mirror of
https://github.com/kata-containers/kata-containers.git
synced 2025-10-21 20:08:54 +00:00
kernel: add required configs for ip6tables support
Currently, the UVM kernel fails for istio deployments (at least with the version we tested, 1.27.0). This is because the istio sidecar container uses ip6tables and the required kernel configs are not built-in: ``` iptables binary ip6tables has no loaded kernel support and cannot be used, err: exit status 3 out: ip6tables v1.8.10 (legacy): can't initialize ip6tables table `filter': Table does not exist (do you need to insmod?) Perhaps ip6tables or your kernel needs to be upgraded. ``` Signed-off-by: Cameron Baird <cameronbaird@microsoft.com>
This commit is contained in:
committed by
Fabiano Fidêncio
parent
49ca96561b
commit
d16026f7b9
@@ -74,3 +74,19 @@ CONFIG_VETH=y
|
||||
|
||||
# We need TUN/TAP support is a must for VPN kinda services
|
||||
CONFIG_TUN=y
|
||||
|
||||
# Need netfilter support for iptables
|
||||
CONFIG_NF_TABLES=y
|
||||
CONFIG_NF_TABLES_INET=y
|
||||
CONFIG_NF_TABLES_IPV4=y
|
||||
CONFIG_NF_TABLES_IPV6=y
|
||||
CONFIG_NFT_CT=y
|
||||
CONFIG_NFT_LIMIT=y
|
||||
CONFIG_NFT_MASQ=y
|
||||
CONFIG_NFT_REDIR=y
|
||||
CONFIG_NFT_NAT=y
|
||||
CONFIG_NFT_TUNNEL=y
|
||||
CONFIG_NFT_QUEUE=y
|
||||
CONFIG_NFT_QUOTA=y
|
||||
CONFIG_NFT_COMPAT=y
|
||||
CONFIG_NFT_HASH=y
|
||||
|
@@ -1 +1 @@
|
||||
162
|
||||
163
|
||||
|
Reference in New Issue
Block a user