kernel: add required configs for ip6tables support

Currently, the UVM kernel fails for istio deployments (at least with the
version we tested, 1.27.0). This is because the istio sidecar container
uses ip6tables and the required kernel configs are not built-in:

```
iptables binary ip6tables has no loaded kernel support and cannot be used, err: exit status 3 out: ip6tables v1.8.10 (legacy):
can't initialize ip6tables table `filter': Table does not exist (do you need to insmod?)
Perhaps ip6tables or your kernel needs to be upgraded.
```

Signed-off-by: Cameron Baird <cameronbaird@microsoft.com>
This commit is contained in:
Cameron Baird
2025-08-19 21:01:21 +00:00
committed by Fabiano Fidêncio
parent 49ca96561b
commit d16026f7b9
2 changed files with 17 additions and 1 deletions

View File

@@ -74,3 +74,19 @@ CONFIG_VETH=y
# We need TUN/TAP support is a must for VPN kinda services
CONFIG_TUN=y
# Need netfilter support for iptables
CONFIG_NF_TABLES=y
CONFIG_NF_TABLES_INET=y
CONFIG_NF_TABLES_IPV4=y
CONFIG_NF_TABLES_IPV6=y
CONFIG_NFT_CT=y
CONFIG_NFT_LIMIT=y
CONFIG_NFT_MASQ=y
CONFIG_NFT_REDIR=y
CONFIG_NFT_NAT=y
CONFIG_NFT_TUNNEL=y
CONFIG_NFT_QUEUE=y
CONFIG_NFT_QUOTA=y
CONFIG_NFT_COMPAT=y
CONFIG_NFT_HASH=y

View File

@@ -1 +1 @@
162
163