[WiP] Update docs and manifests for adding iptables lock support to Felix #902
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Felix now supports (projectcalico/felix#1491) taking the iptables lock when doing iptables operations. This prevents it from conflicting with, for example, kube-proxy, which also takes the lock.
This PR:
/run
, which is where the iptables lockfile lives. Sadly, we can't map in a narrower directory or just the file because the file may not exist and, if it doesn't, docker maps in an empty directory instead.Todos
Release Note