
tmsh list auth partition
) --> Partition will have RD0 as default RDExpected Result
Default RD for CIS-managed Partition is consistent with both CIS deployment args (i.e.
--default-route-domain
) and original Partition RD in BIG-IPActual Result
CIS-Managed Partition has RD reset to 0 with no IngressLink CR present, due to CIS pushed bare AS3 declaration without
<tenant>/defaultRouteDomain
parameter. This makes every Static Route push fails until another CR is created.In the worst timing scenario, 30 seconds (or more, depends on the
verify-interval
parameter) would elapse after next CR is created with no connectivity, until the next Static Route push is accepted by BIG-IP.Diagnostic Information
CIS Pod creation log
AS3 declaration after deleting CR
Observations (if any)
Similar issue might also happen in other CR
The text was updated successfully, but these errors were encountered: